One Cloud Security Engineer, assigned to your product and fully managed.

We assign a Cloud Security Engineer to your team full time and run everything around them: a service delivery manager who answers for the work, training and coaching, the office and equipment, and HR and payroll. The price below is for a mid-level Cloud Security Engineer; junior and senior levels are priced in your proposal, and how the monthly fee is built explains the arithmetic.

From price

One mid-level Cloud Security Engineer, full time, everything below included. All 27 things included ››

  • Cloud security engineer From USD 3,900 per month
  • Service

    We manage and develop the team

    • A service delivery manager who runs the team and answers for delivery
    • A 1:1 with our Head of Delivery every two weeks
    • Weekly delivery scoring and monthly capacity reports
    • A Talent Success Manager for every specialist
  • HR

    We are the employer

    • Recruitment and technical assessment
    • Employment contracts
    • Salary and payroll
    • Tax and social security
  • Facilitation

    We provide the workplace

    • A desk in our own office in Chiang Mai or Bangkok
    • A Workplace Experience Manager on site
    • Team events through the year
    • IT support
  • Equipment

    We supply the tools

    • Laptop and hardware
    • Software licences
    • LinkedIn Learning access
    • Device security and management

What a Cloud Security Engineer does on a dedicated cybersecurity team.

They work in your cloud accounts and infrastructure code under your access controls, with your platform and DevOps engineers, and ship security changes the same way every other change ships.

Cloud Security Engineer skills and technologies

  • Least-privilege identity and access, from human users to service accounts and CI roles.

  • Network design and segmentation, so a single exposed service can't reach everything behind it.

  • Configuration reviews against recognised benchmarks, with fixes written as infrastructure code instead of console clicks.

  • Encryption, key management and logging set up so an incident can be investigated afterwards.

  • Kubernetes and container security, from image scanning to runtime permissions.

Cloud Security Engineer seniority levels.

Mid-level to senior. Cloud permissions are easy to get wrong in ways that stay invisible until they matter, so experience across several cloud estates pays off. Seniority is one of the inputs into how the monthly fee is built.

When your team needs a Cloud Security Engineer.

Assigned when a cloud estate has grown faster than its access rules, after a security review flags misconfigurations, or ahead of an audit. Pairs with a DevSecOps engineer who keeps the same rules in the pipeline. Cloud security engineers join as part of a dedicated cybersecurity team at Azendo. It is a targeted addition for companies that hire a dedicated development team on AWS, Azure or GCP.

What we look for in a dedicated Cloud Security Engineer.

We look for engineers who think in permissions and blast radius. They read an IAM policy the way a developer reads code, and they prefer a reviewed Terraform change to a quick fix in the console.

A remote Cloud Security Engineer's first three months on your team.

  1. Weeks 1 to 2Reviewing your accounts, identities, networks and logging against a benchmark, and ranking the findings.
  2. Weeks 3 to 6Fixing the highest risks first, as infrastructure code, starting with access and exposed services.
  3. Months 2 to 3Setting guardrails so new resources start secure, and owning cloud security reviews for new work.
From USD 3,900
Per month for a mid-level cloud security engineer, fully managed
160 h
Typical monthly capacity for this role
Fixed
The same fee every month
4 to 6 weeks
From signing to our specialist starting
Monthly
Add or reduce hours at each cycle

Questions about adding a Cloud Security Engineer to your team.

Which clouds do you work with?

AWS, Azure and GCP, and the Kubernetes clusters running on them. We match the engineer to the cloud you use today, and every change is made in your infrastructure code and your accounts, under your access rules.

Will the engineer have admin access to our cloud?

Only what the work needs, granted by you and reviewable at any time. Changes go through your infrastructure code and pull requests, so they are reviewed and logged like any other change, and you can revoke access whenever you choose.

Tell us what your cloud security engineer would work on.

Loading the form…

We reply within one business day.