Information System Security Engineer (ISSE) Manager
Job Description
Deloitte’s Government & Public Services (GPS) Cyber team helps federal, state, and local organizations strengthen cyber programs and deliver measurable outcomes. In this onsite role in Rosslyn, VA, you will lead security engineering efforts that support system authorization activities, STIG compliance, and security documentation used for authorization decisions.
As an Information System Security Engineer (ISSE) Manager, you will design, build, and integrate security capabilities across information systems, applications, and cloud architectures, while driving remediation based on security maturity assessments. The work aligns with the broader Cyber Strategy & Transformation offering, which supports governance, risk assessments, and improved confidence in an organization’s cyber posture.
What you’ll do
- Design, build, and integrate security capabilities into information systems, applications, and cloud architectures
- Lead system architecture work and Security Technical Implementation Guide (STIG) compliance efforts
- Support Authorization to Operate (ATO) activities across IT and Operational Technology systems, including development of security documentation and implementation of controls
- Develop and maintain security engineering artifacts and compliance evidence to support authorization decisions and ongoing security requirements
- Assess security maturity, identify architecture and control gaps, and drive remediation actions with stakeholders
- Collaborate with systems engineers, architects, compliance teams, and client stakeholders to resolve technical security issues and strengthen operational resilience
Required qualifications
- Bachelor’s degree
- Legally authorized to work in the United States without employer sponsorship, now or in the future
- Active Top Secret (SCI Eligibility) security clearance required
- Ability to work onsite 5 days a week at the client site in Washington, D.C.
- 12+ years of experience supporting U.S. Department of Defense (DoD) or Federal Government information systems, including:
- Information security engineering
- System or application design and architecture
- Application security
- Security architecture
- Experience implementing STIGs for information systems
- Hold one of the following certifications: CRISC or CISSP
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced, dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
Technologies and frameworks you’ll work with
- FedRAMP
- Security Technical Implementation Guide (STIG)
- Authorization to Operate (ATO)
- Risk Management Framework (RMF)
- Assessment and Authorization (A&A)
- National Institute of Standards and Technology (NIST) RMF
- Governance, risk and compliance (GRC) tools such as JCAM and OpenRMF
- U.S. Department of Defense (DoD)
- Operational Technology
- Information Systems Security Engineer (ISSE)
Team focus
- Deloitte’s GPS practice supports federal, state, and local government clients and public higher education institutions
- The Cyber Strategy & Transformation offering develops and transforms cyber programs aligned to a client’s strategic objectives, regulatory requirements, and risk appetite
- Work includes design of the cyber organization, governance, and risk assessments
- Includes the Project Delivery Talent Model for professionals with specialized skills tied to a current client need
Compensation
Rosslyn, VA / Virginia compensation range estimate: USD 137,500 to $278,300 per year (Deloitte required estimate for individuals assigned and/or hired to work in Virginia).
Incentive program
You may also be eligible to participate in a discretionary annual incentive program, subject to program rules, where any award depends on individual and organizational performance.