Dedicated cloud security engineers for your offshore team.
Offshore cloud security engineers in Chiang Mai and Bangkok, working full time on your roadmap and managed by us. A cloud security engineer makes sure the people, services and networks in your cloud accounts can reach only what they need, and that the setup stays that way.
One agreement and one fixed monthly fee, with a service delivery manager in Thailand who runs your team day to day.
This role is part of a dedicated cybersecurity team. It's staff augmentation, fully managed: take one role on its own, or the whole discipline as one delivery team.
One Cloud Security Engineer, assigned to your product and fully managed.
We assign a Cloud Security Engineer to your team full time and run everything around them: a service delivery manager who answers for the work, training and coaching, the office and equipment, and HR and payroll. The price below is for a mid-level Cloud Security Engineer; junior and senior levels are priced in your proposal, and how the monthly fee is built explains the arithmetic.
From price
One mid-level Cloud Security Engineer, full time, everything below included. All 27 things included ››
- Cloud security engineer From USD 3,900 per month
-
Service
We manage and develop the team
- A service delivery manager who runs the team and answers for delivery
- A 1:1 with our Head of Delivery every two weeks
- Weekly delivery scoring and monthly capacity reports
- A Talent Success Manager for every specialist
-
HR
We are the employer
- Recruitment and technical assessment
- Employment contracts
- Salary and payroll
- Tax and social security
-
Facilitation
We provide the workplace
- A desk in our own office in Chiang Mai or Bangkok
- A Workplace Experience Manager on site
- Team events through the year
- IT support
-
Equipment
We supply the tools
- Laptop and hardware
- Software licences
- LinkedIn Learning access
- Device security and management
What a Cloud Security Engineer does on a dedicated cybersecurity team.
They work in your cloud accounts and infrastructure code under your access controls, with your platform and DevOps engineers, and ship security changes the same way every other change ships.
Cloud Security Engineer skills and technologies
-
Least-privilege identity and access, from human users to service accounts and CI roles.
-
Network design and segmentation, so a single exposed service can't reach everything behind it.
-
Configuration reviews against recognised benchmarks, with fixes written as infrastructure code instead of console clicks.
-
Encryption, key management and logging set up so an incident can be investigated afterwards.
-
Kubernetes and container security, from image scanning to runtime permissions.
Cloud Security Engineer seniority levels.
Mid-level to senior. Cloud permissions are easy to get wrong in ways that stay invisible until they matter, so experience across several cloud estates pays off. Seniority is one of the inputs into how the monthly fee is built.
When your team needs a Cloud Security Engineer.
Assigned when a cloud estate has grown faster than its access rules, after a security review flags misconfigurations, or ahead of an audit. Pairs with a DevSecOps engineer who keeps the same rules in the pipeline. Cloud security engineers join as part of a dedicated cybersecurity team at Azendo. It is a targeted addition for companies that hire a dedicated development team on AWS, Azure or GCP.
What we look for in a dedicated Cloud Security Engineer.
We look for engineers who think in permissions and blast radius. They read an IAM policy the way a developer reads code, and they prefer a reviewed Terraform change to a quick fix in the console.
A remote Cloud Security Engineer's first three months on your team.
- Weeks 1 to 2Reviewing your accounts, identities, networks and logging against a benchmark, and ranking the findings.
- Weeks 3 to 6Fixing the highest risks first, as infrastructure code, starting with access and exposed services.
- Months 2 to 3Setting guardrails so new resources start secure, and owning cloud security reviews for new work.
Questions about adding a Cloud Security Engineer to your team.
Which clouds do you work with?
AWS, Azure and GCP, and the Kubernetes clusters running on them. We match the engineer to the cloud you use today, and every change is made in your infrastructure code and your accounts, under your access rules.
Will the engineer have admin access to our cloud?
Only what the work needs, granted by you and reviewable at any time. Changes go through your infrastructure code and pull requests, so they are reviewed and logged like any other change, and you can revoke access whenever you choose.
Add remote cloud security engineers to your team.
Tell us your roadmap and your stack, and we'll come back with the right profile, the capacity and a start date. You can also talk to a service delivery manager first.
Tell us what your cloud security engineer would work on.
Loading the form…
We reply within one business day.