← All job descriptionsIT & Security

Cloud Security Engineer Job Description

A complete cloud security engineer job description template, the ATS keywords hiring teams screen for, and which certifications actually apply.

SeniorInformation TechnologyOn-site

"Cloud Security Engineer" reads like a specialization of "Cybersecurity Analyst," but the two jobs barely overlap. An analyst mostly watches: alerts, logs, tickets. This role mostly builds — identity and access policies, network segmentation, key management, the guardrails that make it hard to misconfigure a cloud account into a breach in the first place. A posting under this title that's heavy on "monitor alerts and escalate" is describing a differently scoped role wearing this title for the salary band.

Postings in this space routinely list AWS, Azure and GCP as if fluency in all three is standard. It isn't. Most cloud security engineers have real depth in whichever platform their employer actually runs, plus enough pattern recognition in the others to read documentation and get by. Worth asking directly which cloud is in production before assuming the other two matter for the interview.

Certifications follow the same pattern here as elsewhere in security: CISSP shows up on hands-on engineering listings by habit more than by need, since it's a broad, management-oriented body of knowledge for a job that's mostly implementation. A cloud-specific credential — AWS Certified Security, CCSP — says more about whether someone can actually do this work. And one more thing worth noting about this particular listing: cloud engineering is one of the more remote-friendly disciplines in tech, so an on-site requirement at the senior level, like this one, is worth asking about directly rather than assuming it's the default.

Sample job description — not a live opening

Ormsbury · Chicago, IL

Full-time · On-site

$150,000 – $190,000

About the role

Ormsbury verifies identity and detects fraud for banks and fintech platforms, and our Chicago office sits next to the co-located data center that houses our core production infrastructure and the regulated customer data that runs through it. We're hiring a senior Cloud Security Engineer to own the guardrails across our AWS environment: identity and access management, key management, network segmentation, and the checks that keep insecure infrastructure from reaching production at all.

You'll report to the Head of Security and work closely with the platform team that runs AWS day to day. This is a hands-on build role, not a monitoring one — you'll be the person other engineers come to when 'is this safe to ship' needs a real answer, which is also why we keep this role on-site: fast, in-person calls on production risk are worth more here than a few extra remote applicants.

What you'll do

  • Design and maintain IAM policies, service roles and permission boundaries across our AWS accounts.
  • Own encryption strategy for data at rest and in transit, including customer-managed encryption keys for our regulated data stores.
  • Build and maintain network segmentation between production, staging and internal tooling.
  • Run cloud security posture checks and fix misconfigurations before they show up in an audit.
  • Review infrastructure-as-code changes for security issues before they merge.
  • Lead root-cause investigation on cloud-specific incidents: exposed storage, over-permissioned roles, leaked credentials.
  • Partner with the platform team to build security checks into CI/CD instead of bolting them on afterward.
  • Support SOC 2 Type II and customer security audits with evidence pulled directly from our cloud environment.

What we're looking for

  • 5+ years in security engineering, with at least 2 focused specifically on cloud infrastructure.
  • Deep working knowledge of AWS IAM, VPC networking and key management services.
  • Experience with infrastructure as code (Terraform or CloudFormation) and reviewing it for security issues.
  • Practical understanding of encryption at rest and in transit, including how customer-managed encryption keys change an incident response story.
  • Comfort reading application code well enough to explain a vulnerability to the engineer who introduced it.
  • A track record of shipping security improvements that engineering teams didn't fight.

Nice to have

  • AWS Certified Security – Specialty or CCSP.
  • Prior experience in a regulated industry: financial services, healthcare or payments.
  • Working familiarity with a second cloud provider, even without production-level depth.
  • Kubernetes security experience — network policies, pod security standards, image scanning.
  • Prior on-call ownership of a production security tool: a SIEM, a CSPM, or similar.

Benefits

  • Medical, dental and vision coverage, with employee premiums covered in full.
  • 401(k) with a 4% company match.
  • On-site in our Chicago office, a five-minute walk from the Blue Line, with free garage parking if you drive instead.
  • $2,500 annual budget for security training, conferences or certification exams.
  • Twenty-two days of paid time off plus company holidays.

Salary range

As posted for this sample role. Real pay varies by employer, location and experience.

$150,000$190,000/ yr

What gets you noticed

ATS keywords for this role

The applicant tracking system (ATS) — the recruiting software a hiring team searches and filters applicants with — will screen for these. Weight shows how central each one is to this specific posting.

Required and central (4)

AWSIAMcloud securityencryption key management

Important (8)

Terraformnetwork segmentationinfrastructure as codeCI/CDvulnerability remediationSOC 2incident responseAWS Certified Security Specialty

Mentioned in passing (6)

KubernetesCCSPCISSPVPC networkingsecurity code reviewcross-functional communication

Frequently asked questions

Do I need hands-on experience with AWS, Azure and GCP to apply?

No — real depth in whichever cloud actually runs the company's production environment matters far more than shallow exposure to all three. Ask which cloud is in use before worrying about the others; most cloud security engineers specialize in one and read documentation for the rest when they need to.

Is CISSP required for this role?

Some postings ask for it out of habit, but for a hands-on engineering role a cloud-specific credential — AWS Certified Security, CCSP — is a better match for the actual work. Treat CISSP on a listing like this one as a soft preference rather than a hard filter unless the posting says otherwise explicitly.

What's the difference between this and a cybersecurity analyst role?

Scope and posture. An analyst monitors and responds to what's already happening; an engineer designs and builds the systems that make monitoring necessary in the first place. Pay for the engineering track usually runs higher, in part because a misconfiguration here can be expensive at a scale an analyst can't personally introduce.

Why does a cloud role require on-site work when so much of cloud security is remote by nature?

It varies by company. Some require it for badge-controlled access to sensitive systems tied to a compliance program; others simply want a small, high-trust security team in one room. It isn't the industry default for this discipline, so it's worth asking directly rather than assuming.

Tailor it to a real posting

This was a sample. Your resume should be tailored to the real thing.

Rezi Ninja reads an actual job posting and rewrites your resume to match it, with a Ninja Score so you know it lands before you hit send. Free to start, with the AI usage included.

We use privacy-conscious analytics to see how the site is used — no ads, no selling data. Read our Privacy Policy.