Deloitte Jobs

Job Information

Deloitte Security Control Assessor in Washington, District Of Columbia

Are you looking to elevate your cyber career? Your technical skills? Your opportunity for growth? Deloitte's Government and Public Services Cyber Practice (GPS Cyber Practice) is the place for you! Our GPS Cyber Practice helps organizations create a cyber minded culture and become stronger, faster, and more innovative. You will become part of a team that advises, implements, and manages solutions across five verticals: Strategy, Defense and Response; Identity; Infrastructure; Data; and Application Security. Our dynamic team offers opportunities to work with cutting-edge cyber security tools, and grow both vertically and horizontally at an accelerated rate. Join our cyber team and elevate your career.

Work you'll do

Security Controls Assessor performs security controls assessments (SCA) using NIST guidance in compliance with FISMA. Key responsibilities include:

  • Interviewing key stakeholders (developers, ISSOs, business POCs, etc.) to determine security controls implementation.

  • Executing security control assessment plan by following provided assessment procedures, collecting and analyzing evidence, and documenting steps taken and findings noted.

  • Updating System Security Plan with actual control implementation determined during assessment.

  • Developing Security Assessment Report for management staff providing residual risk statement, impact, and suggested corrective actions.

  • Reviewing vulnerability scans and Remediation

  • Implement risk management programs by utilizing NIST, FISMA, HIPAA, and PII.

  • Document complex technology, data protection, confidentiality, and data residency solutions.

  • Monitor the privacy landscape for regulatory changes surrounding data privacy, data protection, data confidentiality, data classification, and data residency.

  • Assist clients with identifying gaps within existing privacy programs and designing solutions to help address those challenges.

    The team

Deloitte's Government and Public Services (GPS) practice - our people, ideas, technology and outcomes-is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of more than 15,000 professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.

At Deloitte, we believe cyber is about starting things-not stopping them-and enabling the freedom to create a more secure future. Our Cyber Data team assists our clients in developing a better understanding of the personal, sensitive, and confidential information they collect, process, and share, along with the associated protection requirements. If you're seeking a career creating strategy, reporting and validation, architecture, privacy, and protection then the Cyber Data offering at Deloitte is for you.



  • Bachelor's degree required

  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future

  • Must be able to obtain and maintain the required clearance for this role.

  • Federal security test and evaluations

  • Understanding the Plan of Action and Milestones (POA&M) Management

  • System Change Management

  • Contingency Plan Creation, Documentation, Implementation, Testing, Maintenance

  • Interconnection Security Agreements, MOU, MOAs, Interface Connection Documents

  • IT Security Engineering Life Cycle and Release Management

  • Certification and Accreditation (C&A) / Security Assessment and Authorization (SA&A)

  • Knowledge of Security and Privacy controls noted in NIST 800-53.

  • Conducted Security Control Assessments

  • Strong attention to detail and have the ability to adjust their process in a moments notice


  • Hold at least one Data Protection and/or Privacy certification such as, CIPP, CIPT, ISEB, etc.

    All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.