Information Technology
Cloud Security Engineer II Job Description
Cloud Security Engineer II is a mid-level practitioner who operates independently on complex security engineering projects, owns portions of the cloud security tooling platform, mentors junior engineers, and contributes architectural input to security program decisions. Engineers at this level are expected to drive projects from design through delivery without close supervision.
Last updated
Role at a glance
- Typical education
- Bachelor's degree in CS, software engineering, or information security or equivalent experience
- Typical experience
- 4-7 years total, with 3+ years in cloud security
- Key certifications
- AWS Certified Security Specialty, Azure Security Engineer Associate, Certified Kubernetes Security Specialist, CISSP
- Top employer types
- Financial services, healthcare, regulated industries, major technology companies
- Growth outlook
- Strong demand; supply of practitioners remains persistently below demand
- AI impact (through 2030)
- Strong tailwind — demand is expanding rapidly as organizations require engineers to extend security architectures to cover new AI-specific attack surfaces like GPU clusters and LLM inference services.
Duties and responsibilities
- Own and maintain major components of the cloud security tooling platform: CSPM integration, identity governance tooling, or detection pipeline infrastructure
- Design and implement complex IAM control architectures including multi-account trust structures, privileged access workflows, and federated identity configurations
- Build security automation systems that enforce policies at scale — policy-as-code frameworks, auto-remediation workflows, and compliance reporting pipelines
- Lead cloud security projects from requirements through delivery, coordinating with platform engineering, DevOps, and application teams
- Conduct threat modeling for cloud-native architectures, identifying attack surfaces and recommending defensive designs before implementation
- Develop advanced detection capabilities for cloud-specific attack techniques, including building custom data sources not covered by commercial tooling
- Evaluate and recommend new security tools and approaches, leading proof-of-concept assessments and vendor technical evaluations
- Mentor Level I cloud security engineers through code reviews, architecture discussions, and one-on-one technical guidance
- Document security control architectures, design decisions, and operational procedures to standards that support audit and knowledge transfer requirements
- Represent cloud security requirements in architecture review boards, pre-deployment design reviews, and engineering planning processes
Overview
Cloud Security Engineer II is the level where cloud security practitioners move from executing assigned work to owning technical domains. Level II engineers are responsible for components of the security platform that run in production and that other teams depend on — the IAM vending system, the detection pipeline, the compliance automation framework. When those components have issues, the Level II engineer is expected to diagnose and fix them without escalating.
Project ownership is the defining characteristic. A Level II engineer doesn't just build what's specified — they develop the specification. When a new requirement comes in — say, implementing workload identity federation for Kubernetes pods to access cloud resources without long-lived credentials — the Level II engineer is expected to research the options, recommend an architecture, get feedback from senior engineers and architects, and deliver the implementation. The loop from problem to production runs through their judgment.
Threat modeling is where Level II engineers contribute most visibly to the security posture of new systems. When a platform team is designing a new data pipeline or a product team is building a new API, the cloud security engineer is expected to review the design and identify the security implications. That review needs to be specific enough to be actionable — not a generic security checklist but an assessment of the specific attack surfaces in the specific design, with specific recommended controls.
Mentoring Level I engineers is an expectation, not just an opportunity. Level II engineers are a resource for their less-experienced colleagues on technical questions, code reviews, and complex investigations. The experience of explaining security concepts to someone building their skills typically deepens the Level II engineer's own understanding as well.
Automation quality matters at this level. Level II engineers are expected to build automation that works reliably in production — not just scripts that run correctly when manually executed but systems with error handling, logging, alerting, and operational runbooks. The difference between a proof-of-concept script and production-grade security automation is engineering discipline that Level II practitioners are expected to demonstrate.
