The honest version: "Cloud security engineer" isn't one job - it's at least a dozen, with very different day-to-day work, hiring bars, and pay bands. Most rejections come from applying to the wrong shape of role for your background, not from being underqualified. Read the role taxonomy first, then work backwards from the one that fits.
All numbers below are US-centric, 2026, and approximate. Adjust for region, industry, and company size. Outside the US, halve and add a question mark.
Preparing to apply? Deep-dive guides: getting in with no experience, is it a good career, the resume guide, and interview questions with model answers.
On this page
The roles (and what they actually do)
Job titles vary wildly - "Cloud Security Engineer" at one company is "Detection Engineer" at another. Read the responsibilities, not the title. Most teams have at least two of these, sometimes blended into one person.
Each role below includes a "Natural fit if you currentlyβ¦" note - the backgrounds and day-to-day work that map cleanly into that role. If two or three of the bullets describe your current job, that's the role you'll ramp fastest into.
Cloud Security Engineer
The default generalist. IAM, CSPM triage, guardrails, design reviews. Breadth over depth. Deep guide β
Detection Engineer
Builds the rules that catch attackers in cloud. Sigma/KQL/SPL, MITRE ATT&CK Cloud, purple-team. Deep guide β
Cloud IR / DFIR
The pager-carriers. Investigates GuardDuty alerts and leaks, reads CloudTrail at speed, scopes blast radius. Deep guide β
Cloud Pentester / Red Team
Offensive. Pacu, ROADtools, custom scripts. Smaller market, high pay at senior end. Deep guide β
CSPM / CNAPP Analyst
Lives in Wiz, Orca, Defender, Prisma. Triages findings, drives remediation. Underrated way in. Deep guide β
IAM / Identity Architect
Most strategically important specialization right now. Identity boundaries, least-privilege at scale, IdP. Deep guide β
Cloud AppSec / IaC Security
Between security and app teams. IaC scanning, container images, supply chain, K8s admission. Code-centric. Deep guide β
GRC / Compliance Engineer
SOC 2, ISO, FedRAMP into cloud controls. Owns audits, automates evidence. Paths to security leadership. Deep guide β
Security SRE / Platform
Builds the security platform other engineers use. Shared SIEM, secret rotation, account vending. Deep guide β
Cloud Security Architect
Staff+ IC. Sets direction, reviews high-stakes designs, owns the roadmap. 8+ years operational first. Deep guide β
Sales Engineer / Solutions Architect
Vendor-side. Demos, POVs, architecture for customers. Highest-paid role most engineers never consider. Deep guide β
Customer Success Engineer
Vendor-side, post-sale. Onboarding, adoption, renewals. Goes by many names (CSE, CSA, TAM). Technical and customer-facing. Deep guide β
Cloud Security Engineer (generalist)
The default role. Configures and reviews IAM, owns the CSPM tool and triages findings, writes guardrail policies (SCPs, Azure Policy, Org Policy), reviews cloud architectures during design, automates security tooling. Half the day is in code review and Terraform PRs; the other half is in IAM consoles and the SIEM. Demands breadth over depth. Read the full guide β
Natural fit if you currently:
- Work as a DevOps / cloud / platform engineer and already write Terraform or CDK against a real cloud account
- Are a sysadmin who has moved workloads to AWS/Azure/GCP and now manages security groups, IAM, and patching there
- Did Security+ / SSCP / Network+ training and want a role that mixes security with infrastructure
- Came from a SOC and want broader scope than alert triage
Detection Engineer (cloud-focused)
Builds and maintains the rules that catch attackers in cloud environments. Writes Sigma / KQL / SPL detections, maps coverage to MITRE ATT&CK Cloud, tunes false positives, runs purple-team exercises with Stratus Red Team / Atomic Red Team. Highly technical, mostly written in code. Strong career arc into senior IC tracks. Read the full guide β
Natural fit if you currently:
- Work as a SOC analyst (Tier 2/3) and have written or tuned Splunk / Sentinel / Chronicle / Elastic queries
- Did the SANS blue-team track (SEC555, SEC511, SEC503) or studied for GCDA / GCIA
- Were a threat hunter and enjoy the "what would I look for" thought experiment
- Are a developer or data engineer comfortable in SQL and event-stream pipelines and want to apply it to security
Cloud Incident Responder / DFIR
The pager-carriers. When GuardDuty fires or a customer reports a leak, this is who investigates. Knows what evidence each cloud actually retains (and what it doesn't), reads CloudTrail at speed, scopes blast radius, drives containment and recovery. Often blended with detection engineering at smaller orgs. Read the full guide β
Natural fit if you currently:
- Work in traditional DFIR and want to add cloud to your range - most of the SANS DFIR (FOR500, FOR508, FOR572) skills carry directly
