Cyber - AWS Forward Deployed Security Engineer (FDE) - Senior Consultant

Deloitte
Deloitte

Austin, TX, USA · Houston, TX, USA · San Antonio, TX, USA · Fort Worth, TX, USA · Dallas, TX, USA

USD 134,500-265,100 / year

Posted on Aug 21, 2026

Position Summary

Join Deloitte’s Cloud Cyber Risk practice as a Forward Deployed Security Engineer and help organizations secure their Amazon Web Services (AWS) cloud and AI workloads at scale while working directly with client engineering teams. This is not an assessment-and-handoff role. You will design, build, deploy, and operate secure-by-default AWS environments and automated security controls across generative AI services, container and data platforms, infrastructure-as-code, and secure delivery pipelines. This role is designed for a hands-on engineer who enjoys solving complex cloud security challenges, building working automation, and supporting security outcomes in production environments.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As an Engineering and Product Engineer III on the Cloud Cyber Risk team, you will be responsible for:

  • Embed directly with client cloud and platform engineering teams to design, build, deploy, and operate automated security controls across AWS environments from initial design through production support.
  • Design and implement security guardrails for AWS generative artificial intelligence (AI) and machine learning services, including Amazon Bedrock, Amazon Bedrock AgentCore, and Amazon SageMaker, as well as containerized and serverless workloads on Amazon Elastic Kubernetes Service (EKS).
  • Build automated data protection and data loss prevention capabilities using Amazon Macie, AWS Key Management Service (KMS), and encryption and tokenization patterns across Amazon Simple Storage Service (S3), databases, and analytics platforms.
  • Deploy and maintain AWS-native security services, including AWS Security Hub, Amazon GuardDuty, AWS Config, AWS Identity and Access Management (IAM) Access Analyzer, and AWS CloudTrail, within client monitoring and security operations workflows.
  • Write and maintain production infrastructure-as-code using Terraform and/or AWS CloudFormation, integrate security scanning into continuous integration / continuous deployment (CI/CD) pipelines, and contribute reusable modules, runbooks, and reference implementations for future engagements.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

The team

Deloitte’s Cloud Cyber Risk team helps organizations pursue growth, innovation, and performance through proactive management of cyber risk. Our Forward Deployed Security Engineers work directly within client teams, combining risk, regulatory, and technology capabilities with hands-on engineering to design, build, and operate scalable, automated AWS cloud security solutions. This team works closely with clients to implement controls in production environments and support security outcomes at scale.

Qualifications

Required:

  • 5+ years of experience in cloud security, cybersecurity, technology risk, or technology consulting; and a bachelor’s degree in computer science, cybersecurity, information technology, engineering, or a technical field
  • 3+ years of hands-on experience designing, building, or operating security solutions in Amazon Web Services (AWS) production environments, including AWS Security Hub, Amazon GuardDuty, AWS Config, AWS Identity and Access Management (IAM), AWS Key Management Service (KMS), and AWS CloudTrail
  • 2+ years of experience using Terraform and/or AWS CloudFormation to deploy infrastructure and security controls through production deployment pipelines
  • Experience securing at least one of the following in a production environment: Amazon Elastic Kubernetes Service (EKS) / containers, Amazon SageMaker or Amazon Bedrock workloads, or data protection using Amazon Macie
  • Experience integrating security controls into continuous integration / continuous deployment (CI/CD) pipelines, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secrets scanning, and infrastructure-as-code (IaC) scanning; experience scripting in Python, Bash, or Go to automate enforcement or remediation; and experience working directly with client or customer engineering teams in onsite or virtual delivery environments
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Experience securing generative AI and agentic workloads on Amazon Bedrock, Amazon Bedrock AgentCore, or Amazon SageMaker in production environments
  • Experience using policy-as-code and guardrail tools, including AWS Service Control Policies, Open Policy Agent, Checkov, or tfsec
  • Experience with AWS Control Tower, secure landing zones, and multi-account governance
  • Experience with Kubernetes security tooling and runtime protection
  • Experience implementing security controls aligned to International Organization for Standardization (ISO) 27001, National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), National Institute of Standards and Technology Special Publication 800-53 (NIST SP 800-53), Payment Card Industry Data Security Standard (PCI DSS), or System and Organization Controls 2 (SOC 2)
  • Prior experience in a forward-deployed, startup, or professional services delivery model; AWS Certified Security – Specialty, AWS Certified Solutions Architect, or Certified Cloud Security Professional (CCSP)

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Deloitte is committed to providing reasonable accommodations for people with disabilities. If you require a reasonable accommodation to participate in the recruiting process, please direct your inquiries to the Global Call Center (GCC) at USTalentCICInbox@deloitte.com.
Recruiting tips

From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.
Our people and culture

Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ways of thinking, ideas, and perspectives, and bring more creativity and innovation to help solve our clients' most complex challenges. This makes Deloitte one of the most rewarding places to work.
Our purpose
Deloitte’s purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities. Learn more.
Professional development

From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.
As used in this posting, "Deloitte" means Deloitte & Touche LLP, a subsidiary of Deloitte LLP. Please see www.deloitte.com/us/about for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. Certain services may not be available to attest clients under the rules and regulations of public accounting.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.
Requisition code: 363463
Job ID 363463