Cloud Security Engineer
Cloud-native IAM, workload security, policy-as-code. Entered from cloud, not from SOC.
The right specialisation if you already know cloud. A bad first job if you don't, no matter how interesting it sounds.
You've worked as a cloud or platform engineer for a couple of years and you want to specialise without leaving the cloud world. Policy-as-code, workload identity, and IAM at scale are where the work is.
You're trying to jump in from a SOC seat without ever having built infrastructure. Cloud security hiring assumes you can read Terraform and reason about a VPC, and bluffing through that interview is hard.
Phased progression
Foundations → first role → specialisation → advanced. The realistic order, not a script.
- 010–6 monthsFoundations
Literacy, lab habits, the cert that opens first conversations.
AZ-500 - 026–18 monthsFirst paid role
Land a Cloud Security Engineer. Operational time, not more certs, earns the next move.
Cloud Security Engineer£65–90k mid - 031.5–3 yearsSpecialisation
Add a specialist credential aligned to the work you're already doing.
AWS Security SpecialtyTerraform Associate£95–130k senior cloud security (UK) - 043+ yearsAdvanced
Move into adjacent roles. Long-term credentials become worth their cost.
Platform Security EngineerCCSP£95–130k senior cloud security (UK)
- 01Foundations0–6 months
Literacy, lab habits, the cert that opens first conversations.
AZ-500 - 02First paid role6–18 months
Land a Cloud Security Engineer. Operational time, not more certs, earns the next move.
Cloud Security Engineer£65–90k mid - 03Specialisation1.5–3 years
Add a specialist credential aligned to the work you're already doing.
AWS Security SpecialtyTerraform Associate£95–130k senior cloud security (UK) - 04Advanced3+ years
Move into adjacent roles. Long-term credentials become worth their cost.
Platform Security EngineerCCSP£95–130k senior cloud security (UK)
Certification sequence
Ordered by realistic relevance, not vendor marketing.
Practical projects
What to actually build, the portfolio that opens interviews.
- Author OPA / Cedar policies against a real cloud account
- Implement guardrails with AWS Control Tower or Azure Policy
- Build a workload-identity setup with no static keys
- ·Platform security via the platform team
- ·Security architect via senior cloud architect
Realistic expectations
What no recruiter will tell you.
That a cloud security cert is enough on its own. The market wants people who've shipped cloud infrastructure and then learned to secure it, not the reverse.
Two to four years from a working cloud or platform role. Faster if your current employer has a security team you can pivot into internally.
Where this fits
A pathway is a sequence, not a destination. Here are the roles and certs along it.
- Security Architect (after 7+ years)
Design the trust boundaries. Pursued after 7+ years of hands-on work, not as a starting lane.
- GRC (Audit, Risk, Compliance)
Governance, risk and compliance. Policy, audit, evidence, frameworks. Biased toward CISA / CRISC / CISM, NOT toward OSCP.
- Cloud Engineer → Cloud Architect
Highest-paid generalist track. Stack: networking + Linux + cloud + IaC.
- Is CISSP actually worth it in 2026?
Yes, but only for a specific person at a specific moment. For everyone else it's 12–18 months optimising for the wrong thing.
- Cloud engineering isn't entry-level anymore
In progress. The market that hired junior cloud engineers in 2019 doesn't exist. What replaced it, and the realistic path in.
The next step
The pathway is plausible. Whether it holds for five years is a different question.
A Career Verdict applies the framework to your actual stage and stack: what holds, what breaks, what would change the call.
A route shows what people usually do. A Career Verdict judges whether it's realistic for you.
A Career Verdict includes
Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.