Qualifications
Education:
- Bachelor's degree in computer science, software engineering, or information security
- Equivalent hands-on experience accepted at most organizations if backed by strong certifications and portfolio
Certifications:
- AWS Certified Security Specialty — required at most AWS-focused organizations at this level
- Azure Security Engineer Associate (AZ-500) — required for Azure-focused roles
- Certified Kubernetes Security Specialist (CKS) — expected if containers are in scope
- HashiCorp Terraform Associate or Professional
- CISSP for roles with compliance and program exposure
Experience:
- 4–7 years total, with 3+ years specifically in cloud security engineering
- Demonstrable ownership of a cloud security component or system — something that runs in production and that the team depends on
- Code portfolio showing Terraform modules, Python automation, or custom detection logic
Technical skills (intermediate to advanced):
- IAM: multi-account trust architectures, permission boundaries, SCP design, federated identity
- Policy-as-code: OPA/Rego at intermediate level — custom policy authoring, not just deploying pre-written policies
- Detection engineering: custom rule development in Sigma, KQL, or SPL; integrating non-standard log sources
- Container security: Kubernetes RBAC, admission controllers, OPA Gatekeeper, Falco rule authoring
- Secrets management: Vault dynamic secrets, AWS Secrets Manager rotation automation
- Programming: Python at intermediate level — classes, testing, error handling, API integrations
Engineering discipline:
- Version control: Git-based workflows, pull request processes, code review practices
- CI/CD integration: security controls deployed through pipelines, not manual processes
- Documentation standards: design documents, runbooks, and architecture diagrams at audit-quality level
Career outlook
The Level II tier in cloud security engineering is the most active hiring tier in the specialty. Organizations that have moved past early-stage security programs are looking for engineers who can own technical domains independently — not just implement instructions but drive solutions from design through production. The supply of practitioners at this level with the right combination of skills remains persistently below demand.
Compensation at Level II reflects the scarcity. The salary range puts Level II Cloud Security Engineers at or above comparably-experienced software engineers at most companies, with the gap widening at organizations in financial services, healthcare, and other regulated industries where cloud security is tied to compliance outcomes.
AI security engineering is the highest-growth area within the specialty right now. Organizations deploying ML workloads on cloud infrastructure — GPU clusters, model training pipelines, LLM inference services — need engineers who can extend existing cloud security control architectures to cover AI-specific attack surface. This requires combining cloud security engineering fundamentals with developing AI security knowledge, and the practitioners who are building that combination early have a significant advantage.
The cloud security engineering skill set is also increasingly portable across cloud providers. An engineer who has deep AWS security expertise and working knowledge of Azure and GCP can move between employers with different cloud configurations more easily than a general software engineer whose skills are more employer-specific. That portability contributes to the leverage practitioners have in compensation negotiations.
Progression from Level II typically goes to Senior Cloud Security Engineer, Staff Engineer, or Security Architect. The Senior designation requires demonstrated architectural influence and technical leadership beyond the Level II scope. Total compensation at the senior level at major technology companies frequently exceeds $200K including equity — making the technical track financially competitive with engineering management alternatives.
Sample cover letter
Dear Hiring Manager,
I'm applying for the Cloud Security Engineer II position at [Company]. I've been in cloud security engineering for five years, the last three at [Current Company] where I've owned our IAM control architecture and our policy-as-code framework for an AWS environment covering 40 accounts.
The project I've contributed most to is our IAM vending system. When I joined, developer teams provisioned IAM roles directly through the console with inconsistent permission scopes and no tagging. I designed a Terraform-based role provisioning module that engineers request through a GitOps workflow — they submit a pull request with their role requirements, our validation pipeline checks it against a policy library I wrote in OPA/Rego, and approved requests deploy automatically. It's been in production for two years and processes about 30 role changes per week. Manual IAM changes in developer accounts dropped to near zero.
I also built our detection pipeline using EventBridge and Lambda. I wrote 28 custom detection rules beyond what GuardDuty covers natively — primarily behavioral detections for IAM enumeration patterns, cross-account access anomalies, and data access outside business hours. I instrument each rule with CloudWatch metrics so I can track false positive rates over time and tune them. Current false positive rate across the custom rule set is about 12%, down from 31% when I started tracking it.
I hold AWS Security Specialty and Terraform Associate, and I'm actively studying for CKS — our Kubernetes workloads are a gap in my current security coverage that I want to close.
I'm interested in [Company] because of your Kubernetes-first infrastructure and the scale of the engineering organization. I'd welcome a conversation.
[Your Name]
Frequently asked questions
- What does a Cloud Security Engineer II do?
- Cloud Security Engineer II is a mid-level practitioner who operates independently on complex security engineering projects, owns portions of the cloud security tooling platform, mentors junior engineers, and contributes architectural input to security program decisions. Engineers at this level are expected to drive projects from design through delivery without close supervision.
- What are the main duties of a Cloud Security Engineer II?
- Core duties include: own and maintain major components of the cloud security tooling platform: CSPM integration, identity governance tooling, or detection pipeline infrastructure; design and implement complex IAM control architectures including multi-account trust structures, privileged access workflows, and federated identity configurations; and build security automation systems that enforce policies at scale — policy-as-code frameworks, auto-remediation workflows, and compliance reporting pipelines.