- Studied or hold GCFA / GCIH / GCFE
- Are a SRE who has handled high-pressure on-call and wants the security flavor of the same skill
- Came from a SOC and want to own end-to-end investigations rather than triage
Cloud Penetration Tester / Red Team
Offensive. Audits cloud environments by attacking them, often via consultancy or as an internal red team. Lives in Pacu, ROADtools, custom scripts. Reports look like breach kill chains. Smaller market than defensive roles, but high pay and prestige at the senior end. Read the full guide β
Natural fit if you currently:
- Do traditional pentesting / web app testing and hold OSCP, OSEP, OSWE, or PNPT
- Did the SANS offensive track (SEC560, SEC588 - the cloud pentest course is the most direct on-ramp)
- Compete in CTFs and especially the cloud-focused ones (CloudGoat, IAM Vulnerable, AWSGoat) and write up your work
- Were a red-teamer in on-prem environments and want to add cloud to the engagement scope
CSPM / CNAPP Analyst
Lives inside Wiz, Orca, Sysdig, Prisma Cloud, Defender for Cloud, or similar. Triages findings, drives remediation, builds custom policies, runs reporting for leadership. Common entry-level role at companies that bought a CNAPP and need humans to make it useful. Underrated path in. Read the full guide β
Natural fit if you currently:
- Are an IT auditor or junior GRC analyst who already maps controls to evidence and wants more technical depth
- Did vulnerability management in an on-prem environment (Tenable, Qualys, Rapid7) - same skill, cloud-shaped
- Hold AWS Cloud Practitioner / AZ-900 / Cloud Digital Leader and want a first technical security role
- Were a NOC or ops engineer used to dashboards-and-tickets workflows
IAM / Identity Architect
The most strategically important specialization right now. Designs identity boundaries (cross-account access, federation, conditional access, service-to-service auth), builds least-privilege policy frameworks at scale, owns the IdP integration. Senior IC track in most large orgs, often the closest thing to "Cloud Security Architect" with a real job to do. Read the full guide β
Natural fit if you currently:
- Are an Active Directory / Entra ID admin and have lived in group policy, conditional access, and PIM
- Did Okta / Auth0 / Ping admin work or hold the Okta Certified Professional/Administrator track
- Built or maintained an SSO integration and understand SAML, OIDC, and OAuth 2 at depth
- Came from network security and want a specialty that's becoming more important, not less
Cloud AppSec / IaC Security
Sits between security and the application teams. Owns IaC scanning (Checkov, Terrascan, KICS, tfsec), container image security, dependency review in CI/CD, secret scanning, supply-chain controls, and Kubernetes admission & workload identity. Strong fit for developers moving into security - very PR-driven, very code-centric. Read the full guide β
Natural fit if you currently:
- Are a software engineer who already does code review and wants security as the deeper specialty
- Did web AppSec work, OWASP top-10 testing, or hold Burp Suite Certified Practitioner / GWAPT
- Are a build / release engineer who lives in GitHub Actions / GitLab CI / Jenkins pipelines
- Trained on the SANS DevSecOps track (SEC540) or did Snyk / GitGuardian / Semgrep work
Cloud GRC / Compliance Engineer
Translates frameworks (SOC 2, ISO 27001, FedRAMP, HIPAA, PCI) into cloud controls. Owns the audit relationship, automates evidence collection (Drata, Vanta, Secureframe), maps controls to AWS Config / Azure Policy rules. Less code-heavy, more cross-functional. Paths to security leadership. Read the full guide β
Natural fit if you currently:
- Hold CISA, CRISC, ISO 27001 LA/LI, or have worked at a Big 4 audit practice
- Are a project manager or program manager who's run cross-functional security work
- Did paralegal / privacy / compliance work and want a more technical specialty (CIPP/T pairs well)
- Hold CISSP and want the management-track flavor of cloud security rather than the IC track
Security SRE / Platform Security
Builds the security platform other engineers use: shared SIEM pipelines, secret rotation services, golden VPC patterns, account-vending automation. The "security as a product" team. Often the highest-leverage role on a security org. Read the full guide β
Natural fit if you currently:
- Work as an SRE / platform engineer and already think in terms of golden paths, error budgets, and self-service
- Are a backend engineer who has built and operated production services at scale
- Did data-engineering work and want to apply pipeline / event-bus skills to security telemetry
- Hold AWS / Azure / GCP DevOps Pro and want a security specialty next
Sales Engineer / Solutions Architect (vendor-side)
