Cloud Engineer
Provision, glue services, fight IAM, own one cloud account end-to-end.
The single best risk-adjusted move from sysadmin or networking right now, provided you've already shipped something in a real AWS or Azure account.
- You've got two-plus years of Linux or networking and want a salary jump
- You enjoy IAM puzzles and reading other people's Terraform without crying
- You're happy working in tickets, PRs and reviews, less keyboard-on, more thinking
- You'll keep building lab projects, not just collecting certifications
- You haven't touched a console yet, do the rep work first or you'll bomb the interview
- You want the title without the on-call, mid-sized orgs almost always pair them
- You think AWS SAA on its own opens the door, in 2026 it doesn't
- You can debug an IAM problem without resorting to wildcard policies
- Your PRs get merged with minor feedback, not full rewrites
- You're the one who notices the cost spike before finance does
- You can explain your design choices to a stakeholder who doesn't care about the tech
The interview market has hardened. Two years ago a SAA plus a half-decent CV got you a phone screen. Now you're competing with people who've migrated production workloads, owned a P1 outage in cloud, and can talk through a landing zone from memory. If your only cloud time is in your own sandbox account, you'll plateau at interview stage for six months before you work out what's missing. Build something that mattered to someone other than you.
Tradeoffs at a glance
Hover any chip for the calibrated meaning. Ratings are directional, not absolute.
Promotion ceiling
Strong. Senior cloud / staff platform is one of the best-paid IC tracks.
- +Sysadmin
- +Network engineer
- +Backend dev
- −That AWS SAA gets you the job, projects with real IaC do.
Where this leads
- DevOps / Platform
- Cloud Security
- Solutions Architect
Certifications people pair with this
Listed because the graph connects them to this role, not because you need all of them. Most practitioners pick one or two.
Pathways that pass through here
- Cloud Engineer → Cloud Architect
Highest-paid generalist track. Stack: networking + Linux + cloud + IaC.
- Cloud Security Engineer
Cloud-native IAM, workload security, policy-as-code. Entered from cloud, not from SOC.
- Identity Security (IAM, PAM, SSO)
Engineer the identity layer. Entra ID, Okta, CyberArk, PAM, SSO, MFA, Zero Trust. Operational, technical, in demand.
Where this fits
Roles connect to pathways, certs and other roles. Use one to test the next.
- Cloud Engineer → Cloud Architect
Highest-paid generalist track. Stack: networking + Linux + cloud + IaC.
- Cloud Security Engineer
Cloud-native IAM, workload security, policy-as-code. Entered from cloud, not from SOC.
- Platform / DevOps Engineer → SRE
Build the systems other engineers depend on. Requires coding fluency. Rarely entry-level.
The serious next step
You've read about the role. The harder question is whether it's the right one for you.
A Career Verdict is the written, practitioner-authored call on your specific route into and out of this role. Six primitives, same format every time.
Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.