Cloud Security Engineer - EY GDS
Job description
Security Technology – Cloud Security Engineer
EY Technology
Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of over 1000 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team help protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
The opportunity
We are looking for a Cloud Security Engineer to join our Security Technology Services Engineering team. In this role you will help design and deliver organization-wide secure development capabilities, including standardized CI/CD patterns that embed security tooling and quality gates, so teams can build and ship securely at scale. You will also contribute to cloud security engineering across Azure, AWS, and GCP, including CNAPP platforms such as Wiz, and support selective use of AI to strengthen security workflows and guide secure AI adoption. You will work alongside like-minded engineers, partner across technology and security teams, and help make security automated, consistent, and easier for developers to adopt.
Your key Responsibilities
As an individual contributor, you’ll bring your engineering expertise into efforts which introduce new technologies and upgrade existing ones. Active project participation in new or integrated technologies as the Subject Matter Expert for the Information Security use cases pertaining to Cloud Security technology. You will be responsible for the design, engineering, implementation, and early life cycle support of systems and services within our EY multi-cloud environments. You will work closely with Teams across EY such as: Security Architects, Service Delivery, Security Operations, and Cyber Defense for the enablement of security solutions and services. You will also provide consulting services to other teams and act as a level four contact for operational issues.
- Provide technical oversight of Information Security technologies that fall under the team’s responsibilities, confirming they are operating within agreed service levels and at peak possible performance
- Represent the team in specific Project activities, including Leading projects and managing the activity of others towards successful completion.
- Engineer security solutions and services following all relevant EY standards and practices for On-Premises, Hybrid and Cloud-Based environments.
- Lead the design, implementation, testing of security solutions and services for a large or more complex project to its completion which includes production support and documentation.
- Take accountability for the design, delivery, and maintenance of new and existing security solutions or services, driving compliance with and contributing to the development of relevant standards.
- Apply modern standards/principles, global product-specific guidelines, security standards, design standards, to security solutions and services as appropriate.
- Improve existing security solutions and services in use by partnering with Security Architecture, Service Owners, and Security Operations. Drives automation and innovation across the security solutions supported.
- Work in a diverse, global environment and build strong relationships across all levels of a matrixed, geographically, and culturally dispersed organization.
- Be flexible to work out of regular office hours to accommodate the team and organizational calls and meetings. Weekend or late-night work may occur during project and early life cycle support phases.
- No direct supervision responsibilities though technical leadership required within assigned projects.
- Articulate technology issues/concerns that may emerge at any level of the technical stack, and from any component across the ecosystem, to senior business and technology leaders.
Skills and attributes for success
We are interested in engineers who blend DevOps/automation and security in large enterprise environments; people who improve developer experience by making security standardized and easy to adopt, while also applying strong cloud security judgment across platforms and tooling. Success in this role means collaborating with technical teams, stakeholders, and internal customers to deliver practical, scalable solutions.
To qualify for the role, you must have
- Hands-on experience designing or operating DevSecOps / secure CI/CD pipelines that integrate security controls and gate checks (e.g., GitHub Actions, Azure DevOps Pipelines, or equivalent).
- Practical experience with several application and software supply-chain security capabilities, such as SAST, SCA/OSS scanning, secrets scanning, DAST, and container image scanning, and helping teams adopt them through standards, templates, or reusable patterns.
- Hands-on experience with cloud security across one or more major providers (Azure, AWS, GCP), with the ability to apply security controls, automation, and good architectural judgment in cloud environments (Azure experience strongly preferred).
- Experience with CNAPP / CSPM / CWPP / KSPM capabilities, ideally including Wiz (or comparable platforms), and using findings to drive remediation and secure-by-default patterns.
- Proficiency in scripting and automation with PowerShell, Bash, Python, or similar languages.
- Experience with Infrastructure as Code and automation (e.g., Terraform, Bicep, or equivalent).
- 4+ years of experience in security, DevOps/platform engineering, or software delivery with a strong security focus.
- Proven track record of working with a team as well as managing projects and initiatives.
- Proficiency with change control management processes.
- The ability and desire to train and mentor staff in technical process and best practices.
- Extensive experience working in large, global, and virtual environments.
- Strong English language skills, both written and verbal.
Ideally, you’ll also have
- Experience building reusable pipeline templates / golden paths that make secure development the default for many teams.
- Experience introducing or operationalizing AI tooling to improve security engineering workflows, and/or familiarity with secure use of AI/LLM capabilities in an enterprise context.
- Hands-on experience with containers and Kubernetes security as it intersects delivery pipelines and runtime posture (e.g., AKS/EKS/GKE, image scanning, admission/policy controls).
- Experience with policy-as-code or cloud guardrails (e.g., Azure Policy, OPA/Gatekeeper, or equivalent).
- Experience with automation and workflow orchestration services (e.g., Logic Apps/Power Automate, n8n, or similar).
- Experience or awareness of observability and operational telemetry platforms (e.g., Azure Log Analytics, Grafana, or equivalent).
- Relevant certifications in cloud administration, engineering, or security (e.g., Azure, AWS, GCP).
- Security certifications such as GSEC, CISSP, or equivalents from ISC2 or GIAC.
- Project management experience and familiarity with service introduction and readiness processes.
- Familiarity with hybrid cloud architectures and connectivity solutions (e.g., Azure Arc, Azure ExpressRoute, AWS Direct Connect).
What we look for
- This role is perfect for you, if you have excellent problem solving, decision making and communication skills.
- We are looking for people who are comfortable working with culturally diverse on/offshore team members, able to react appropriately during stressful and ambiguous situations, and drive efforts to successful and timely completion.
What we offer:
As part of this role, you will work in a highly coordinated, globally diverse team with the opportunity and tools to grow, develop and drive your career forward. Here, you can combine global opportunity with flexible working. The EY benefits package goes above and beyond too, focusing on your physical, emotional, financial and social well-being. Your recruiter can talk to you about the benefits available in your country. Here’s a snapshot of what we offer:
- Continuous learning: You will develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We will provide the tools and flexibility, so you can make a significant impact, your way.
- Transformative leadership: We will give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You will be accepted for who you are and empowered to use your voice to help others find theirs
EY is committed to being an inclusive employer and we are happy to consider flexible working arrangements. We strive to achieve the right balance for our people, enabling us to deliver excellent client service whilst allowing you to build your career without sacrificing your personal priorities. While our client-facing professionals can be required to travel regularly, and at times be based at client sites, our flexible working arrangements can help you to achieve a lifestyle balance.
If you can confidently demonstrate that you meet the criteria above, please contact us as soon as possible.
Make your mark.
Apply now.