Cloud Security Careers

Roles, salary bands, interview formats, portfolio projects, and how to translate from adjacent jobs into your first cloud security role. Written for the person trying to break in - and the practitioner figuring out the next step.

Β· Β· Vendor-neutral Β· View source on GitHub

The honest version: "Cloud security engineer" isn't one job - it's at least a dozen, with very different day-to-day work, hiring bars, and pay bands. Most rejections come from applying to the wrong shape of role for your background, not from being underqualified. Read the role taxonomy first, then work backwards from the one that fits.

All numbers below are US-centric, 2026, and approximate. Adjust for region, industry, and company size. Outside the US, halve and add a question mark.

Preparing to apply? Deep-dive guides: getting in with no experience, is it a good career, the resume guide, and interview questions with model answers.

On this page

  1. The roles (and what they actually do)
  2. Salary bands
  3. What hiring managers look for
  4. Interview formats
  5. Portfolio projects worth building
  6. Translating from adjacent roles
  7. The application game
  8. Common mistakes
  9. Where next
Cloud security career tracks Common progression from entry roles through senior into five specialty branches. Career tracks - most cloud security pros land somewhere in this map ENTRY SOC Analyst Cloud / DevOps Eng MID-LEVEL Cloud Security Engineer SENIOR Sr. Cloud Security Engineer ARCHITECTCloud Securitystrategy, design DETECTION ENGDetection &SIEM content INCIDENT RESPCloud IR Leadforensics, recovery APPSEC / CNAPPPlatform & AppSecSAST, IaC, runtime GRC / COMPLIANCECompliance LeadSOC 2, ISO, FedRAMP
The most common path is left-to-right; specialization usually happens around year 4-6. The role descriptions below match these branches.

The roles (and what they actually do)

Job titles vary wildly - "Cloud Security Engineer" at one company is "Detection Engineer" at another. Read the responsibilities, not the title. Most teams have at least two of these, sometimes blended into one person.

Each role below includes a "Natural fit if you currently…" note - the backgrounds and day-to-day work that map cleanly into that role. If two or three of the bullets describe your current job, that's the role you'll ramp fastest into.

Cloud Security Engineer

The default generalist. IAM, CSPM triage, guardrails, design reviews. Breadth over depth. Deep guide β†’

Detection Engineer

Builds the rules that catch attackers in cloud. Sigma/KQL/SPL, MITRE ATT&CK Cloud, purple-team. Deep guide β†’

Cloud IR / DFIR

The pager-carriers. Investigates GuardDuty alerts and leaks, reads CloudTrail at speed, scopes blast radius. Deep guide β†’

Cloud Pentester / Red Team

Offensive. Pacu, ROADtools, custom scripts. Smaller market, high pay at senior end. Deep guide β†’

CSPM / CNAPP Analyst

Lives in Wiz, Orca, Defender, Prisma. Triages findings, drives remediation. Underrated way in. Deep guide β†’

IAM / Identity Architect

Most strategically important specialization right now. Identity boundaries, least-privilege at scale, IdP. Deep guide β†’

Cloud AppSec / IaC Security

Between security and app teams. IaC scanning, container images, supply chain, K8s admission. Code-centric. Deep guide β†’

GRC / Compliance Engineer

SOC 2, ISO, FedRAMP into cloud controls. Owns audits, automates evidence. Paths to security leadership. Deep guide β†’

Security SRE / Platform

Builds the security platform other engineers use. Shared SIEM, secret rotation, account vending. Deep guide β†’

Cloud Security Architect

Staff+ IC. Sets direction, reviews high-stakes designs, owns the roadmap. 8+ years operational first. Deep guide β†’

Sales Engineer / Solutions Architect

Vendor-side. Demos, POVs, architecture for customers. Highest-paid role most engineers never consider. Deep guide β†’

Customer Success Engineer

Vendor-side, post-sale. Onboarding, adoption, renewals. Goes by many names (CSE, CSA, TAM). Technical and customer-facing. Deep guide β†’

