Cloud Security Architect - Senior Consultant

The Cloud Security Architect - Senior Consultant at Deloitte will be responsible for defining and assessing client organizations' cloud security strategy, architecture, and practices. This role involves providing expertise in cloud security planning, deployment, and review, leading technical guidance for cloud cyber risk projects, and assisting with business development activities. The consultant will act as a technical specialist in CNAPP, CWPP, and CSPM technologies, generate project deliverables, and maintain domain knowledge of multi-hyperscaler cloud solutions and security concepts.

What you'd actually do

  1. Lead/provide technical guidance and solutioning for the delivery of Cloud Cyber Risk projects in a project manager and or architect role, overseeing the activities of onsite and offshore engineers and architects across 8 key cyber domains: Governance, Identity, Application Security, PaaS security, Infrastructure security, Security Monitoring, Resilience and Data protection
  2. Assist in business development activities such as defining scope of services, building resource estimates and related pricing, packaging proposals and supporting the delivery of the proposal to the client for AWS, GCP, Azure and/or Oracle Cloud services
  3. Function as key client point of contact interface building rapport and trust with the client
  4. Function as a technical specialist in CNAPP, CWPP and CSPM technologies and security risk frameworks relevant to cloud as well as the industry leading benchmarks
  5. Lead the generation of all project deliverables such as assessment reports, system designs/ architectures and risk/security recommendations

Skills

Required

  • Cloud security strategy and architecture
  • Cloud security planning, deployment, and review
  • Technical guidance for Cloud Cyber Risk projects
  • CNAPP, CWPP, CSPM technologies
  • Security risk frameworks for cloud
  • Project deliverables generation (assessment reports, system designs, risk recommendations)
  • Multi-hyperscaler cloud solutions (AWS, GCP, Azure, Oracle)
  • Cloud configuration standards
  • Cloud vulnerability resolution
  • Technical health checks for cloud platforms
  • DevSecOps and CI/CD pipelines
  • Cyber tooling for cloud (Wiz, Snyk)
  • Proof of concept and production deployments of cloud technologies
  • Tenant setup and service configuration
  • MFA, SSO, Conditional Access, PIM
  • Security Operations tooling and scanning solutions
  • Third-party security technologies (firewall, WAF, PAM)
  • Cloud security and compliance reporting
  • Industry leading practices for cyber risks and cloud security
  • Cloud-specific security policies, standards, and procedures
  • Troubleshooting system-level problems in multi-vendor environments
  • Documentation of technical issues and resolutions
  • Internal cloud and devsecops security technical training

Nice to have

  • Project management
  • Business development support (scoping, pricing, proposals)
  • Client relationship management
  • Industry leading benchmarks

What the JD emphasized

  • cloud security strategy
  • cloud security planning
  • cloud security architecture
  • cloud security engagements
  • cloud security and compliance reports
  • cloud cyber risk mitigation
  • cloud cyber risk
  • cloud platforms