The technical half of a two-person selling team at a security vendor. Owns discovery, demos, the proof of value inside the customer's environment, architecture conversations, and the security-review defense. Comp routinely lands above equivalent IC engineering roles. Closer to "consultant paid by the vendor" than to the cold-call stereotype of sales. Read the deep guide β
Natural fit if you currently:
- Work as a cloud security engineer or architect at a customer and have done your own vendor evaluations - you've sat in the buyer's seat already
- Did consulting (Big 4, boutique, freelance) and already do client-facing scoping, writing, and presentations for a living
- Are in customer success or professional services at a security vendor and want to move upstream into pre-sales
- Enjoy explaining hard technical concepts to mixed audiences, get energy from variety and people, and want to compound a network across your career
Cloud Security Architect / Staff+ IC
Senior strategic role. Sets technical direction, reviews high-stakes designs, owns the security roadmap for a business unit or product area. Usually 8+ years of operational experience first. Often has no individual deliverables - the deliverable is alignment. Read the full guide β
Natural fit if you currently:
- Hold CISSP-ISSAP, CCSP, or AWS / Azure / GCP solutions architect professional and have used those certs at depth
- Have 5+ years as a senior cloud security engineer in any of the IC tracks above and want broader scope without the manager track
- Were a TOGAF-trained enterprise architect and want a security focus
- Already act as the "go-to" security voice in design reviews even though it's not your title
Salary bands (US, 2026)
Approximate ranges for general industry. Big-tech total comp can be 1.5-2x these numbers. Federal contractors and consulting firms tend lower on base, sometimes higher on cash bonus.
- Junior / Associate (0-2 yrs): $95K-$135K base. Often a SOC analyst or DevOps engineer with a security focus, not titled "cloud security."
- Mid-level (2-5 yrs): $140K-$190K base. The first true "Cloud Security Engineer" role for most people.
- Senior (5-8 yrs): $180K-$240K base. Owns a domain (IAM, detection, CSPM, etc.), mentors others.
- Staff / Principal (8+ yrs): $230K-$320K base, often $400K+ TC at large tech.
- Manager / Director: $180K-$260K base, plus larger bonus and equity components than IC at the same level.
- Consultant / contractor: $800-$1,500/day in the US, occasionally higher for incident response or specialty offensive work.
For real numbers, check levels.fyi for big-tech comp, the BLS information security analysts data for general industry, and recent salary threads on r/cybersecurity for anecdata. Bring real numbers to negotiations.
What hiring managers actually look for
Distilled from interviewing hundreds of cloud security candidates and from years of conversations with hiring peers. The order matters.
- Hands-on evidence with the cloud you'll be working in. Public CloudGoat write-ups, blog posts, GitHub repos, conference talks. One CTF write-up beats three certs every time.
- The ability to explain IAM precisely. If you can't explain the difference between an identity-based and a resource-based policy, or between AssumeRole and trust policies, you fail the technical screen at most shops.
- Comfort with the command line and Terraform/CDK/Pulumi. Cloud security is API-first. The console is for hiring managers, not engineers.
- One cloud at depth, not three at surface. "I know AWS well, Azure passably, GCP barely" beats "I know AWS, Azure, and GCP" 90% of the time. Pick one.
- Specific incident or breach knowledge. Be able to walk through Capital One, MOVEit, MGM/Scattered Spider, or whatever's recent. The breach kill chains are interview fodder.
- A relevant cert as a baseline filter. Recruiters use certs to pass the resume screen. CCSK or your cloud's security specialty does the job. See the certifications guide.
- Communication. Most senior cloud security work is influence - convincing engineering teams to fix things. Candidates who write well and explain trade-offs without jargon stand out fast.
- Curiosity and momentum. "What did you learn last month?" If the answer is "nothing in particular," that's a no.
Hands-on portfolio plus a relevant cert beats a degree without practical work, every time. - from the “do I need a degree?” answer below
Interview formats you'll actually see
Loops vary, but the modules below cover ~90% of what shows up. Practice each one before you need to.
- Recruiter screen (30 min). Past experience, comp expectations, why this company. Bring a number.
- Hiring-manager screen (45-60 min). Deeper dive on your background and motivation. Often includes one technical question to filter obvious bluffers.
- Live IAM policy review. They paste an AWS or Azure policy. You read it and explain what it grants, what's wrong, and how you'd fix it. Practice with the AWS policy simulator and real-world examples from SummitRoute resources.