Cloud Security Engineer (generalist)

The default role. Configures and reviews IAM, owns the CSPM tool and triages findings, writes guardrail policies (SCPs, Azure Policy, Org Policy), reviews cloud architectures during design, automates security tooling. Half the day is in code review and Terraform PRs; the other half is in IAM consoles and the SIEM. Demands breadth over depth. Read the full guide β†’

Natural fit if you currently:

Detection Engineer (cloud-focused)

Builds and maintains the rules that catch attackers in cloud environments. Writes Sigma / KQL / SPL detections, maps coverage to MITRE ATT&CK Cloud, tunes false positives, runs purple-team exercises with Stratus Red Team / Atomic Red Team. Highly technical, mostly written in code. Strong career arc into senior IC tracks. Read the full guide β†’

Natural fit if you currently:

Cloud Incident Responder / DFIR

The pager-carriers. When GuardDuty fires or a customer reports a leak, this is who investigates. Knows what evidence each cloud actually retains (and what it doesn't), reads CloudTrail at speed, scopes blast radius, drives containment and recovery. Often blended with detection engineering at smaller orgs. Read the full guide β†’

Natural fit if you currently:

Cloud Penetration Tester / Red Team

Offensive. Audits cloud environments by attacking them, often via consultancy or as an internal red team. Lives in Pacu, ROADtools, custom scripts. Reports look like breach kill chains. Smaller market than defensive roles, but high pay and prestige at the senior end. Read the full guide β†’

Natural fit if you currently:

CSPM / CNAPP Analyst

Lives inside Wiz, Orca, Sysdig, Prisma Cloud, Defender for Cloud, or similar. Triages findings, drives remediation, builds custom policies, runs reporting for leadership. Common entry-level role at companies that bought a CNAPP and need humans to make it useful. Underrated path in. Read the full guide β†’

Natural fit if you currently:

IAM / Identity Architect

The most strategically important specialization right now. Designs identity boundaries (cross-account access, federation, conditional access, service-to-service auth), builds least-privilege policy frameworks at scale, owns the IdP integration. Senior IC track in most large orgs, often the closest thing to "Cloud Security Architect" with a real job to do. Read the full guide β†’

Natural fit if you currently:

Cloud AppSec / IaC Security

Sits between security and the application teams. Owns IaC scanning (Checkov, Terrascan, KICS, tfsec), container image security, dependency review in CI/CD, secret scanning, supply-chain controls, and Kubernetes admission & workload identity. Strong fit for developers moving into security - very PR-driven, very code-centric. Read the full guide β†’

Natural fit if you currently:

Cloud GRC / Compliance Engineer

Translates frameworks (SOC 2, ISO 27001, FedRAMP, HIPAA, PCI) into cloud controls. Owns the audit relationship, automates evidence collection (Drata, Vanta, Secureframe), maps controls to AWS Config / Azure Policy rules. Less code-heavy, more cross-functional. Paths to security leadership. Read the full guide β†’

Natural fit if you currently:

Security SRE / Platform Security

Builds the security platform other engineers use: shared SIEM pipelines, secret rotation services, golden VPC patterns, account-vending automation. The "security as a product" team. Often the highest-leverage role on a security org. Read the full guide β†’

Natural fit if you currently:

Sales Engineer / Solutions Architect (vendor-side)

The technical half of a two-person selling team at a security vendor. Owns discovery, demos, the proof of value inside the customer's environment, architecture conversations, and the security-review defense. Comp routinely lands above equivalent IC engineering roles. Closer to "consultant paid by the vendor" than to the cold-call stereotype of sales. Read the deep guide β†’

Natural fit if you currently:

Cloud Security Architect / Staff+ IC

Senior strategic role. Sets technical direction, reviews high-stakes designs, owns the security roadmap for a business unit or product area. Usually 8+ years of operational experience first. Often has no individual deliverables - the deliverable is alignment. Read the full guide β†’

Natural fit if you currently:

High-angle view of a contract document with pens on a wooden table
Photo by RDNE Stock project on Pexels

Salary bands (US, 2026)

Approximate ranges for general industry. Big-tech total comp can be 1.5-2x these numbers. Federal contractors and consulting firms tend lower on base, sometimes higher on cash bonus.