- What typically distinguishes a Level II Cloud Security Engineer from Level I?
- Level I engineers execute well-defined tasks with supervision and are growing into the technical domain. Level II engineers own components independently, design solutions rather than executing defined designs, and contribute architectural judgment that influences how security controls are built. The practical difference shows up most clearly on ambiguous problems — a Level II engineer is expected to develop the approach, not just execute an approach given to them.
- Is threat modeling a core skill at Level II?
- Yes. Level II engineers are expected to review cloud architectures and identify threats before implementation — not just react to misconfigurations after deployment. Threat modeling in cloud contexts means understanding how services interact, where data flows, what IAM permissions enable, and which attack patterns the design is susceptible to. Structured methodologies like STRIDE are a starting framework; effective threat modelers develop judgment that goes beyond the checklist.
- How much of the Level II role involves writing code versus configuring tools?
- It varies by organization but generally shifts further toward coding at Level II compared to Level I. Building automation systems, developing custom detection logic, and creating policy-as-code frameworks are all coding-heavy work. Level II engineers who rely primarily on UI-based tool configuration and pre-built scripts are leaving capabilities on the table that more effective practitioners develop. Python and Terraform at intermediate to advanced levels are essentially required at this career stage.
- What's the best path from Level II to Senior Cloud Security Engineer?
- The clearest path involves demonstrating that you can own a technically significant project end-to-end — from requirements through design, implementation, and operation — and contribute architectural thinking that influences how the broader program is built. Mentoring junior engineers and building a reputation for solid engineering judgment with stakeholders outside the security team also mark readiness for senior designation. Most organizations expect 3–5 years total cloud security engineering experience before promoting to senior.
- How are AI security requirements changing what Level II engineers build?
- AI workloads on cloud infrastructure create new security engineering requirements: securing model artifact storage, governing IAM access to training data pipelines, monitoring LLM inference APIs for data exfiltration, and integrating AI system deployments into existing policy-as-code frameworks. Level II engineers are being asked to extend their existing control architectures to cover AI workloads — which requires learning new threat models before well-established defensive patterns exist.
Related job descriptions
See all Information Technology jobs →- Cloud Security Analyst II$100K–$145K
Cloud Security Analyst II is a mid-level practitioner role that combines independent threat detection and incident response with mentorship responsibilities and deeper technical specialization. Analysts at this level operate with minimal oversight, lead investigations on complex incidents, contribute to detection engineering, and serve as a resource for junior analysts on the team.
- Cloud Security Specialist II$115K–$165K
Cloud Security Specialist II is the advanced tier of cloud security specialization — practitioners who have built recognized expertise in their domain, are driving program decisions beyond their immediate team, and are developing the organizational influence and mentorship skills that mark the transition toward principal-level contribution.
- Cloud Security Engineer$120K–$175K
Cloud Security Engineers design and build the security controls, automation, and tooling that protect cloud infrastructure at scale. They write infrastructure-as-code for security configurations, automate compliance checks, build detection pipelines, harden cloud environments, and serve as the technical bridge between security strategy and engineering execution.
- DevSecOps Cloud Security Engineer$115K–$185K
DevSecOps Cloud Security Engineers embed security controls directly into software delivery pipelines and cloud infrastructure, shifting vulnerability detection left toward development rather than catching issues after deployment. They design and enforce security guardrails across AWS, Azure, or GCP environments, automate compliance checks in CI/CD toolchains, and work alongside application and platform engineering teams to make security a built-in property rather than a bolt-on review. The role sits at the intersection of software engineering, cloud operations, and information security.
- Cloud Automation Engineer II$120K–$165K
Cloud Automation Engineer II is a mid-to-senior level role for practitioners who independently own significant automation workstreams, design IaC frameworks rather than just implementing them, and actively shape the direction of a cloud automation or platform engineering function. At this level, engineers are expected to set technical standards, mentor junior engineers, and drive improvements to platform capabilities beyond their individual task queue.
- Cloud DevOps Engineer II$110K–$155K
A Cloud DevOps Engineer II is a mid-level practitioner who builds and maintains the CI/CD pipelines, container infrastructure, and cloud automation that development teams rely on to ship software reliably. They work across cloud providers and internal tooling with enough autonomy to own substantial platform components end-to-end.