- Architecture review. They sketch a system (or share a real one). You identify the threats, controls, and trade-offs. STRIDE as a mental model. Don't be afraid to ask clarifying questions - interviewers are watching how you scope.
- Take-home lab. Increasingly common. Format is usually "here's a vulnerable AWS account or repo - find the issues, write up the kill chain and remediation." 4-8 hours of work, expect a follow-up call to walk through it.
- Live debugging / log analysis. They drop you in a CloudTrail / Sentinel / SCC console with a scenario ("user reports they think they were compromised"). You investigate aloud. Tests how you actually think.
- Detection design / threat modeling exercise. "Write a detection for this attack technique" or "what alerts would you build for this service?" Expect to map to MITRE ATT&CK.
- Behavioral / leadership. STAR-format stories. Specific, recent, with measurable outcomes. Have one for: a contentious security decision you won, one you lost, an incident you led, a time you changed your mind.
- Bar-raiser / cross-functional panel. Common at big tech. Less technical, more "would I want to work with this person." Don't underestimate.
Portfolio projects worth building
Your portfolio is your interview. Pick three of these, do them well, write each one up publicly. A blog (Substack, GitHub Pages, dev.to) plus a public GitHub is enough - no fancy site needed.
Each link below is a step-by-step walkthrough - prerequisites, the actual steps, what hiring managers look for in the write-up, and the common mistakes to avoid:
- Walk every CloudGoat scenario. Publish your kill chain, screenshots, and remediation for each. The canonical project - most interviewers have done it themselves and will recognize you've done the work.
- Build a multi-account AWS Organization with SCPs. Terraform a 3-account org, IAM Identity Center, and a baseline of SCPs. Push the code to GitHub. Real production-shaped work.
- Run Prowler against your own account and remediate everything. Document the before/after. Bonus: turn the remediation into Terraform.
- Build 5 detections in a lab SIEM. Spin up Wazuh, Elastic, or Matano; pick five MITRE ATT&CK Cloud techniques and write Sigma rules; validate with Stratus Red Team.
- Take a real breach, rebuild it in a lab. Recreate the Capital One architecture in your own account, exploit it end-to-end, then build the controls and detections that would have stopped it. Best single portfolio piece you can ship.
- Contribute to an open-source cloud security tool. Prowler, Cloud Custodian, Pacu, ROADtools, KICS, Steampipe - all welcome contributors. Even a small PR is a strong signal.
- Write a CNAPP comparison. Pick three (Wiz, Orca, Defender for Cloud, Prisma, Sysdig) and write an honest comparison. Hands-on trial work, false-positive sampling, and a who-should-pick-which section.
See the full portfolio playbook for time estimates, difficulty, and how to talk about each one in interviews.
What not to do: don't build a "cloud security dashboard" toy webapp. Hiring managers see hundreds. Build operational artifacts that look like real work.
Translating from an adjacent role
Most people don't enter cloud security cold. They pivot. The fastest path is usually one role-step from where you are now, not a leap straight to "Cloud Security Engineer."
From SOC analyst
You already understand alerts, triage, and incident workflow. Add: cloud-native log sources (CloudTrail, Activity Log, Audit Logs), GuardDuty / Defender / SCC, and one cloud's IAM model. Target: cloud-focused SOC roles or detection engineering.
From DevOps / SRE
You already know IaC, CI/CD, and at least one cloud at depth. Add: IAM specifics, threat modeling, posture management, common misconfigurations. Target: Cloud AppSec, IaC security, or platform security. Often the fastest pivot - security teams are desperate for engineers who can actually ship code.
From software developer
You know systems and code review. Add: AppSec fundamentals (OWASP Top 10), IaC scanning, supply-chain controls, container security. Target: Cloud AppSec, secure-by-design consulting roles. Strong pivot if you're a senior dev - security pays similarly and the work is varied.
From sysadmin / network engineer
You understand systems, networks, and "how things actually break." Add: IaC, the cloud-native equivalents of what you already do (security groups vs. firewall rules, IAM vs. AD, etc.), and one cloud's services. Target: cloud security generalist or network-security-in-cloud roles.
From traditional security (on-prem, GRC, AppSec)
You have the security mental model. Add: at least one cloud at operational depth, cloud-specific tooling, IaC. Target: the equivalent of your current role but cloud-flavored. Easiest pivot conceptually, hardest practically because hiring managers look hard for hands-on cloud evidence.
From totally outside tech
Longest road, but doable. Stage 1: get into IT (helpdesk, sysadmin, junior cloud). Stage 2: pivot to security from there. Trying to leap directly into a cloud security role is rarely successful. Plan for 18-36 months. Already on a help desk? The dedicated help desk to cloud security guide walks the whole staircase step by step.
