Deloitte Jobs

Job Information

Deloitte Hybrid-Operate Cyber Service Delivery Manager in Pittsburgh, Pennsylvania

Service Delivery Manager: Hybrid-Operate Cyber Risk Services

Unanticipated risks have great consequences for clients. That's especially true today as new risks and complexities brought on by regulatory mandates, rapidly evolving technologies, and the digitalization of business operations are disrupting traditional business models. Deloitte Risk and Financial Advisory's Hybrid-Operate teams deliver next-generation managed services and advanced technology products to help organizations solve complex problems on a long-term basis. Teams do this by bringing together advanced analytics, robust domain knowledge and experience, and strong technology products to help clients monitor, manage, and measure their operational environment for risk.

Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. We collaborate with teams from across our organization that are client focused and mission driven. As a Service Delivery Manager, you will work with our diverse teams of passionate and expert professionals to help solve for some of today's toughest cybersecurity and organizational challenges to enable or clients to enable achieve business growth and continue to manage evolving risk.

In your role as a Service Delivery Manager, you will be the helping our clients with run their end-to-end cyber operations to effectively prevent, detect, and remediate known and unknown attacks that potentially disrupt their business. You should possess a deep understanding of various security threats and attacks, and their detection, and mitigation options. An exposure of working across multiple cyber domains, including but not limited to Security Operations & Incident Response, Network and Endpoint Security, Threat and Vulnerability Management, Identity & Access Management etc., is an important qualification for this role.

Key expectations from this role includes -

  • Increasing maturity of key cyber operations capabilities across service governance, processes, and technology to help our clients achieve integrated cyber defense and service delivery efficiency

  • Providing Deloitte's perspective on effective approaches to cyber capability development and service operations, and collaborating with client stakeholders on implementation roadmaps and execution

  • Leading the development of actionable use cases to detect, triage, investigate and remediate based on latest threat actor trends, including actual technical implementation of parsing log sources creating, validating, and testing alerting queries to reduce false positives.

  • Building enduring client relationships, ensure client satisfaction and expanding the footprint of our cyber business

  • Adopting a pragmatic approach to dealing with situations where confidentiality is important or where our work is of a sensitive nature. Helping maintain our client's strong professional relationships is integral to our business.

    For individuals assigned and/or hired to work in New York City or Jersey City, Deloitte is required by law to include a reasonable estimate of the compensation range for this role. This compensation range is specific to New York City, Jersey City and takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $170,980 - $213,725.

    Work you will do

  • Act as a service delivery lead and trusted advisor for the client through effective and efficient delivery of cyber operations services

  • Lead multiple, cross region teams to deliver complex cyber operation engagements for global clients

  • Maintain operational oversight on service delivery activities in the engagement environment including but not limited to, security incidents, service requests, tuning recommendations, change requests, and ad hoc requests

  • Responsible for overall adherence and reporting of contracted Service Level Agreements (SLAs) with the client

  • Implement and enhance service management processes and governance to improve the service delivery quality

  • Identify and recommend operational improvements to the client, drawing on deep experience and industry specific knowledge of risks

  • Understand and leverage various technologies and product capabilities across the gamut of cyber services that best serve the client's needs

  • Responsible for development and delivery of periodic operational reports and operational status

  • Assist with the design and implementation of cyber operating models

  • Display leadership and business judgment in anticipating client needs and developing alternative solutions

  • Track and communicate engagement performance and planning to Deloitte engagement management and escalate risks as appropriate

  • Provide mentoring/counseling/coaching, oversight, and support for delivery teams and staff

  • Participate actively in staff recruitment and retention activities, providing input and guidance into the staffing process

  • Participate and lead aspects of the proposal development process

    The successful candidate will possess:

  • Excellent communication, listening & facilitation skills

  • Demonstrated consulting skills (client service orientation, conflict resolution, analysis/synthesis of information, negotiation, project management, etc.)

  • Proven leadership skills demonstrating strong judgment, problem-solving, and decision-making abilities

  • Experience managing client relationships

  • Experience mentoring and coaching others

    Required Qualifications

  • 8+ year of cybersecurity work experience with at least two of in any of the following cybersecurity disciplines: Cyber Fusion Center, Security Operations Center, Cloud Security (AWS/Azure), Network Security Operations, Endpoint Security, Incident Response, Forensics, Threat Intelligence, Vulnerability Management

  • Bachelor of Science/Business Administration with a concentration in computer science, information systems, information security, math, decision sciences, risk management, engineering (mechanical, electrical, industrial) or equivalent work experience

  • In depth knowledge of general security concepts, such as defense-in-depth, least privilege, security architecture and design, threat modeling, etc.

  • Experience with IT Service Management (ITSM) tools, workflow, and automation (e.g., Service NOW)

  • Rich experience in any of the following cybersecurity technologies: SIEM technology (e.g., Splunk, IBM QRadar, Microsoft Sentinel, etc.), Threat Vulnerability Management, SOC Operations, NextGen Firewalls, IDS/IPS, Data Loss Prevention (DLP), Proxy, Web Application Firewall (WAF), Endpoint detection and response (EDR), Threat Intelligence, Application Penetration Testing, Advanced Persistent Threats (APT)

  • Experience extending enterprise security controls to the cloud (AWS/Azure)

  • Certifications; CISSP / CCSP / AWS certified solution architect or security specialty / OSCP / GIAC/ GMON

  • Pre-sales, proposal, and RFP experience

  • Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve

  • Limited immigration sponsorship may be available


  • Previous consulting or cyber operations experience

  • Master's degree in Cybersecurity, Information Assurance, or related field

  • Demonstrable personal interest in computing, security, and digital communication


All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.