Function as the primary day-to-day client interface, building rapport and driving outcomes across Engineering, Security, Risk/Compliance, and Operations. * Assist in business development (scope ...
Function as the primary day-to-day client interface, building rapport and driving outcomes across Engineering, Security, Risk/Compliance, and Operations. * Assist in business development (scope ...
Security Coordinator
Hodgkins, IL · On-site
$61K - $74K/yr
Security Risk Management * Conduct regular security audits and risk assessments to identify ... Ensure compliance with C-TPAT, OEA, and other relevant supply chain security standards and ...
Security Coordinator
Hodgkins, IL · On-site
$61K - $74K/yr
Security Risk Management * Conduct regular security audits and risk assessments to identify ... Ensure compliance with C-TPAT, OEA, and other relevant supply chain security standards and ...
Security Risk Management * Conduct regular security audits and risk assessments to identify ... Ensure compliance with C-TPAT, OEA, and other relevant supply chain security standards and ...
Security Risk Management * Conduct regular security audits and risk assessments to identify ... Ensure compliance with C-TPAT, OEA, and other relevant supply chain security standards and ...
They excel in risk management, regulatory compliance, and driving operational excellence within ... S. Department of Homeland Security E-Verify program in all facilities located in the United States ...
They excel in risk management, regulatory compliance, and driving operational excellence within ... S. Department of Homeland Security E-Verify program in all facilities located in the United States ...
Third Party Risk Manager
Chicago, IL · On-site
... information security, compliance, operational risk, privacy, and broader TPRM practices. The ... position will work within a Crowe team at a client or third-party site and be responsible for ...
Third Party Risk Manager
Chicago, IL · On-site
... information security, compliance, operational risk, privacy, and broader TPRM practices. The ... position will work within a Crowe team at a client or third-party site and be responsible for ...
They excel in risk management, regulatory compliance, and driving operational excellence within ... S. Department of Homeland Security E-Verify program in all facilities located in the United States ...
They excel in risk management, regulatory compliance, and driving operational excellence within ... S. Department of Homeland Security E-Verify program in all facilities located in the United States ...
Documenting information security risk and compliance findings, presenting recommendations for remediation, and communicating results to client leadership * Performing quality assurance reviews of ...
Documenting information security risk and compliance findings, presenting recommendations for remediation, and communicating results to client leadership * Performing quality assurance reviews of ...
Be Seen First
Security Operations Coordinator
Hodgkins, IL · On-site
$61K - $74K/yr
Security Risk Management * * Conduct regular security audits and risk assessments to identify ... Ensure compliance with C-TPAT, OEA, and other relevant supply chain security standards and ...
Quick apply
Be Seen First
Security Operations Coordinator
Hodgkins, IL · On-site
$61K - $74K/yr
Security Risk Management * * Conduct regular security audits and risk assessments to identify ... Ensure compliance with C-TPAT, OEA, and other relevant supply chain security standards and ...
The role partners closely with engineering, architecture, security, risk, compliance, and platform teams to enable high-performance cloud-native solutions and guide critical decisions as Early ...
The role partners closely with engineering, architecture, security, risk, compliance, and platform teams to enable high-performance cloud-native solutions and guide critical decisions as Early ...
... security risk assessments with cross-functional stakeholders. * Supports SOX-relevant logistics ... Tracks/analyzes trade compliance KPIs and findings; and tariff/geopolitical impact assessments.
... security risk assessments with cross-functional stakeholders. * Supports SOX-relevant logistics ... Tracks/analyzes trade compliance KPIs and findings; and tariff/geopolitical impact assessments.
SOX Compliance Analyst
Chicago, IL · Hybrid
$50 - $60/hr
Partner with Internal Audit, Information Security, Risk Management, and Technology teams to support audit and regulatory requests. * Maintain accurate compliance documentation, metrics reporting ...
SOX Compliance Analyst
Chicago, IL · Hybrid
$50 - $60/hr
Partner with Internal Audit, Information Security, Risk Management, and Technology teams to support audit and regulatory requests. * Maintain accurate compliance documentation, metrics reporting ...
IT Compliance Auditor
Chicago, IL · Hybrid
$96K - $97K/yr
Partner with Internal Audit, Information Security, Risk Management, and Technology teams to support audit and regulatory requests. * Maintain accurate compliance documentation, metrics reporting ...
