Posted today
Top Secret
Unspecified
No Traveling
Polygraph
Management
Saint Louis, MO (On-Site/Office)•Richmond, VA (On-Site/Office)
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
Work You'll Do:
Our team, within Cyber Division, performs IV&V functions for infrastructure and applications / cybersecurity WAN risk assessments. JCIP Technical Reviewers play a pivotal role in evaluating the cybersecurity posture of enterprise environments across the Intelligence Community (IC). They conduct comprehensive technical assessments and perform detailed analysis of vulnerability scans to ensure compliance, Technical Implementation Guides (TIGs), Security Technical Implementation Guides (STIGs), Security Requirement Guides (SRGs), and NIST 800-53 rev 5 security controls. DUTIES: Leverage extensive expertise in vulnerability management tools, processes, and lifecycle to independently review and assess technical security controls in support of JCIP Inspections.
Knowledge:
The Team
Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.
Our Enterprise Security offering embeds security in all aspects of digital transformation by securing a client's technical backbone while enabling secure digital transformation. Includes security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected products.
The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals.
Qualifications
Required:
Information for applicants with a need for accommodation: https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html

Work You'll Do:
Our team, within Cyber Division, performs IV&V functions for infrastructure and applications / cybersecurity WAN risk assessments. JCIP Technical Reviewers play a pivotal role in evaluating the cybersecurity posture of enterprise environments across the Intelligence Community (IC). They conduct comprehensive technical assessments and perform detailed analysis of vulnerability scans to ensure compliance, Technical Implementation Guides (TIGs), Security Technical Implementation Guides (STIGs), Security Requirement Guides (SRGs), and NIST 800-53 rev 5 security controls. DUTIES: Leverage extensive expertise in vulnerability management tools, processes, and lifecycle to independently review and assess technical security controls in support of JCIP Inspections.
- Engage with site leadership and technical staff to plan and coordinate vulnerability assessments and remediation verification.
- Interview organizational subject matter experts and review documentation to validate vulnerability findings and risk prioritization using TICCL and KCoHR frameworks.
- Participate in the planning, execution, and reporting of vulnerability assessments with minimal supervision. Prepare detailed assessment deliverables.
- Clearly communicate risk impact and remediation strategies through presentations and written reports.
- Stay current with latest vulnerability management tools, techniques, threat intelligence, and IC policies.
- Travel as required to support remote inspections (8-12 weeks of travel avg some international and passport required).
Knowledge:
- Proven experience with vulnerability scanning tools (e.g., Tenable Nessus, Qualys, Rapid7 Nexpose), vulnerability lifecycle management, and remediation verification.
- Strong understanding of vulnerability risk ratings, threat intelligence integration, and mitigation strategies.
- Familiarity with IC directives, NIST 800-53 and 800-171 security controls as they relate to vulnerability management.
The Team
Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.
Our Enterprise Security offering embeds security in all aspects of digital transformation by securing a client's technical backbone while enabling secure digital transformation. Includes security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected products.
The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals.
Qualifications
Required:
- Bachelor's degree + 13 years of experience OR Master's Degree with 5+ years of experience
- Active Top Secret/SCI clearance with a CI Poly
- Ability to travel 25%, on average, based on the work you do and the clients and industries/sectors you serve
- Local to St. Louis, Missouri or Norfolk, VA area and able to come onsite 5 days a week.
- IAT LEVEL III (CASP, CISA, CISSP, GCED, or GCIH)
- 8+ years of experience with the following:
- QualysGuard
- Rapid7
- NIST 800-53
- Security Technical Implement Guide (STIGS)
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
Information for applicants with a need for accommodation: https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html
group id: 10106525c