Cloud Engineer, Forensic & Financial Crime Technology Advisory and Data Analytics

Deloitte
London, UK
1 day ago
Apply on apply.deloitte.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Java (Programming Language) Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Automation of Tests Microsoft Azure BigQuery C Sharp (Programming Language) Cloud Computing Cloud Storage Encodings Computer Networks
+63 more
Databases Continuous Integration DevOps Domain Name System (DNS) Amazon DynamoDB Github Identity and Access Management Python (Programming Language) Key Management Log Analysis Network Segmentation Node.Js Octopus Deploy Site Reliability Engineering Practices Cloud Services Prometheus Zero Trust Network Access Azure Data Lake Search Technologies Security Information and Event Management Software Engineering SQL Databases Data Streaming TypeScript Azure Service Bus Policy as Code Data Logging Data Processing Google Cloud Azure Data Factory Cloud Monitoring Istio Retrieval-Augmented Generation Large Language Models Snowflake Grafana Amazon Virtual Private Cloud (VPC) Cloudformation Data Lakes AI Platforms Kubernetes Deployment Automation Google Cloud Functions Bicep AWS Fargate Apache Kafka Cosmos DB Azure AKS CIS Benchmarks Cloudwatch Api Gateway Terraform Azure Synapse Analytics Data Pipelines Dynatrace Api Management Serverless Computing Docker Key Vault Static Application Security Testing Databricks Vulnerability Analysis Dynamic Application Security Testing

Job description

Using cutting edge technology, you’ll work alongside colleagues, often in multi-disciplinary teams, helping to solve our clients’ most significant challenges. As a senior member of the team you will lead the technical design and hands-on delivery of cloud solutions, frequently working directly within the client’s own cloud environment, controls and change processes.

You will be expected to go deep as well as broad: making and defending architecture decisions, writing and reviewing infrastructure-as-code and application code, and owning solutions through to production operation. Specific responsibilities will include:

Owning end-to-end solution and platform architecture across compute, storage, data, networking and identity: producing target-state designs, reference architectures, well-architected reviews and trade-off analysis, and documenting decisions as ADRs;

Designing and implementing secure landing zones and multi-account / multi-subscription topologies, including hub-and-spoke networking, private connectivity (private endpoints / PrivateLink / Private Service Connect), DNS, and network segmentation;

Building and operating workloads as Infrastructure as Code (Terraform, Bicep/ARM or CloudFormation) with modular, reusable components, policy-as-code guardrails and automated drift detection;

Designing and deploying containerised and serverless workloads: Kubernetes (AKS/EKS/GKE), serverless functions and managed app platforms, including autoscaling, ingress, service mesh and zero-downtime deployment strategies (blue/green, canary);

Building CI/CD pipelines and GitOps workflows (GitHub Actions, Azure DevOps, Argo CD/Flux) with automated testing, security scanning (SAST/DAST, IaC and container scanning) and supply-chain controls;

Architecting data and AI platforms (data lakes/lakehouses, warehouses, streaming and event-driven patterns) and integrating managed AI/model services (Azure OpenAI / AI Foundry, AWS Bedrock, GCP Vertex AI), including retrieval-augmented generation, vector search and secure prompt/data handling;

Engineering for reliability and observability: defining SLOs/SLIs, instrumenting metrics, logs and traces (OpenTelemetry, Azure Monitor, CloudWatch, Prometheus/Grafana), and leading incident response, DR and resilience testing;

Embedding security and compliance by design: IAM least privilege, secrets and key management (Key Vault/KMS/Secret Manager), encryption in transit and at rest (including CMK/BYOK), private endpoints, network policy, data residency and data-zone requirements, and UK/EU GDPR and financial-services regulatory obligations;

Owning FinOps and cost optimisation: right-sizing, commitment-based discounts, tagging/showback and architectural changes that materially reduce run cost;

Providing hands-on technical leadership and SME input: setting engineering standards, reviewing code and designs, mentoring engineers, and managing technical risk and quality across the workstream; and