For real numbers, check levels.fyi for big-tech comp, the BLS information security analysts data for general industry, and recent salary threads on r/cybersecurity for anecdata. Bring real numbers to negotiations.

Business professionals networking in a conference room setting
Photo by Pavel Danilyuk on Pexels

What hiring managers actually look for

Distilled from interviewing hundreds of cloud security candidates and from years of conversations with hiring peers. The order matters.

  1. Hands-on evidence with the cloud you'll be working in. Public CloudGoat write-ups, blog posts, GitHub repos, conference talks. One CTF write-up beats three certs every time.
  2. The ability to explain IAM precisely. If you can't explain the difference between an identity-based and a resource-based policy, or between AssumeRole and trust policies, you fail the technical screen at most shops.
  3. Comfort with the command line and Terraform/CDK/Pulumi. Cloud security is API-first. The console is for hiring managers, not engineers.
  4. One cloud at depth, not three at surface. "I know AWS well, Azure passably, GCP barely" beats "I know AWS, Azure, and GCP" 90% of the time. Pick one.
  5. Specific incident or breach knowledge. Be able to walk through Capital One, MOVEit, MGM/Scattered Spider, or whatever's recent. The breach kill chains are interview fodder.
  6. A relevant cert as a baseline filter. Recruiters use certs to pass the resume screen. CCSK or your cloud's security specialty does the job. See the certifications guide.
  7. Communication. Most senior cloud security work is influence - convincing engineering teams to fix things. Candidates who write well and explain trade-offs without jargon stand out fast.
  8. Curiosity and momentum. "What did you learn last month?" If the answer is "nothing in particular," that's a no.
Hands-on portfolio plus a relevant cert beats a degree without practical work, every time. - from the “do I need a degree?” answer below

Interview formats you'll actually see

Loops vary, but the modules below cover ~90% of what shows up. Practice each one before you need to.

Portfolio projects worth building

Your portfolio is your interview. Pick three of these, do them well, write each one up publicly. A blog (Substack, GitHub Pages, dev.to) plus a public GitHub is enough - no fancy site needed.

Each link below is a step-by-step walkthrough - prerequisites, the actual steps, what hiring managers look for in the write-up, and the common mistakes to avoid:

  1. Walk every CloudGoat scenario. Publish your kill chain, screenshots, and remediation for each. The canonical project - most interviewers have done it themselves and will recognize you've done the work.
  2. Build a multi-account AWS Organization with SCPs. Terraform a 3-account org, IAM Identity Center, and a baseline of SCPs. Push the code to GitHub. Real production-shaped work.
  3. Run Prowler against your own account and remediate everything. Document the before/after. Bonus: turn the remediation into Terraform.
  4. Build 5 detections in a lab SIEM. Spin up Wazuh, Elastic, or Matano; pick five MITRE ATT&CK Cloud techniques and write Sigma rules; validate with Stratus Red Team.
  5. Take a real breach, rebuild it in a lab. Recreate the Capital One architecture in your own account, exploit it end-to-end, then build the controls and detections that would have stopped it. Best single portfolio piece you can ship.
  6. Contribute to an open-source cloud security tool. Prowler, Cloud Custodian, Pacu, ROADtools, KICS, Steampipe - all welcome contributors. Even a small PR is a strong signal.
  7. Write a CNAPP comparison. Pick three (Wiz, Orca, Defender for Cloud, Prisma, Sysdig) and write an honest comparison. Hands-on trial work, false-positive sampling, and a who-should-pick-which section.