IT Compliance Auditor
Chicago, IL · Hybrid
$96K - $97K/yr
Partner with Internal Audit, Information Security, Risk Management, and Technology teams to support audit and regulatory requests. * Maintain accurate compliance documentation, metrics reporting ...
You will drive integrity across client engagements and internal initiatives while leveraging deep securities industry expertise to support litigation, compliance assessments, and risk mitigation ...
You will drive integrity across client engagements and internal initiatives while leveraging deep securities industry expertise to support litigation, compliance assessments, and risk mitigation ...
You will drive integrity across client engagements and internal initiatives while leveraging deep securities industry expertise to support litigation, compliance assessments, and risk mitigation ...
You will drive integrity across client engagements and internal initiatives while leveraging deep securities industry expertise to support litigation, compliance assessments, and risk mitigation ...
You will drive integrity across client engagements and internal initiatives while leveraging deep securities industry expertise to support litigation, compliance assessments, and risk mitigation ...
You will drive integrity across client engagements and internal initiatives while leveraging deep securities industry expertise to support litigation, compliance assessments, and risk mitigation ...
Director of Risk Management and Compliance
Chicago, IL · On-site
$80K - $85K/yr
Risk Manager is responsible for supporting the development, implementation, and ongoing oversight ... Security Compliance * Participate in monitoring compliance with HIPAA Privacy, Security, and Breach ...
Director of Risk Management and Compliance
Chicago, IL · On-site
$80K - $85K/yr
Risk Manager is responsible for supporting the development, implementation, and ongoing oversight ... Security Compliance * Participate in monitoring compliance with HIPAA Privacy, Security, and Breach ...
You will drive integrity across client engagements and internal initiatives while leveraging deep securities industry expertise to support litigation, compliance assessments, and risk mitigation ...
You will drive integrity across client engagements and internal initiatives while leveraging deep securities industry expertise to support litigation, compliance assessments, and risk mitigation ...
Documenting information security risk and compliance findings and recommendations for remediation * Perform quality assurance and review of assessments performed by other team members * Delivering ...
Documenting information security risk and compliance findings and recommendations for remediation * Perform quality assurance and review of assessments performed by other team members * Delivering ...
Documenting information security risk and compliance findings and recommendations for remediation * Perform quality assurance and review of assessments performed by other team members * Delivering ...
Documenting information security risk and compliance findings and recommendations for remediation * Perform quality assurance and review of assessments performed by other team members * Delivering ...
Strong executive presence and ability to engage C-level stakeholders across IT, Security, Risk/Compliance, Digital, and line-of-business functions * Highly organized operator with excellent territory ...
Strong executive presence and ability to engage C-level stakeholders across IT, Security, Risk/Compliance, Digital, and line-of-business functions * Highly organized operator with excellent territory ...
Security Risk Compliance information
See Romeoville, IL salary details
$33.1K - $41.6K
6% of jobs
$41.6K - $50K
0% of jobs
$50K - $58.4K
6% of jobs
$64.5K is the 25th percentile. Wages below this are outliers.
$58.4K - $66.9K
17% of jobs
The median wage is $74.9K / yr.
$66.9K - $75.3K
21% of jobs
$75.3K - $83.7K
7% of jobs
$83.7K - $92.2K
9% of jobs
$92.2K - $100.6K
7% of jobs
$101K is the 75th percentile. Wages above this are outliers.
$100.6K - $109.1K
12% of jobs
$109.1K - $117.5K
6% of jobs
$117.5K - $125.9K
7% of jobs
$33.1K
$82.7K
$125.9K
How much do security risk compliance jobs pay per year?
What is the difference between Security Risk Compliance vs Security Analyst?
| Aspect | Security Risk Compliance | Security Analyst |
|---|---|---|
| Certifications | ISO 27001 Lead Implementer, CISSP, CISA | CISSP, CompTIA Security+, GIAC Security Certifications |
| Work Environment | Policy development, compliance audits, risk assessments | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Financial, healthcare, government sectors focusing on regulatory adherence | IT departments across various industries focusing on security operations |
Security Risk Compliance professionals focus on ensuring organizations meet regulatory standards and manage security risks through policies and audits. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within similar environments, their core responsibilities differ: compliance versus active security monitoring.
What are some common challenges faced by Security Risk Compliance professionals when balancing regulatory requirements with business objectives?
