Skip to main content
Cloud security

Cloud Security Engineer

Cloud-native IAM, workload security, policy-as-code. Entered from cloud, not from SOC.

Last reviewed May 2026Reviewed by a practitioner working in cloud security engineer hiringUpdated quarterly against live job listings
The verdict

The right specialisation if you already know cloud. A bad first job if you don't, no matter how interesting it sounds.

You've worked as a cloud or platform engineer for a couple of years and you want to specialise without leaving the cloud world. Policy-as-code, workload identity, and IAM at scale are where the work is.

You're trying to jump in from a SOC seat without ever having built infrastructure. Cloud security hiring assumes you can read Terraform and reason about a VPC, and bluffing through that interview is hard.

Phased progression

Foundations → first role → specialisation → advanced. The realistic order, not a script.

  1. 01Foundations
    0–6 months

    Literacy, lab habits, the cert that opens first conversations.

    AZ-500
  2. 02First paid role
    6–18 months

    Land a Cloud Security Engineer. Operational time, not more certs, earns the next move.

    Cloud Security Engineer
    £65–90k mid
  3. 03Specialisation
    1.5–3 years

    Add a specialist credential aligned to the work you're already doing.

    AWS Security SpecialtyTerraform Associate
    £95–130k senior cloud security (UK)
  4. 04Advanced
    3+ years

    Move into adjacent roles. Long-term credentials become worth their cost.

    Platform Security EngineerCCSP
    £95–130k senior cloud security (UK)

Certification sequence

Ordered by realistic relevance, not vendor marketing.

  • Terraform Associate
  • CCSP
  • SC-100

Practical projects

What to actually build, the portfolio that opens interviews.

  • Author OPA / Cedar policies against a real cloud account
  • Implement guardrails with AWS Control Tower or Azure Policy
  • Build a workload-identity setup with no static keys
Platform Security EngineerSecurity ArchitectCloud Architect
  • ·Platform security via the platform team
  • ·Security architect via senior cloud architect

Realistic expectations

What no recruiter will tell you.

Misconception

That a cloud security cert is enough on its own. The market wants people who've shipped cloud infrastructure and then learned to secure it, not the reverse.

Honest window

Two to four years from a working cloud or platform role. Faster if your current employer has a security team you can pivot into internally.

Where this fits

A pathway is a sequence, not a destination. Here are the roles and certs along it.

The next step

The pathway is plausible. Whether it holds for five years is a different question.

A Career Verdict applies the framework to your actual stage and stack: what holds, what breaks, what would change the call.

A route shows what people usually do. A Career Verdict judges whether it's realistic for you.

Get a judgement on your situation£39, one-off. Built for your inputs, yours to keep.

Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.