Security Product Manager Jobs at Deloitte with Visa Sponsorship
Security Product Manager jobs at Deloitte span its cyber and risk practices, placing hired professionals on client-facing engagements that require both technical depth and business acumen. The firm has an established visa sponsorship process for this function, covering multiple nonimmigrant and immigrant pathways for qualified candidates.
Find Security Product Manager Jobs at DeloitteOverview
Showing 5 of 26+ Security Product Manager Jobs at Deloitte










See all Security Product Manager Jobs at Deloitte
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Security Product Manager Jobs at Deloitte.
Get Access To All Jobs
INTRODUCTION
Join Deloitte's Cloud Cyber Risk practice as a Forward Deployed Security Engineer and help organizations secure their Amazon Web Services (AWS) cloud and AI workloads at scale while working directly with client engineering teams. This is not an assessment-and-handoff role. You will design, build, deploy, and operate secure-by-default AWS environments and automated security controls across generative AI services, container and data platforms, infrastructure-as-code, and secure delivery pipelines. This role is designed for a hands-on engineer who enjoys solving complex cloud security challenges, building working automation, and supporting security outcomes in production environments.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As an Engineering and Product Engineer III on the Cloud Cyber Risk team, you will be responsible for:
- Embed directly with client cloud and platform engineering teams to design, build, deploy, and operate automated security controls across AWS environments from initial design through production support.
- Design and implement security guardrails for AWS generative artificial intelligence (AI) and machine learning services, including Amazon Bedrock, Amazon Bedrock AgentCore, and Amazon SageMaker, as well as containerized and serverless workloads on Amazon Elastic Kubernetes Service (EKS).
- Build automated data protection and data loss prevention capabilities using Amazon Macie, AWS Key Management Service (KMS), and encryption and tokenization patterns across Amazon Simple Storage Service (S3), databases, and analytics platforms.
- Deploy and maintain AWS-native security services, including AWS Security Hub, Amazon GuardDuty, AWS Config, AWS Identity and Access Management (IAM) Access Analyzer, and AWS CloudTrail, within client monitoring and security operations workflows.
- Write and maintain production infrastructure-as-code using Terraform and/or AWS CloudFormation, integrate security scanning into continuous integration / continuous deployment (CI/CD) pipelines, and contribute reusable modules, runbooks, and reference implementations for future engagements.
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Deloitte's Cloud Cyber Risk team helps organizations pursue growth, innovation, and performance through proactive management of cyber risk. Our Forward Deployed Security Engineers work directly within client teams, combining risk, regulatory, and technology capabilities with hands-on engineering to design, build, and operate scalable, automated AWS cloud security solutions. This team works closely with clients to implement controls in production environments and support security outcomes at scale.
QUALIFICATIONS
Required:
- 5+ years of experience in cloud security, cybersecurity, technology risk, or technology consulting; and a bachelor's degree in computer science, cybersecurity, information technology, engineering, or a technical field
- 3+ years of hands-on experience designing, building, or operating security solutions in Amazon Web Services (AWS) production environments, including AWS Security Hub, Amazon GuardDuty, AWS Config, AWS Identity and Access Management (IAM), AWS Key Management Service (KMS), and AWS CloudTrail
- 2+ years of experience using Terraform and/or AWS CloudFormation to deploy infrastructure and security controls through production deployment pipelines
- Experience securing at least one of the following in a production environment: Amazon Elastic Kubernetes Service (EKS) / containers, Amazon SageMaker or Amazon Bedrock workloads, or data protection using Amazon Macie
- Experience integrating security controls into continuous integration / continuous deployment (CI/CD) pipelines, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secrets scanning, and infrastructure-as-code (IaC) scanning; experience scripting in Python, Bash, or Go to automate enforcement or remediation; and experience working directly with client or customer engineering teams in onsite or virtual delivery environments
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Experience securing generative AI and agentic workloads on Amazon Bedrock, Amazon Bedrock AgentCore, or Amazon SageMaker in production environments
- Experience using policy-as-code and guardrail tools, including AWS Service Control Policies, Open Policy Agent, Checkov, or tfsec
- Experience with AWS Control Tower, secure landing zones, and multi-account governance
- Experience with Kubernetes security tooling and runtime protection
- Experience implementing security controls aligned to International Organization for Standardization (ISO) 27001, National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), National Institute of Standards and Technology Special Publication 800-53 (NIST SP 800-53), Payment Card Industry Data Security Standard (PCI DSS), or System and Organization Controls 2 (SOC 2)
- Prior experience in a forward-deployed, startup, or professional services delivery model; AWS Certified Security - Specialty, AWS Certified Solutions Architect, or Certified Cloud Security Professional (CCSP)
COMPENSATION
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
See all Security Product Manager Jobs at Deloitte
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Security Product Manager Jobs at Deloitte.