What are the key skills and qualifications needed to thrive as a Security Risk Compliance professional, and why are they important?
What is Security Risk Compliance?
Deloitte rating
8.1
Based on 86 frontline employees who took The Breakroom Quiz
58th of 138 rated financial services
Job description
Cloud Security - DevSecOps Manager
Position Summary
Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to both secure and support technology innovation required by the business. Join Deloitte's Cloud Cyber Services team and become a member of the largest group of cybersecurity professionals worldwide.
Recruiting for this role will end on 6/30/2026
Work you'll do
As a DevSecOps Security(Manager), you will lead client engagements that define, operationalize, and scale secure-by-design software delivery in cloud-agnostic environments. Responsibilities include:
- Lead delivery of DevSecOps / Secure SDLC programs as a project manager and/or architect, overseeing onsite/offshore teams across governance, identity, application security, platform/infrastructure security, monitoring, resilience, and data protection.
- Design and implement Secure by Design / security engagement intake workflows that streamline how engineering teams initiate governance/security processes (e.g., rationalizing questionnaires, automating routing/approvals, reducing cycle time).
- Build or tailor controls frameworks and control mappings (e.g., aligned to NIST 800-53 and enterprise policies/standards) and translate them into actionable engineering requirements and measurable outcomes.
- Conduct DevSecOps current-state assessments (people/process/technology), facilitate leading-practices workshops, and produce multi-year roadmaps with sequenced initiatives, resourcing, and cost estimates.
- Define DevSecOps operating model options (team structure, service catalog, intake, RACI, governance forums) and drive executive decision-making on the target approach.
- Embed security into CI/CD and SDLC workflows (requirements, design, build, test, deploy, operate) including security controls, evidence capture, and release/go-live governance.
- Advance software supply chain security (e.g., dependency risk, artifact integrity, code signing, PKI/HSM considerations) and guide implementation patterns appropriate to client context.
- Support container and runtime security assessments and backlog acceleration; help teams prioritize security work without stalling delivery.
- Define metrics, reporting, and dashboards (e.g., delivery throughput, control compliance, intake cycle time, risk burndown, vulnerability trends) to improve transparency and accountability.
- Function as the primary day-to-day client interface, building rapport and driving outcomes across Engineering, Security, Risk/Compliance, and Operations.
- Assist in business development (scope, estimates, pricing, proposals) and contribute to eminence (POVs/whitepapers) and internal enablement
The team
Deloitte's Cyber Cloud team helps complex organizations more confidently pursue their growth, innovation and performance agendas through proactive management of the associated cyber risks. Our professionals provide advisory and implementation services that integrate risk, regulatory, and technology skills to help clients transform their legacy programs into proactive Secure.Vigilant.Resilient.TM cyber risk programs. Join the team developing the future state of cyber risk solutions.
Required:
- 6+ years of experience in technical consulting, client problem solving, and delivery leadership.
- 2+ years designing or leading DevSecOps / Secure SDLC programs (assessment, roadmap, operating model, and implementation oversight).
- Experience translating policy/standards into engineering-ready controls and workflows; familiarity with security control frameworks (e.g., NIST CSF and/or NIST 800-53).
- Experience with automation/workflow platforms (e.g., ServiceNow or similar) to support security intake, governance, and evidence collection.
- Experience with application security and modern engineering ecosystems (CI/CD concepts, containers, SDLC tooling).
- BA/BS degree preferably in a technical field.
- Ability to travel up to 80%, on average, based on the work you do and the clients and industries/sectors you serve
- Locations include: Houston, Dallas, Cleveland, Detroit, St. Louis, Pittsburgh, Boston, Charlotte, Atlanta, Miami, Memphis, Denver, Phoenix, Salt Lake City, Los Angeles, San Diego, San Franciso, Seattle. Must be within a reasonable commute and willing to work part-time in the Deloitte and/or client offices.
Preferred:
- Previous consulting or Big 4 experience.
- Certifications (e.g., CCSP or comparable); familiarity with industry maturity models (e.g., OWASP SAMM, BSIMM) and/or supply chain frameworks (e.g., SLSA).
- Experience with code signing/PKI concepts and security tooling ecosystems; experience with dashboarding/analytics (e.g., Power BI) a plus.
- Understanding of regulatory/compliance requirements (e.g., ISO 27001/27017, SOC 2, PCI, HIPAA, SOX, GLBA, NIST 800-53).