The application game
- Resume: results, not responsibilities. "Reduced critical CSPM findings from 1,200 to 80 in 6 months" beats "responsible for cloud security posture." Numbers force specificity.
- One page if you're early-career, two pages max otherwise. Recruiters skim for 20 seconds. Make every line count.
- Tailor to the JD. Mirror the language of the posting (within reason). ATS systems literally pattern-match keywords.
- LinkedIn matters more than people admit. Recruiters source heavily from LinkedIn. Headline, banner, and "About" should make it obvious in 5 seconds what you do and what you want next. Post your write-ups there.
- Cold applications work, but referrals work better. Roughly 5-10x conversion rate from referral vs. cold apply. Coffee chats with people at companies you want to work at are the highest-leverage hour you'll spend in a job search.
- Show up where hiring happens. CSOH Friday Zoom, fwd:cloudsec, BSides, DEF CON Cloud Village, local meetups. Half of cloud security hiring happens through someone who knows someone.
- Negotiate. Always. The first number is rarely the best number. "Based on my research and other conversations, I was hoping for X" is the whole script.
Common mistakes
- Stacking certs without a portfolio. Three certs and zero CTF write-ups looks worse than one cert plus a public CloudGoat repo.
- Applying only to "cloud security engineer" roles. The titles you can land first might be "DevSecOps Engineer," "Security Analyst II," or "Cloud Engineer (Security focus)." Same work, broader funnel.
- Chasing big-tech FAANG comp before you have the experience. Big tech raises the bar; mid-market companies will hire you sooner and pay you to learn. You can move up later.
- Going dark for 6 months to "get ready." You learn faster in a job adjacent to your target than you do studying alone. Take the SOC role; pivot in 12 months.
- Treating the interview as a test. It's a conversation. The interviewer is also being evaluated by you - ask the questions you'd want answered before accepting.
- Skipping the take-home. If they ask for one, it usually means they value evidence over interviews. Strongest signal you can send.
- Not asking about the team's actual work. "What's the team's biggest unsolved problem this year?" tells you everything about whether you'd be happy. Ask it every loop.
Where next
- Cloud security learning path - the skills foundation underneath the hiring story.
- Build a safe home lab - the free-tier playground where the portfolio actually gets made.
- Certifications guide - which credential per career stage.
- Help desk to cloud security - the realistic transition guide if you're starting from IT support.
- Customer Success Engineer path - the post-sale, customer-facing vendor role and its many names.
- Cloud CTF directory - what to put in the portfolio.
- Job-search resources - boards, recruiters, and references.
- Reading list & people to follow - the practitioners and publications that hiring managers also read.
- Friday Zoom sessions - practitioners who hire and people who got hired. The single highest-leverage hour for a cloud security job-seeker.
Quick answers
What does a cloud security engineer actually do?
Day-to-day work splits across configuring and reviewing IAM policies, running posture management tools (CSPM/CNAPP) and triaging the findings, building detections in the SIEM, responding to alerts from GuardDuty/Defender/SCC, reviewing cloud architectures for security issues, automating guardrails (SCPs, Azure Policy, Org Policy), and writing runbooks. Less cloud-console clicking than people expect; more code review, IaC review, and arguing with engineers about least privilege.
How much do cloud security engineers make?
In the US, mid-level cloud security engineers (2-5 years) typically earn $140K-$190K base. Senior roles (5-8 years) run $180K-$240K base. Staff and principal levels often clear $250K base, with total comp of $350K+ at large tech companies. Numbers are lower outside major tech hubs and significantly lower outside the US. Contractor day rates run $800-$1,500 in the US.
Do I need a degree to get into cloud security?
No. The field is unusually credential-friendly: hands-on portfolio (CloudGoat write-ups, public repos, blog posts) plus a relevant cert (CCSK, AWS Security Specialty, or AZ-500) consistently outperforms a degree without practical work. Many practitioners come from sysadmin, SRE, dev, or SOC backgrounds with no cloud-security degree. A degree helps in regulated industries (defense, finance) and is occasionally a hard filter for federal roles.
What's the best way to break into cloud security with no experience?
Pick one cloud (AWS by default), get hands-on in your free-tier account, complete 5+ CTF scenarios from CloudGoat or similar and publish write-ups, earn one foundational cert (CCSK or your provider's fundamentals), then target adjacent-role pivots first: DevOps engineer, SOC analyst, or junior cloud engineer with a security focus. Pure 'cloud security engineer' roles rarely take true beginners; the pivot path is faster than the cold application path.