Information Technology
Cloud Security Analyst II Job Description
Cloud Security Analyst II is a mid-level practitioner role that combines independent threat detection and incident response with mentorship responsibilities and deeper technical specialization. Analysts at this level operate with minimal oversight, lead investigations on complex incidents, contribute to detection engineering, and serve as a resource for junior analysts on the team.
Last updated
Role at a glance
- Typical education
- Bachelor's degree in CS, Information Security, or equivalent experience
- Typical experience
- 3-6 years
- Key certifications
- AWS Certified Security Specialty, Azure Security Engineer Associate, SANS GIAC GCIH, CompTIA CySA+
- Top employer types
- Cloud providers, financial services, large technology companies, enterprise organizations
- Growth outlook
- Strong demand driven by cloud migration and the scarcity of independent, mid-level practitioners.
- AI impact (through 2030)
- Augmentation and expanding scope — AI introduces new attack vectors like model abuse that require advanced detection engineering, while automating routine log analysis allows analysts to focus on complex threat hunting.
Duties and responsibilities
- Lead cloud security incident investigations independently, including scoping, containment, evidence collection, and post-incident reporting
- Conduct proactive threat hunting across cloud logs, identifying attacker behaviors that automated detection missed
- Develop and tune detection rules for cloud-specific attack techniques, reducing false positive rates while improving detection coverage
- Analyze complex IAM configurations to identify privilege escalation paths, cross-account trust issues, and least-privilege violations
- Perform forensic analysis of compromised cloud workloads — container snapshots, memory acquisition, API call reconstruction from logs
- Mentor and technically guide Analyst I team members, reviewing their investigation work and helping build their cloud security skills
- Evaluate new security tooling through structured proof-of-concept assessments, comparing effectiveness against current stack
- Contribute to the security runbooks and playbooks that guide incident response procedures for cloud environments
- Participate in purple team exercises and red team findings review to improve cloud detection coverage
- Brief engineering teams, security leadership, and occasionally executives on investigation findings and risk implications
Overview
Cloud Security Analyst II is the mid-career inflection point in cloud security operations — the level where practitioners transition from working through defined procedures to handling novel situations independently and contributing to the team's collective capability.
At the core, the Analyst II is still doing threat detection and incident response. They monitor alerts, investigate events, and contain threats. The difference is the complexity of what they're expected to handle independently. A Level II analyst leads the investigation on a sophisticated incident — an IAM credential compromise that spans multiple accounts and involves lateral movement across cloud services — rather than handing it off when the playbook runs out. They make containment decisions under time pressure, manage the stakeholder communication, and produce the post-incident report.
Threat hunting is where Analyst II practitioners distinguish themselves. Automated detection catches known attack patterns; hunters look for attacker behavior that doesn't match existing rules. At this level, analysts should be able to form hypotheses about what attacker activity might look like in their environment, translate those hypotheses into log queries, and pursue findings that are ambiguous enough that a junior analyst wouldn't know whether they were significant. The ability to find things that weren't being looked for is what advances practitioners from mid-level to senior.
Detection engineering is the other growth area. Writing detection rules — not just deploying ones that came with the SIEM — requires understanding both the attack technique being detected and the characteristics of normal behavior that the rule needs to avoid flagging. Tuning an existing rule to reduce false positives without reducing true positive coverage is harder than it looks and represents a skill that Analyst II practitioners are expected to develop.
Mentorship rounds out the role. Level II analysts are typically a resource for Level I analysts on difficult investigations, and the experience of explaining security concepts and investigative approaches to less experienced colleagues deepens the Analyst II's own understanding.