'Information for applicants with a need for accommodation: https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $144,200 to $265,600
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberES27
Cloud Security - DevSecOps Manager
Position Summary
Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to both secure and support technology innovation required by the business. Join Deloitte's Cloud Cyber Services team and become a member of the largest group of cybersecurity professionals worldwide.
Recruiting for this role will end on 6/30/2026
Work you'll do
As a DevSecOps Security(Manager), you will lead client engagements that define, operationalize, and scale secure-by-design software delivery in cloud-agnostic environments. Responsibilities include:
- Lead delivery of DevSecOps / Secure SDLC programs as a project manager and/or architect, overseeing onsite/offshore teams across governance, identity, application security, platform/infrastructure security, monitoring, resilience, and data protection.
- Design and implement Secure by Design / security engagement intake workflows that streamline how engineering teams initiate governance/security processes (e.g., rationalizing questionnaires, automating routing/approvals, reducing cycle time).
- Build or tailor controls frameworks and control mappings (e.g., aligned to NIST 800-53 and enterprise policies/standards) and translate them into actionable engineering requirements and measurable outcomes.
- Conduct DevSecOps current-state assessments (people/process/technology), facilitate leading-practices workshops, and produce multi-year roadmaps with sequenced initiatives, resourcing, and cost estimates.
- Define DevSecOps operating model options (team structure, service catalog, intake, RACI, governance forums) and drive executive decision-making on the target approach.
- Embed security into CI/CD and SDLC workflows (requirements, design, build, test, deploy, operate) including security controls, evidence capture, and release/go-live governance.
- Advance software supply chain security (e.g., dependency risk, artifact integrity, code signing, PKI/HSM considerations) and guide implementation patterns appropriate to client context.
- Support container and runtime security assessments and backlog acceleration; help teams prioritize security work without stalling delivery.
- Define metrics, reporting, and dashboards (e.g., delivery throughput, control compliance, intake cycle time, risk burndown, vulnerability trends) to improve transparency and accountability.
- Function as the primary day-to-day client interface, building rapport and driving outcomes across Engineering, Security, Risk/Compliance, and Operations.
- Assist in business development (scope, estimates, pricing, proposals) and contribute to eminence (POVs/whitepapers) and internal enablement
The team
Deloitte's Cyber Cloud team helps complex organizations more confidently pursue their growth, innovation and performance agendas through proactive management of the associated cyber risks. Our professionals provide advisory and implementation services that integrate risk, regulatory, and technology skills to help clients transform their legacy programs into proactive Secure.Vigilant.Resilient.TM cyber risk programs. Join the team developing the future state of cyber risk solutions.
Required:
- 6+ years of experience in technical consulting, client problem solving, and delivery leadership.
- 2+ years designing or leading DevSecOps / Secure SDLC programs (assessment, roadmap, operating model, and implementation oversight).
- Experience translating policy/standards into engineering-ready controls and workflows; familiarity with security control frameworks (e.g., NIST CSF and/or NIST 800-53).
- Experience with automation/workflow platforms (e.g., ServiceNow or similar) to support security intake, governance, and evidence collection.
- Experience with application security and modern engineering ecosystems (CI/CD concepts, containers, SDLC tooling).
- BA/BS degree preferably in a technical field.
- Ability to travel up to 80%, on average, based on the work you do and the clients and industries/sectors you serve
- Locations include: Houston, Dallas, Cleveland, Detroit, St. Louis, Pittsburgh, Boston, Charlotte, Atlanta, Miami, Memphis, Denver, Phoenix, Salt Lake City, Los Angeles, San Diego, San Franciso, Seattle. Must be within a reasonable commute and willing to work part-time in the Deloitte and/or client offices.
Preferred:
- Previous consulting or Big 4 experience.
- Certifications (e.g., CCSP or comparable); familiarity with industry maturity models (e.g., OWASP SAMM, BSIMM) and/or supply chain frameworks (e.g., SLSA).
- Experience with code signing/PKI concepts and security tooling ecosystems; experience with dashboarding/analytics (e.g., Power BI) a plus.
- Understanding of regulatory/compliance requirements (e.g., ISO 27001/27017, SOC 2, PCI, HIPAA, SOX, GLBA, NIST 800-53).
'Information for applicants with a need for accommodation: https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $144,200 to $265,600
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberES27