Cyber IAM Managed Service - Cloud Security Consultant
KPMG
KPMG
We are looking for a of Cloud Security resource with 4+ years of experience for one of our engagements. The resource must work from our Nodia office and willing to work on shifts
Work experience
§
We are looking for a of Cloud Security resource with 4+ years of experience for one of our engagements. The resource must work from our Nodia office and willing to work on shifts
The ideal candidate will:
•
Demonstrate solid understanding of cloud security architectures across AWS and Azure, with a strong grasp of Zero Trust principles and defense-in-depth strategies.
•
Design secure cloud topologies, define security governance workflows, and guide risk-based access controls.
•
Produce clear SOPs, runbooks, security assessment reports, and technical design documents for cloud environments.
•
Collaborate with compliance, architecture, DevOps, and operations teams to ensure security by design.
•
Drive continuous improvements via automation, Infrastructure as Code (IaC), and actionable security metrics.
•
Effectively manage day-to-day security operations while balancing strategic initiatives and stakeholder expectations.
•
Demonstrate ability to define, monitor, and drive SLA/KPI compliance across security operations, ensuring consistent and measurable service delivery.
Mandatory Certification Required:
(At least one required; multiple strongly preferred)
Core Certifications
·
AWS Certified Solutions Architect – Associate
·
AZ-500 – Microsoft Certified Azure Security Engineer – Associate
·
Wiz Certified Cloud Fundamentals
Preferred Advanced Certifications
·
AWS Certified Security – Specialty
·
Microsoft Certified: Cloud and AI Security Engineer Associate
·
Certified Cloud Security Professional (CCSP)
·
Certified Information Systems Security Professional (CISSP)
Technical Skills Required:
Cloud Security:
•
Good working knowledge of AWS security services: IAM, Security Groups, NACLs, AWS Config, GuardDuty, Security Hub, CloudTrail, KMS, AWS WAF.
•
Good working knowledge of Azure security services: Azure AD/Entra ID, NSGs, Azure Firewall, Microsoft Sentinel, Key Vault, Azure Policy, Defender for Cloud.
•
Proven experience leading cloud security assurance programs, compliance audits, and governance frameworks across AWS and Azure.
Experience with CSPM tools (Wiz preferred; Prisma, Aqua Sec etc.) for posture management, automated compliance, and vulnerability remediation
Cloud Networking and Architecture:
•
Hands-on experience designing AWS VPC architectures: security groups, NACLs, transit gateways, VPC peering, PrivateLink, and Direct Connect.
•
Proficiency with Azure Virtual Networks (VNets), NSGs, Azure Firewall, User-Defined Routes (UDRs), Application Gateway, and ExpressRoute.
•
Understanding of hybrid cloud connectivity, micro-segmentation, and secure network architectures across AWS and Azure.
•
Familiarity with Zero Trust architecture principles and cloud-native security design patterns.
Security Operations & Analytics:
•
Hands-on experience managing day-to-day cloud security operations including monitoring security alerts, triaging incidents, and coordinating remediation activities across AWS and Azure.
•
Strong ability to perform security assessments, configuration reviews, and compliance checks within AWS and Azure environments.
•
Experience investigating findings in cloud environments, conducting root cause analysis, and implementing preventive controls.
•
Proficiency in reviewing and responding to security findings from CSPM tools (Wiz, Prisma Cloud, or similar) and ensuring timely resolution within defined SLAs.
•
Experience working with ITSM/ticketing tools such as ServiceNow to log, track, prioritize, and close security incidents and service requests in line with defined SLAs and KPIs.
DevSecOps & Automation:
•
Familiarity with Infrastructure as Code (Terraform, CloudFormation, ARM templates) and integrating security controls into IaC pipelines.
•
Understanding of CI/CD security integration, container security (Docker, Kubernetes), and API security.
Experience with automation scripting (Python, PowerShell, Lambda, or Azure Functions) to support and improve security operations
Behavioral / team skills
§
•
Strong
communication and stakeholder management
skills, including ability to explain complex security concepts in simple terms.
•
Analytical mindset with strong problem‑solving and decision‑making skills.
•
High level of ownership, accountability, and attention to detail.
•
Ability to handle multiple priorities in fast‑paced cloud and security environments.
•
Collaborative mindset with a willingness to mentor junior team members.
•
Proactive, structured, and self-driven approach to work.
•
Strong documentation and presentation abilities.
