> Markdown version of [/jobs/ext/1245525-cloud-security-specialist](https://www.wearedevelopers.com/jobs/ext/1245525-cloud-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Specialist - **Company:** Wood Mackenzie Limited - **Location:** Edinburgh, UK - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Computing Security, Cyber Security, DevOps, Identity and Access Management, Intrusion Detection Systems, Information Systems Security Architecture Professional, Network Security, PCI Data Security Standards, Remote Access Technology, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Cloud Platform System, Mitre Att&ck, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology, CIS Benchmarks, Splunk, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** July 12, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=e4caa48072f89f30 ## About the Role You'll be someone who is comfortable working directly in cloud consoles and security tooling, enjoys getting into the technical detail, and can communicate clearly with both technical teams and other stakeholders. You'll be a technical point of reference for colleagues on cloud security matters., * 4+ years of cyber security experience, with 2+ years hands-on in cloud security * Deep, practical experience securing your primary cloud platform (AWS and Azure) * Working knowledge of IAM, network security concepts, and encryption/data-protection fundamentals * Familiarity with at least one major security framework (NIST CSF, MITRE ATT&CK, CIS Benchmarks, or Zero Trust) * Ability to explain security issues and trade-offs clearly to both technical and non-technical audiences Desirable (nice to have, not required) * Experience integrating security into CI/CD pipelines / DevSecOps practices * Exposure to SIEM platforms (e.g. Splunk, Sentinel) and EDR solutions * Experience with SAST/DAST or vulnerability-scanning tools * Background in penetration testing or offensive security * Experience with threat intelligence or threat-hunting tooling * Experience in a regulated industry (financial services, healthcare, energy) Technical Skills: * Strong, hands-on expertise with cloud platform security services and native tooling * Understanding of network security, firewalls, IDS/IPS, and VPN technologies * Comfortable working with IAM, cloud configuration, and infrastructure security settings directly Certifications and Education (one or more is a plus, not essential) * Bachelor's degree in Computer Science, Information Security, or a related field -or equivalent practical experience * CCSP (Certified Cloud Security Professional) * AWS Certified Security - Specialty * Microsoft Certified: Azure Security Engineer Associate * CISSP (Certified Information Systems Security Professional) Soft Skills: * Strong analytical and problem-solving abilities * Clear written and verbal communication * Ability to explain complex security concepts to technical and non-technical audiences * Strong attention to detail and the ability to prioritise under pressure * Collaborative approach to working with cross-functional teams #LI-DB1 ## Description We are looking for an experienced, hands-on Cloud Security Specialist to join our cyber security team. This is a technical individual-contributor role focused on securing our cloud and application environments day to day; designing and implementing controls, assessing our cloud posture, and working alongside engineering and DevOps teams to build security in from the start., * Design, implement, and maintain security controls across our cloud environment in align with our cyber risk and control framework * Conduct cloud security assessments and architecture reviews, and track findings through to remediation * Manage and tune cloud-native security tooling (CSPM, CWPP, cloud WAF) * Working knowledge and input to identity and access management (IAM) policies and controls * Coordinate cloud vulnerability remediation with the relevant teams * Investigate cloud security events and support incident response * Help ensure our cloud environment aligns with recognised frameworks and benchmarks (CIS, CSA CCM, NIST) * Contribute to security policies, standards, and technical documentation * Support compliance activities (e.g. SOC 2, ISO 27001, PCI-DSS, GDPR) as they relate to the cloud environment * Keep current with emerging cloud threats, vulnerabilities, and tooling, and share knowledge with the team * Supporting wider security team where possible ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [7 Most Popular Web Developer Jobs in Europe](https://www.wearedevelopers.com/magazine/163-7-most-popular-web-developer-jobs-in-europe)