Qualifications
Education:
- Bachelor's degree in computer science, information security, or related field
- Equivalent experience accepted at most employers if certifications and portfolio of work are strong
Certifications:
- AWS Certified Security Specialty — standard expectation at this level for AWS environments
- Azure Security Engineer Associate (AZ-500) — equivalent for Azure-focused roles
- SANS GIAC GCIH or GCIA — respected in the incident response community
- CompTIA CySA+ — useful if still working toward GIAC or cloud-specific certs
Experience:
- 3–6 years in security operations or cloud security roles
- Demonstrated independent incident response — cases where the analyst led the investigation without a playbook
- Evidence of detection engineering work: custom rules written, false positive rates improved, new detection categories built
Technical skills:
- Log analysis: CloudTrail, Azure Activity Logs, GCP Audit Logs — complex multi-hop query patterns
- SIEM proficiency: Splunk SPL, KQL for Sentinel, or equivalent — intermediate to advanced query construction
- Cloud attack techniques: MITRE ATT&CK for Cloud — at least 20–30 techniques at working knowledge level
- Forensic skills: container snapshot analysis, log-based timeline reconstruction, IAM policy path analysis
- Detection rule development: Sigma, KQL, Splunk SPL, YARA-L — writes and validates new rules
- Programming: Python for log processing, custom detections, and tooling automation at intermediate level
Soft skills:
- Clear incident communication to technical and non-technical stakeholders under pressure
- Patience and structure for mentoring less experienced analysts
- Ability to write clear, evidence-based investigation reports
Career outlook
The Cloud Security Analyst II level is the first rung where practitioners have enough specialized knowledge to command meaningful compensation premiums and enough independence to be genuinely productive without close supervision. It's also the level where retention becomes a challenge for employers — Analyst II practitioners are experienced enough to be attractive to competing organizations, and turnover at this level is expensive.
Demand at the mid-level is strong. Organizations that are investing in cloud security programs need analysts who can operate independently and who don't require months of development before contributing. The pipeline from Analyst I to Analyst II is long — 3–4 years of development — which constrains supply and keeps compensation above what the title alone might suggest.
Specialization is becoming more valuable at this career stage. Cloud security is broad enough that practitioners who develop deep expertise in a specific area — IAM security, container security, detection engineering, cloud forensics — command higher compensation than generalists. The specialization also differentiates candidates in competitive hiring processes.
The threat landscape continues to evolve, which keeps the work technically challenging. Cloud credential theft, supply chain attacks on cloud-deployed applications, and AI model abuse are all emerging attack categories that require analysts to continuously develop new skills. Practitioners who approach this requirement as an opportunity rather than a burden tend to advance faster.
From Analyst II, the typical progressions are Senior Cloud Security Analyst, Detection Engineer, Threat Hunter, or Cloud Security Architect. Management tracks open at the senior level for those who develop the organizational skills to complement their technical depth. At large financial services and technology companies, senior and principal individual contributors reach $160K–$190K before accounting for bonuses — making the technical track financially competitive with management alternatives.
Sample cover letter
Dear Hiring Manager,
I'm applying for the Cloud Security Analyst II position at [Company]. I've been a cloud security analyst at [Current Company] for three and a half years — the first year focused on getting comfortable with the environment and our tooling, and the last two and a half years taking ownership of our more complex investigations and contributing to our detection improvement program.
The investigation I'm most proud of was a credential compromise that started as a single GuardDuty finding and expanded into a two-week investigation across four AWS accounts. I traced the initial credential exposure to an overly permissive CI/CD pipeline permission, followed the lateral movement through CloudTrail across three accounts, identified two instances where the attacker had staged data for exfiltration without actually exfiltrating it, and documented the full attack path in a 15-page investigation report. The CISO presented the report to the board's audit committee as an example of our security program's detection capability.
On the detection side, I've written 11 custom detection rules over the last year — eight for CloudTrail anomaly patterns and three for container runtime behavior. The most impactful was a rule that detects IMDS credential access followed within 60 seconds by cross-account STS assume-role calls — a pattern that indicates automated exploitation rather than legitimate infrastructure behavior. It caught two incidents in its first three months.
I'm looking for a role where I can deepen my Azure security skills — currently about 80% of my experience is AWS — and work alongside senior practitioners who are doing advanced threat hunting work.
I'd welcome a conversation.
[Your Name]
Frequently asked questions
- What does a Cloud Security Analyst II do?
- Cloud Security Analyst II is a mid-level practitioner role that combines independent threat detection and incident response with mentorship responsibilities and deeper technical specialization. Analysts at this level operate with minimal oversight, lead investigations on complex incidents, contribute to detection engineering, and serve as a resource for junior analysts on the team.
- What are the main duties of a Cloud Security Analyst II?
- Core duties include: lead cloud security incident investigations independently, including scoping, containment, evidence collection, and post-incident reporting; conduct proactive threat hunting across cloud logs, identifying attacker behaviors that automated detection missed; and develop and tune detection rules for cloud-specific attack techniques, reducing false positive rates while improving detection coverage.
- What separates a Cloud Security Analyst II from a Level I?
- Level I analysts work through defined playbooks with supervisor review. Level II analysts are expected to investigate novel incidents without a playbook, make independent containment decisions under time pressure, and communicate findings to stakeholders without hand-holding. The technical skills difference is real but the independence and judgment gap is often larger. Most organizations expect 2–4 years of security analyst experience before promoting to Level II.
- What does cloud threat hunting actually involve day-to-day?
- Threat hunting starts with a hypothesis — for example, 'if an attacker has stolen an IAM credential, they will try to enumerate what access the credential has before exploiting it.' The hunter then queries CloudTrail or Azure Activity Logs for that enumeration pattern, looking for instances where it occurred without a corresponding business justification. If the pattern appears, the investigation begins. Most hunts find nothing; the value is in the few that find attacker activity that automated detection missed.
- Do Cloud Security Analyst II roles require management skills?
- Not formal management — the II title is an individual contributor role. But mentorship and informal technical leadership are expected. Level II analysts review Level I investigation work, answer questions, and help develop newer team members' skills. Organizations that value career-track growth want Level II analysts who are developing the technical leadership skills that eventually lead to senior, lead, or management roles.
- How important is detection engineering at this level?
- It's a differentiator. Level I analysts primarily consume detections built by others. Level II analysts are expected to contribute to the detection library — writing new rules, tuning existing ones to reduce noise, and mapping gaps in coverage to cloud attack techniques. The ability to build a detection rule in Sigma or a KQL query in Microsoft Sentinel, test it against real log data, and validate it against known-good behavior patterns is a skill that marks a practitioner ready for senior roles.
- What cloud certifications are relevant at the Level II career stage?
- By Level II, practitioners should have at least one cloud-specific security certification — AWS Security Specialty or AZ-500. SANS GIAC certifications become more relevant at this level: GCIH (Incident Handler) or GCIA (Intrusion Analyst) for detection and response depth. OSCP is valued if offensive security knowledge is part of the role. Some analysts pursue CISSP or CISM as they approach senior level, building the breadth needed for leadership roles.
Related job descriptions
See all Information Technology jobs →- Cloud Security Engineer II$140K–$190K
Cloud Security Engineer II is a mid-level practitioner who operates independently on complex security engineering projects, owns portions of the cloud security tooling platform, mentors junior engineers, and contributes architectural input to security program decisions. Engineers at this level are expected to drive projects from design through delivery without close supervision.
- Cloud Security Specialist II$115K–$165K
Cloud Security Specialist II is the advanced tier of cloud security specialization — practitioners who have built recognized expertise in their domain, are driving program decisions beyond their immediate team, and are developing the organizational influence and mentorship skills that mark the transition toward principal-level contribution.
- IT Security Analyst II$78K–$118K
An IT Security Analyst II is a mid-level cybersecurity professional responsible for monitoring, detecting, and responding to security threats across enterprise networks and systems. Operating above entry-level triage and below senior architecture roles, they own incident response investigations, conduct vulnerability assessments, tune SIEM rules, and translate technical findings into actionable remediation guidance for engineering and IT teams.
- Cloud Security Analyst$85K–$125K
Cloud Security Analysts monitor cloud environments for threats, investigate security events, assess compliance posture, and support incident response activities. They operate in the intersection of cloud operations and security operations, using cloud-native and third-party security tools to detect and analyze threats before they become breaches.
- Cloud Data Analyst II$95K–$135K
Cloud Data Analyst II is a mid-senior level designation for data analysts who work independently on complex analysis projects, own production data models, and serve as the analytical resource for key stakeholder relationships. The II level implies demonstrated competence at foundational analysis tasks and the ability to scope and execute multi-week projects without close supervision.
- IT Security Consultant II$95K–$145K
An IT Security Consultant II is a mid-senior cybersecurity practitioner who assesses, designs, and implements security controls for client or enterprise environments. They conduct risk assessments, lead penetration testing engagements, develop security architecture recommendations, and guide organizations through compliance frameworks such as NIST, ISO 27001, and SOC 2. The role sits above entry-level analyst work and below principal or architect-level strategy — it is where deep technical execution meets client-facing advisory responsibility.