Posted today
Top Secret
Unspecified
No Traveling
Polygraph
Management
Saint Louis, MO (On-Site/Office)•Richmond, VA (On-Site/Office)
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
Work You'll Do:
Our team, within Cyber Division, performs IV&V functions for infrastructure and applications / cybersecurity WAN risk assessments. JCIP Technical Reviewers play a pivotal role in evaluating the cybersecurity posture of enterprise environments across the Intelligence Community (IC). They conduct comprehensive technical assessments and perform detailed analysis of vulnerability scans to ensure compliance with Intelligence Community Directives (ICDs), IC Technical Implementation Guides (TIGs), Security Technical Implementation Guides (STIGs), Security Requirement Guides (SRGs), and NIST 800-53 rev 5 security controls. OTHER: Conduct thorough technical assessments and manual audits of host-based security controls across enterprise endpoints, servers, and workstations within Intelligence Community (IC) environments.
Knowledge:
The Team
Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.
Our Enterprise Security offering embeds security in all aspects of digital transformation by securing a client's technical backbone while enabling secure digital transformation. Includes security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected products.
The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals.
Qualifications
Required:
Information for applicants with a need for accommodation: https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html

Work You'll Do:
Our team, within Cyber Division, performs IV&V functions for infrastructure and applications / cybersecurity WAN risk assessments. JCIP Technical Reviewers play a pivotal role in evaluating the cybersecurity posture of enterprise environments across the Intelligence Community (IC). They conduct comprehensive technical assessments and perform detailed analysis of vulnerability scans to ensure compliance with Intelligence Community Directives (ICDs), IC Technical Implementation Guides (TIGs), Security Technical Implementation Guides (STIGs), Security Requirement Guides (SRGs), and NIST 800-53 rev 5 security controls. OTHER: Conduct thorough technical assessments and manual audits of host-based security controls across enterprise endpoints, servers, and workstations within Intelligence Community (IC) environments.
- Analyze system configurations, host-based firewalls, endpoint detection and response (EDR) tools, antivirus/antimalware solutions, and application whitelisting to ensure compliance with IC Directives and STIG requirements.
- Evaluate compliance with IC Technical Implementation Guides (TIGs), Security Technical Implementation Guides (STIGs), Security Requirement Guides (SRGs), and applicable NIST 800-53 Rev 5 controls relevant to host-based security.
- Independently perform manual checklist reviews of host security settings and controls; identify vulnerabilities, risks, and recommend mitigations.
- Engage with system administrators, endpoint security teams, and leadership to clarify findings, provide risk assessments, and coordinate remediation efforts.
- Lead and mentor Level 1 IDRs in host-based security tasks and inspections.
- Stay current on emerging host security threats, vulnerabilities, and mitigation strategies including zero-day exploits, advanced persistent threats (APTs), and endpoint hardening techniques.
- Participate in planning, execution, and reporting phases of inspections with minimal oversight; prepare clear and concise technical reports and presentations.
- Travel as necessary to support onsite inspections at IC facilities. (8-12 weeks of travel avg, some international and passport required).
Knowledge:
- Deep understanding of endpoint security technologies including EDR, antivirus, host-based firewalls, application whitelisting, and system hardening best practices.
- Familiarity with common host OS platforms (Windows, UNIX/Linux) and their security architectures.
- Proficient in interpreting and applying STIGs, SRGs, and NIST 800-53/800-171 controls related to host security.
The Team
Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.
Our Enterprise Security offering embeds security in all aspects of digital transformation by securing a client's technical backbone while enabling secure digital transformation. Includes security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected products.
The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals.
Qualifications
Required:
- Bachelor's degree + 13 years of experience OR Master's Degree with 5+ years of experience
- Active Top Secret/SCI clearance with a CI Poly
- Ability to travel 25%, on average, based on the work you do and the clients and industries/sectors you serve
- Local to St. Louis, Missouri or Norfolk, VA area and able to come onsite 5 days a week.
- IAT LEVEL III (CASP, CISA, CISSP, GCED, or GCIH)
- 8+ years of experience with the following:
- Endpoint Protection
- OS Windows
- OS Linux
- Security Technical Implement Guide (STIGS)
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
Information for applicants with a need for accommodation: https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html
group id: 10106525c