Evaluating and prototyping new cloud and AI services, and contributing to the team’s reusable assets, accelerators and reference implementations., * Azure: Blob/ADLS Gen2, Functions, App Service, SQL Database, Cosmos DB, AKS, API Management, Entra ID, Azure OpenAI, Azure AI Search, AI Foundry, Key Vault, Private Link, Azure Monitor/Log Analytics, Azure Policy, Bicep;

  • AWS: S3, Lambda, VPC, RDS/Aurora, DynamoDB, ECS/Fargate, EKS, API Gateway, IAM, Bedrock, KMS, PrivateLink, CloudWatch, CloudFormation/CDK;
  • GCP: Cloud Storage, Cloud Run, BigQuery, GKE, Vertex AI, Cloud IAM, VPC Service Controls, Cloud Monitoring/Logging;
  • Data & AI: data lake/lakehouse and warehouse patterns (e.g. Databricks, Snowflake, Synapse/Fabric, BigQuery), streaming/event-driven architectures (Kafka/Event Hubs/Pub/Sub), and LLM/RAG patterns with vector databases;
  • Observability & reliability: OpenTelemetry, Prometheus/Grafana, ELK, distributed tracing, SRE practices, chaos/DR testing;
  • Security & governance: Zero Trust, CIS benchmarks, policy-as-code (OPA/Sentinel/Azure Policy), SIEM integration, and cloud security posture management (CSPM);
  • Relevant certifications, e.g. Azure Solutions Architect Expert / DevOps Engineer Expert, AWS Solutions Architect Professional, Google Professional Cloud Architect, or CKA/CKAD;
  • Experience of working on projects for external clients; and
  • Experience of working in or on projects in regulated industries, particularly financial services.

Connect to your business - Strategy, Risk & Transactions Advisory

In an ever-evolving world, there are no certainties in business. Our teams help clients to navigate risks, process major transactions and deliver transformational change that will future-proof their business. Join us to make a positive difference.

Forensic & Financial Crime

Our teams in Forensic and Financial Crime provide proactive advice, transformation and operational support to help clients protect their brand and navigate financial crime risks, including money laundering, fraud and corruption.

Requirements

  • Proven experience designing and operating production cloud solutions, with deep hands-on expertise in at least one of Azure, AWS or GCP and the ability to both build and run/maintain what you deploy;
  • Strong architecture fundamentals across compute, storage, databases, networking and identity, and a track record of making and defending design trade-offs in regulated environments;
  • Expert-level Infrastructure as Code (Terraform and/or Bicep/ARM or CloudFormation) and automation, building modular, reusable, tested infrastructure rather than click-ops;
  • Hands-on experience with containers and orchestration (Docker + Kubernetes: AKS/EKS/GKE) and with serverless and managed application platforms;
  • Solid software engineering skills. Comfortable coding and reviewing in at least one of Python, C#, TypeScript/Node.js or Java, and building/consuming REST/gRPC APIs;
  • Practical experience of CI/CD and DevOps/GitOps, including automated testing and security scanning in the pipeline;
  • A strong, demonstrable security posture, IAM/least privilege, key and secrets management, encryption (incl. CMK/BYOK), private networking, and awareness of data residency (e.g. Azure data zones) and UK/EU GDPR obligations;
  • Experience integrating managed AI/model services and building data pipelines to support them;
  • Ability to lead a workstream and mentor engineers, set technical standards, and communicate complex designs clearly to both technical and non-technical (including senior client) audiences.

About the company

Designing, building and running secure, production-grade cloud platforms that our clients can trust with their most sensitive data, it’s just another day at the office for our Financial Crime Technology Advisory and Data Analytics experts.

This is your opportunity to join Deloitte’s Financial Crime Technology Advisory and Data Analytics team. Our rapidly growing practice is expanding to meet large and consistent client demand for cloud, data and AI-enabled solutions. The team comprises a group of specialists drawn from a wide range of different professional and technical backgrounds. We apply our combined skills and experience to find new ways of solving our clients’ most complex technology, data, and analysis challenges.