Get Access To All JobsTips for Finding Security Product Manager Jobs at Deloitte
Frame your credentials around consulting deliverables
Deloitte evaluates Security Product Managers on client impact, not just technical output. Tailor your resume to show you've owned product roadmaps, managed cross-functional stakeholders, and delivered security capabilities in complex enterprise environments.
Target roles aligned to Deloitte's cyber practice
Deloitte's Security Product Manager openings often sit within its Cyber and Strategic Risk practice. Search specifically for those practice area postings, since the sponsorship process and hiring manager expectations differ meaningfully from general product roles.
Use Migrate Mate to filter open positions by visa type
Not every Security Product Manager posting at Deloitte is tied to a sponsoring team. Use Migrate Mate to filter Deloitte's open roles by the visa category you need, so you're applying only where sponsorship is actively available.
Clarify your visa status before the offer stage
Deloitte's talent acquisition teams move quickly once they decide on a candidate. Know exactly what status you hold, whether you're on OPT, a grace period, or need a transfer, so you can answer sponsorship questions accurately when the offer conversation begins.
Understand how the E-3 fits Deloitte's process
If you're an Australian citizen, the E-3 is often faster to arrange than an H-1B because it requires no lottery and can be obtained at a U.S. consulate without USCIS adjudication. Deloitte sponsors this category, so surface your nationality early in recruiter conversations.
Ask your recruiter about PERM eligibility during negotiation
For longer-term immigration security, Deloitte's professional services structure often supports PERM-based Green Card sponsorship through the EB-2 or EB-3 categories. Raise this during the offer negotiation, since DOL processing timelines mean earlier starts matter significantly.
Frequently Asked Questions
Does Deloitte sponsor H-1B visas for Security Product Managers?
Yes, Deloitte sponsors H-1B visas for Security Product Managers. The firm has a well-established immigration program that handles H-1B petitions through USCIS, including both cap-subject filings and cap-exempt transfers for candidates already holding H-1B status with another employer. The role qualifies as a specialty occupation given its requirement for a bachelor's degree or higher in a relevant technical or business field.
How do I apply for Security Product Manager jobs at Deloitte?
Applications go through Deloitte's careers portal, where Security Product Manager postings are listed by practice area and location. The process typically involves an initial recruiter screen, a technical and behavioral interview series, and a case or presentation round. To find only the openings where visa sponsorship is available for your specific visa category, browse Deloitte's roles on Migrate Mate, which filters by sponsorship type.
Which visa types does Deloitte sponsor for Security Product Manager roles?
Deloitte sponsors several nonimmigrant and immigrant visa categories for Security Product Managers, including the H-1B, H-1B1 visa for Chilean and Singaporean nationals, and E-3 visa for Australian citizens. On the immigrant side, the firm supports EB-2 and EB-3 Green Card pathways through PERM labor certification. The right category depends on your nationality, current status, and career timeline.
What qualifications does Deloitte expect for a Security Product Manager?
Deloitte typically looks for candidates with a bachelor's degree in computer science, information systems, cybersecurity, or a related field, often combined with several years of product management experience in a security or technology context. Familiarity with frameworks like NIST or ISO 27001, experience translating security requirements into product roadmaps, and prior consulting or client-facing work all strengthen an application meaningfully.
How do I time my application around H-1B cap deadlines?
USCIS opens H-1B cap registration in March each year for an October 1 start date. If you're currently on OPT and your status expires before October 1, confirm whether you're eligible for a cap-gap extension, which bridges the period between OPT expiration and H-1B activation. Starting your Deloitte application process by late fall gives enough lead time for an offer, LCA filing with DOL, and timely USCIS registration.