About the role
We are seeking a hands on Cloud Security Lead who excels at deep technical analysis, research, and practical execution across cloud platforms. This role is for a technical practitioner who can translate security standards and policies into implementable controls, partner closely with engineering teams, and drive real improvements in cloud security posture across AWS, Azure, and GCP. The ideal candidate is a strong researcher and problem solver, comfortable working under broad direction, capable of independently driving work to completion, and skilled at clearly communicating complex cloud security concepts to both technical and non technical stakeholders. This role requires a balance of technical depth, collaboration, and clear storytelling to influence security outcomes at scale.
Responsibilities Conduct in-depth research, assessment, and analysis of security configurations for IaaS, PaaS, and SaaS services across AWS, Azure, and GCP Design and deploy cloud services in sandbox environments to perform hands-on security assessments and develop practical security configuration guidance for application teams. Research and interpret Deloitte internal information security standards, translating policy requirements into technical controls, reverse engineering existing controls, and identifying gaps or inconsistencies. Collaborate closely with engineering and platform teams to validate the technical feasibility and effectiveness of security guardrails. Build PowerPoint decks to present metrics/facts to leaderships Present CSPM and CNAPP dashboards to internal stakeholders, clearly explaining cloud security posture, risk drivers, and remediation priorities. Partner with application teams to remediate cloud misconfigurations and improve overall security posture. Develop, maintain, and continuously improve internal documentation, including SOPs, process workflows, and Enterprise Reference Architectures. Stay current with cloud security trends, emerging threats, and best practices, ensuring configuration guidance remains accurate and relevant. Identify and recommend continuous process improvements to strengthen efficiency, scalability, and consistency of cloud security operations.
Required Qualifications Bachelor’s degree in Computer Science, Information Security, or a related field. 5+ years of experience as a Cloud Security Engineer or in a similar security-focused role. Proven, hands-on experience with at least one major cloud platform: AWS, Azure, or GCP. Strong understanding of security frameworks and standards, such as CIS Benchmarks, NIST, and ISO/IEC 27001. A continuous learning mindset, with a strong interest in emerging cloud security technologies and practices. One of the following certifications: ISC² CCSP Cloud Solutions Architect certification (AWS, Azure, or GCP) Cloud Security Specialty certification (AWS, Azure, or GCP) Preferred: Experience working across multiple cloud service providers Software or infrastructure development experience Prior client-facing experience in a consulting or enterprise environment
About Deloitte
Similar Jobs
About the role
We are seeking a hands on Cloud Security Lead who excels at deep technical analysis, research, and practical execution across cloud platforms. This role is for a technical practitioner who can translate security standards and policies into implementable controls, partner closely with engineering teams, and drive real improvements in cloud security posture across AWS, Azure, and GCP. The ideal candidate is a strong researcher and problem solver, comfortable working under broad direction, capable of independently driving work to completion, and skilled at clearly communicating complex cloud security concepts to both technical and non technical stakeholders. This role requires a balance of technical depth, collaboration, and clear storytelling to influence security outcomes at scale.
Responsibilities Conduct in-depth research, assessment, and analysis of security configurations for IaaS, PaaS, and SaaS services across AWS, Azure, and GCP Design and deploy cloud services in sandbox environments to perform hands-on security assessments and develop practical security configuration guidance for application teams. Research and interpret Deloitte internal information security standards, translating policy requirements into technical controls, reverse engineering existing controls, and identifying gaps or inconsistencies. Collaborate closely with engineering and platform teams to validate the technical feasibility and effectiveness of security guardrails. Build PowerPoint decks to present metrics/facts to leaderships Present CSPM and CNAPP dashboards to internal stakeholders, clearly explaining cloud security posture, risk drivers, and remediation priorities. Partner with application teams to remediate cloud misconfigurations and improve overall security posture. Develop, maintain, and continuously improve internal documentation, including SOPs, process workflows, and Enterprise Reference Architectures. Stay current with cloud security trends, emerging threats, and best practices, ensuring configuration guidance remains accurate and relevant. Identify and recommend continuous process improvements to strengthen efficiency, scalability, and consistency of cloud security operations.
Required Qualifications Bachelor’s degree in Computer Science, Information Security, or a related field. 5+ years of experience as a Cloud Security Engineer or in a similar security-focused role. Proven, hands-on experience with at least one major cloud platform: AWS, Azure, or GCP. Strong understanding of security frameworks and standards, such as CIS Benchmarks, NIST, and ISO/IEC 27001. A continuous learning mindset, with a strong interest in emerging cloud security technologies and practices. One of the following certifications: ISC² CCSP Cloud Solutions Architect certification (AWS, Azure, or GCP) Cloud Security Specialty certification (AWS, Azure, or GCP) Preferred: Experience working across multiple cloud service providers Software or infrastructure development experience Prior client-facing experience in a consulting or enterprise environment