Working with the worlds’ largest and most complex financial organisations, you will own the architecture, deployment and operation of cloud platforms and data/AI workloads at scale. You will make the design decisions that balance security, resilience, performance and cost, and you will be accountable for how those decisions hold up in production. Collaborating with colleagues and industry leaders, you will have an opportunity to grow your industry presence and be recognised as a leader in your domain.

No two projects are the same, however the majority will involve architecting and operating cloud, data and web solutions in highly regulated environments. Typical projects include defining target-state cloud architectures and landing zones, delivering solutions directly on the client’s cloud estate, building data and AI pipelines, and hardening, migrating or optimising existing workloads for security, resilience and cost. Most of the projects will be in the regulated financial services sector.

Away from project work, we offer both formal and informal support for continuous professional development, to accelerate your career progression within a rapidly growing team.

We encourage consideration of flexible ways of working, both formal and informal arrangements that allow for the best outcomes for our people and our clients. If this opportunity is of interest to you with some flexibility, please do discuss with us.

Connect to your career at Deloitte

Deloitte drives progress. Using our vast range of expertise, we help our clients’ become leaders wherever they choose to compete. To do this, we invest in outstanding people. We build teams of future thinkers, with diverse talents and backgrounds, and empower them all to reach for and achieve more.

What brings us all together at Deloitte? It’s how we approach the thousands of decisions we make every day. How we behave, our beliefs and our attitudes. In other words: our values. Whatever we do, wherever we are in the world, we lead the way, serve with integrity, take care of each other, foster inclusion, and collaborate for measurable impact. These five shared values lead every decision we make and action we take, guiding us to deliver impact how and where it matters most., Regulation and controls are standard practice in our industry and Deloitte is no exception. These controls provide important legal protection for both you and the firm. We are subject to a number of audit regulations, one of which requires that certain colleagues abide by specific personal independence constraints (e.g., in relation to any financial interests and employment relationships). This can mean that you and your “Immediate Family Members” are not permitted to hold certain financial interests (shares, funds, bonds etc.) with audit clients of the firm, and also prohibitions on certain employment relationships (e.g., you are not permitted to hold a secondary employment role with SEC audit clients of the firm whilst being employed by the firm). The recruitment team will provide further detail as you progress through the recruitment process or you can contact the Independence team upon request.

Connect with your colleagues

“The scale and range of projects you get to work on, because of Deloitte’s capability across all industries and clients, is why I would recommend a career here.”- Jeremy, Strategy, Risk & Transactions Advisory

Our hybrid working policy

You’ll be based in London with hybrid working.

At Deloitte we understand the importance of balancing your career alongside your home life. That’s why we’ll support you to work flexibly through our hybrid working policy. Depending on the requirements of your role, you’ll have the opportunity to work in your local office, virtual collaboration spaces, client sites and remotely. You’ll get the chance to meet face to face when needed, while you collaborate and learn from colleagues, share your experiences, and build the relationships that will fuel your career and prioritise your wellbeing. Please check with your recruiter for the specific working requirements that may apply for your role.

Our commitment to you

Making an impact is more than just what we do: it’s why we’re here. So we work hard to create an environment where you can experience a purpose you believe in, the freedom to be you, and the capacity to go further than ever before.

We want you. The true you. Your own strengths, perspective and personality. So we’re nurturing a culture where everyone belongs, feels supported and heard, and is empowered to make a valuable, personal contribution. You can be sure we’ll take your wellbeing seriously, too. Because it’s only when you’re comfortable and at your best that you can make the kind of impact you, and we, live for.

Your expertise is our capability, so we’ll make sure it never stops growing. Whether it’s from the complex work you do, or the people you collaborate with, you’ll learn every day. Through world-class development, you’ll gain invaluable technical and personal skills. Whatever your level, you’ll learn how to lead.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on apply.deloitte.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · World Congress 2022

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · World Congress 2026 Europe

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

4:09 min

Selecting infrastructure tools and determining proper abstraction layers

Alayshia Knighten Alayshia Knighten · World Congress 2024

Videos

See all

Related articles

See all