ISSO, Senior Consultant

PowerToFly

United States

On-site

USD 108,000 - 180,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Deloitte's Government & Public Services (GPS) cyber risk team seeks a Project - Security Engineer III to support RMF ATO processes, implement security controls, and coordinate with cross-functional federal client teams. You will help manage eMASS, assess vulnerabilities, and drive remediation efforts in a fast-paced environment.

Requires a TS/SCI clearance, Bachelor's degree, and onsite work in Rosslyn, VA with travel. Strong communication and leadership skills are essential for success.

Qualifications

  • Bachelor's degree required.
  • US work authorization with TS/SCI clearance.
  • Onsite work in Rosslyn, VA 4 days/week; travel ~25%.
  • At least 3 years in RMF security engineering and ATO processes.
  • Experience with RMF lifecycle, eMASS, and vulnerability remediation.
  • Experience with ACAS/Tenable scans and vulnerability tracking.
  • Preferred: POA&Ms, ST&E, third-party audits, NIST 800-53, RMF lifecycle, STIGs/SCAP/SCC, Splunk log reviews, sysadmin background.

Responsibilities

  • Provide end-to-end RMF ATO support for cybersecurity, privacy, and financial controls.
  • Interpret risk posture and recommend approaches to meet guidance and requirements.
  • Map, implement, interpret, and document RMF security controls across networks and information systems.
  • Manage eMASS activities, supporting vulnerability identification via ACAS/Tenable scans and remediation tracking.
  • Support monitoring, detection, investigation, and remediation through log reviews and audit support.

Skills

Team collaboration
Communication
Attention to detail
Relationship building
Project leadership
Multitasking
Interpersonal skills
Deadline oriented
Mentoring

Education

Bachelor's degree

Tools

eMASS
ACAS
Tenable
SCAP
SCC
Splunk

Job description

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Work You'll Do

As a PROJECT - Security Engineer III on the Cyber Risk and Compliance team, you will be responsible for:

  • Providing end-to-end Assessment and Authorization support for cybersecurity, privacy, and financial controls implementation, testing, monitoring, and enforcement
  • Interpreting risk posture and recommending approaches to meet Joint Special Access Program Implementation Guide, Department of Defense, and applicable control requirements
  • Mapping, implementing, interpreting, and documenting Risk Management Framework security controls across networks, enclaves, and information system
  • Managing eMASS activities, supporting vulnerability identification through ACAS/Tenable scans, and tracking remediation and mitigation efforts
  • Supporting monitoring, detection, investigation, and remediation activities through log review, security testing, authorization package development, and audit support

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others
The Team

Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.

Our Cyber Strategy & Transformation offering develops and transforms cyber programs in line with a client's strategic objectives, regulatory requirements, and risk appetite. It keeps the enterprise a step ahead of the evolving threat landscape and gives stakeholders confidence in the organization's cyber posture. Includes design of the cyber organization, governance, and risk assessments.

The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals.

Qualifications

Required:

  • Bachelor's degree
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
  • Active TS/SCI security clearance required
  • Ability to work onsite in Rosslyn, Virginia at least 4 days per week and reside within commuting distance of the office
  • Ability to travel 25%, on average, based on the work you do and the clients and industries/sectors you serve
  • 3+ Years of Experience with:
    • RMF and security engineering
    • Supporting the full RMF lifecycle and federal Assessment and Authorization process, including mapping, implementing, interpreting, and documenting RMF security controls
    • Experience managing eMASS cybersecurity management tooling and developing and submitting at least two (2) Authorization to Operate packages
    • generating and interpreting ACAS/Tenable scans, identifying vulnerabilities, and tracking remediation and mitigation efforts

Preferred:

  • Experience managing POA&Ms, conducting Security Tests and Evaluations (ST&E), and creating system security documentation
  • Experience performing authorizations, risk assessments, and supporting third-party audits
  • Experience ensuring compliance with NIST Special Publication 800-53 and performing threat assessments aligned with RMF lifecycle processes
  • Experience with manual STIGs, Security Content Automation Protocol (SCAP), and SCAP Compliance Checker (SCC)
  • Experience conducting Splunk log reviews to support monitoring, detection, investigation, and remediation of security events and potential vulnerabilities
  • Prior technical experience as a system or network administrator

For individuals assigned and/or hired to work in Virginia, Deloitte is required by law to include a reasonable estimate of the compensation range for this role. This compensation range is specific to Virginia and takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $107,700 to $179,500.

  • You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ISSO, Senior Consultant
ISSO, Senior Consultant

Relha LLC • Virginia (IL), Northern (KY)

Hybrid
USD 108,000 - 180,000
ISSO, Senior Consultant
ISSO, Senior Consultant

Relha LLC • United States

On-site
USD 108,000 - 180,000
IT Management Senior Consultant
IT Management Senior Consultant

Relha LLC • Suffolk (VA)

On-site
USD 103,000 - 171,000
Annual incentive program
Cyber Supply Chain & Industrial Control Subject Matter Expert I
Cyber Supply Chain & Industrial Control Subject Matter Expert I

PowerToFly • Virginia (IL)

On-site
USD 131,000 - 218,000
Cyber Management Consultant II, Senior Consultant
Cyber Management Consultant II, Senior Consultant

Relha LLC • Washington, Northern (KY)

On-site
USD 131,000 - 218,000
Security Analyst
Security Analyst

Relha LLC • Herndon (VA)

Hybrid
USD 113,000 - 188,000
Security Engineer III, Splunk Content Engineer (Secret Clearance)
Security Engineer III, Splunk Content Engineer (Secret Clearance)

Relha LLC • Herndon (VA)

Hybrid
USD 113,000 - 188,000
Security Engineer III, Splunk Content Engineer (Secret Clearance)
Security Engineer III, Splunk Content Engineer (Secret Clearance)

Relha LLC • Virginia (IL), Northern (KY)

Hybrid
USD 113,000 - 188,000
Discretionary annual incentive
Cyber Supply Chain & Industrial Control Subject Matter Expert I
Cyber Supply Chain & Industrial Control Subject Matter Expert I

Relha LLC • Washington, Northern (KY)

On-site
USD 131,000 - 218,000
Project Cyber Engineer
Project Cyber Engineer

Relha LLC • Colorado Springs (CO), Northern (KY)

Hybrid
USD 96,000 - 159,000