Senior Cloud Security Specialist

A well-established Australian financial services organisation is expanding its cyber security capability and is seeking a Senior Cloud Security Specialist to strengthen security across a multi-cloud environment (AWS-centric, with Azure exposure desirable). This is a hands-on role combining cloud security engineering with broader security operations responsibilities.

The opportunity

You’ll work across cloud platforms and core security tooling to uplift security posture, reduce risk, improve controls, and support incident response. You’ll partner closely with Infrastructure, Development, Risk/Compliance and business stakeholders to embed security into delivery and operations.

Key responsibilities

Cloud security (core focus)

  • Design, implement and maintain security controls across cloud environments

  • Secure cloud architectures using Infrastructure as Code (IaC), automation and posture management tools

  • Perform cloud risk assessments and threat modelling

  • Identify, prioritise and manage security risks across multi-cloud platforms

  • Ensure alignment to cloud security best practices and secure design patterns

  • Uplift cloud security awareness and capability across teams

Security operations

  • Operate and continuously improve security technologies, including:

    • Vulnerability management platforms

    • Cloud security tooling / CSPM

    • Network & web application firewalls

    • EDR/XDR

    • DLP

    • IAM

    • SIEM / security monitoring

    • Reverse proxies & authentication systems

  • Monitor cloud/network/system telemetry for threats and vulnerabilities

  • Investigate and respond to security incidents, implementing preventive measures

  • Incorporate threat intelligence and emerging risk signals into defensive controls

  • Maintain clear documentation for platforms, services and controls

Ways of working

  • Help mature Cyber Operations delivery by supporting a scrum / agile operating rhythm

  • Collaborate across technical and non-technical stakeholders, communicating risks and recommendations clearly

What you’ll bring

  • 10+ years in technology / infrastructure / cloud, including 5+ years in cyber security (with strong cloud depth)

  • Hands-on experience with AWS in production environments (Azure desirable)

  • Strong understanding of cloud security architecture, control frameworks and best practices

  • A DevSecOps mindset (security embedded into CI/CD and IaC workflows)

  • Broad security tooling knowledge (vuln mgmt, IAM, SIEM, EDR, WAF, etc.)

  • Strong stakeholder engagement and communication skills

  • Certifications (AWS/Azure, Palo Alto, Zscaler, etc.) and tertiary qualifications are desirable

Location & flexibility

  • North Sydney office location

  • Hybrid working arrangements available (flexible WFH)

Apply now via SEEK with your CV, or message for a confidential discussion.

Amanda  Evans's Our  Infrastructure Permanent

Infrastructure Permanent

Amanda Evans

Infrastructure – Permanent

[email protected]
02 8346 6716