Work experience
§
We are looking for a of Cloud Security resource with 4+ years of experience for one of our engagements. The resource must work from our Nodia office and willing to work on shifts
The ideal candidate will:
•
Demonstrate solid understanding of cloud security architectures across AWS and Azure, with a strong grasp of Zero Trust principles and defense-in-depth strategies.
•
Design secure cloud topologies, define security governance workflows, and guide risk-based access controls.
•
Produce clear SOPs, runbooks, security assessment reports, and technical design documents for cloud environments.
•
Collaborate with compliance, architecture, DevOps, and operations teams to ensure security by design.
•
Drive continuous improvements via automation, Infrastructure as Code (IaC), and actionable security metrics.
•
Effectively manage day-to-day security operations while balancing strategic initiatives and stakeholder expectations.
•
Demonstrate ability to define, monitor, and drive SLA/KPI compliance across security operations, ensuring consistent and measurable service delivery.
Mandatory Certification Required:
(At least one required; multiple strongly preferred)
Core Certifications
·
AWS Certified Solutions Architect – Associate
·
AZ-500 – Microsoft Certified Azure Security Engineer – Associate
·
Wiz Certified Cloud Fundamentals
Preferred Advanced Certifications
·
AWS Certified Security – Specialty
·
Microsoft Certified: Cloud and AI Security Engineer Associate
·
Certified Cloud Security Professional (CCSP)
·
Certified Information Systems Security Professional (CISSP)
Technical Skills Required:
Cloud Security:
•
Good working knowledge of AWS security services: IAM, Security Groups, NACLs, AWS Config, GuardDuty, Security Hub, CloudTrail, KMS, AWS WAF.
•
Good working knowledge of Azure security services: Azure AD/Entra ID, NSGs, Azure Firewall, Microsoft Sentinel, Key Vault, Azure Policy, Defender for Cloud.
•
Proven experience leading cloud security assurance programs, compliance audits, and governance frameworks across AWS and Azure.
Experience with CSPM tools (Wiz preferred; Prisma, Aqua Sec etc.) for posture management, automated compliance, and vulnerability remediation
Cloud Networking and Architecture:
•
Hands-on experience designing AWS VPC architectures: security groups, NACLs, transit gateways, VPC peering, PrivateLink, and Direct Connect.
•
Proficiency with Azure Virtual Networks (VNets), NSGs, Azure Firewall, User-Defined Routes (UDRs), Application Gateway, and ExpressRoute.
•
Understanding of hybrid cloud connectivity, micro-segmentation, and secure network architectures across AWS and Azure.
•
Familiarity with Zero Trust architecture principles and cloud-native security design patterns.
Security Operations & Analytics:
•
Hands-on experience managing day-to-day cloud security operations including monitoring security alerts, triaging incidents, and coordinating remediation activities across AWS and Azure.
•
Strong ability to perform security assessments, configuration reviews, and compliance checks within AWS and Azure environments.
•
Experience investigating findings in cloud environments, conducting root cause analysis, and implementing preventive controls.
•
Proficiency in reviewing and responding to security findings from CSPM tools (Wiz, Prisma Cloud, or similar) and ensuring timely resolution within defined SLAs.
•
Experience working with ITSM/ticketing tools such as ServiceNow to log, track, prioritize, and close security incidents and service requests in line with defined SLAs and KPIs.
DevSecOps & Automation:
•
Familiarity with Infrastructure as Code (Terraform, CloudFormation, ARM templates) and integrating security controls into IaC pipelines.
•
Understanding of CI/CD security integration, container security (Docker, Kubernetes), and API security.
Experience with automation scripting (Python, PowerShell, Lambda, or Azure Functions) to support and improve security operations
Behavioral / team skills
§
•
Strong
communication and stakeholder management
skills, including ability to explain complex security concepts in simple terms.
•
Analytical mindset with strong problem‑solving and decision‑making skills.
•
High level of ownership, accountability, and attention to detail.
•
Ability to handle multiple priorities in fast‑paced cloud and security environments.
•
Collaborative mindset with a willingness to mentor junior team members.
•
Proactive, structured, and self-driven approach to work.
•
Strong documentation and presentation abilities.
Ready to apply?
Sign up first — takes a minute — and you get Hiro’s take on this role, a resume tailored to it, and (if available) a referral from a real employee at KPMG. All free with your Pro gift.
Sign up to apply