Cyber Manager - Cloud DevSecOps at Deloitte
Denver, CO
$134,500–$265,100from the description
Aug 19, 2026
Denver, CO
Sep 25, 2026
What this job asks for AI summary
A consulting manager role at Deloitte leading client engagements in DevSecOps, Application Security, and Secure SDLC transformation across cloud and modern engineering environments. The position combines hands-on technical direction — designing secure CI/CD pipelines, AI-enabled security automation, and software supply chain controls — with people management, business development, and executive stakeholder engagement. Suited to an experienced cybersecurity professional with a consulting background who can own delivery end-to-end across distributed teams.
Senior level · 6+ years · Bachelor's required · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $178,991 (middle half $141,096–$225,584). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 20, 2026. It is a model, not a headcount.
Why we read it this way (10)
The title 'Manager' carries no seniority level word (Junior/Senior/Staff/etc.), so advertised seniority is Unspecified. The actual requirements — 6+ years of experience, 3+ years of team management, P&L/budget accountability, and client-facing consulting delivery — support a Senior classification.
SOC classification is a genuine judgment call: the role has substantial people-management and business-development duties (pointing to 11-3021 Computer and Information Systems Managers), but the day-to-day delivery work is deeply technical security consulting (pointing to 15-1212 Information Security Analysts). 11-3021 was chosen because the JD explicitly gates on managing teams, budget oversight, and staffing accountability as hard requirements.
The CI/CD + AppSec tools requirement (SAST, DAST, SCA, secrets scanning, IaC scanning, container security, API security, threat modeling, vulnerability management) is stated as 'at least 3 of the following' — the JD does not require all of them. They are captured as a single skill with alternatives to reflect this interchangeability.
The cybersecurity frameworks requirement (NIST CSF, NIST SP 800-53, NIST SSDF, OWASP SAMM, ISO 27001) is stated as 'at least 2' — captured as a single skill with alternatives.
Cloud platform experience (AWS, Azure, GCP) or Kubernetes/containers is stated as 'at least 1 major cloud platform OR technologies such as Kubernetes and containers' — captured as AWS with alternatives and Kubernetes as a separate skill to reflect both paths.
AI security capabilities (Generative AI, Agentic AI, AI-assisted vulnerability management) appear under Preferred Qualifications.
Software supply chain security capabilities (SBOM, SLSA, code signing, etc.) appear under Preferred Qualifications.
Certifications (CISSP, CCSP, etc.) appear under Preferred Qualifications.
Analytics/reporting platforms (Power BI, Tableau) appear under Preferred Qualifications.
Regulatory/compliance frameworks (ISO 27001/27017, SOC 2, PCI DSS, HIPAA, SOX, GLBA) appear under Preferred Qualifications.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.