See the full portfolio playbook for time estimates, difficulty, and how to talk about each one in interviews.

What not to do: don't build a "cloud security dashboard" toy webapp. Hiring managers see hundreds. Build operational artifacts that look like real work.

Translating from an adjacent role

Most people don't enter cloud security cold. They pivot. The fastest path is usually one role-step from where you are now, not a leap straight to "Cloud Security Engineer."

From SOC analyst

You already understand alerts, triage, and incident workflow. Add: cloud-native log sources (CloudTrail, Activity Log, Audit Logs), GuardDuty / Defender / SCC, and one cloud's IAM model. Target: cloud-focused SOC roles or detection engineering.

From DevOps / SRE

You already know IaC, CI/CD, and at least one cloud at depth. Add: IAM specifics, threat modeling, posture management, common misconfigurations. Target: Cloud AppSec, IaC security, or platform security. Often the fastest pivot - security teams are desperate for engineers who can actually ship code.

From software developer

You know systems and code review. Add: AppSec fundamentals (OWASP Top 10), IaC scanning, supply-chain controls, container security. Target: Cloud AppSec, secure-by-design consulting roles. Strong pivot if you're a senior dev - security pays similarly and the work is varied.

From sysadmin / network engineer

You understand systems, networks, and "how things actually break." Add: IaC, the cloud-native equivalents of what you already do (security groups vs. firewall rules, IAM vs. AD, etc.), and one cloud's services. Target: cloud security generalist or network-security-in-cloud roles.

From traditional security (on-prem, GRC, AppSec)

You have the security mental model. Add: at least one cloud at operational depth, cloud-specific tooling, IaC. Target: the equivalent of your current role but cloud-flavored. Easiest pivot conceptually, hardest practically because hiring managers look hard for hands-on cloud evidence.

From totally outside tech

Longest road, but doable. Stage 1: get into IT (helpdesk, sysadmin, junior cloud). Stage 2: pivot to security from there. Trying to leap directly into a cloud security role is rarely successful. Plan for 18-36 months. Already on a help desk? The dedicated help desk to cloud security guide walks the whole staircase step by step.

The application game

Common mistakes

Where next

Quick answers

What does a cloud security engineer actually do?

Day-to-day work splits across configuring and reviewing IAM policies, running posture management tools (CSPM/CNAPP) and triaging the findings, building detections in the SIEM, responding to alerts from GuardDuty/Defender/SCC, reviewing cloud architectures for security issues, automating guardrails (SCPs, Azure Policy, Org Policy), and writing runbooks. Less cloud-console clicking than people expect; more code review, IaC review, and arguing with engineers about least privilege.

How much do cloud security engineers make?

In the US, mid-level cloud security engineers (2-5 years) typically earn $140K-$190K base. Senior roles (5-8 years) run $180K-$240K base. Staff and principal levels often clear $250K base, with total comp of $350K+ at large tech companies. Numbers are lower outside major tech hubs and significantly lower outside the US. Contractor day rates run $800-$1,500 in the US.

Do I need a degree to get into cloud security?

No. The field is unusually credential-friendly: hands-on portfolio (CloudGoat write-ups, public repos, blog posts) plus a relevant cert (CCSK, AWS Security Specialty, or AZ-500) consistently outperforms a degree without practical work. Many practitioners come from sysadmin, SRE, dev, or SOC backgrounds with no cloud-security degree. A degree helps in regulated industries (defense, finance) and is occasionally a hard filter for federal roles.

What's the best way to break into cloud security with no experience?

Pick one cloud (AWS by default), get hands-on in your free-tier account, complete 5+ CTF scenarios from CloudGoat or similar and publish write-ups, earn one foundational cert (CCSK or your provider's fundamentals), then target adjacent-role pivots first: DevOps engineer, SOC analyst, or junior cloud engineer with a security focus. Pure 'cloud security engineer' roles rarely take true beginners; the pivot path is faster than the cold application path.