Senior Consultant - Cloud Security Architect

KPMG Middle East

Dubai

On-site

AED 240,000 - 420,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

KPMG Middle East is seeking an experienced Cloud Security Architect to lead security design and advisory for client cloud environments in the UAE. The role combines hands-on engineering with strategic guidance across Azure, multi-clouds and governance frameworks.

The ideal candidate can assess risk, map controls to CIS/NIST/ISO baselines, and drive security transformations for complex engagements while maintaining high quality and stakeholder communication.

Qualifications

  • Strong track record in cloud security architecture and consulting.
  • Hands-on experience with Microsoft Azure and Microsoft 365.
  • Experience in secure cloud migration and landing zone design.
  • Knowledge of security controls across Azure and cloud services.
  • Familiarity with CIS, NIST, ISO and CAF baselines.

Responsibilities

  • Understand client challenges, cloud ambitions, regulatory requirements and threat landscape.
  • Advise on secure cloud adoption, lift-and-shift migration and landing zone security.
  • Design and implement security controls across Azure landing zones (identity, networking, logging, governance, encryption).
  • Support security architecture across Azure, M365, AWS and OCI environments.
  • Navigate cybersecurity regulations, frameworks, and cloud compliance requirements.
  • Contribute to cloud security governance, risk management and control frameworks.
  • Assess cloud environments against security baselines and best practices.
  • Deliver automation of security controls, posture reporting and risk dashboards.

Skills

Cloud security architecture
Azure
Identity & access mgmt
Security governance
DevSecOps
Multi-cloud security
Client advisory
Big4 experience

Job description

Job Description:

Responsibilities
JOB DESCRIPTION
You Will Help Deliver High-quality Client Engagements By
  • Understanding clients’ business challenges, cloud ambitions, regulatory requirements, and threat landscape
  • Advising clients on secure cloud adoption, lift-and-shift migration, and landing zone security design
  • Designing and implementing security controls across Azure landing zones, including identity, networking, logging, governance, encryption, workload protection, and monitoring
  • Supporting security architecture across Azure, Microsoft 365, AWS, and OCI environment
  • Helping clients navigate cybersecurity regulations, security frameworks, and cloud compliance requirements
  • Advising on cloud security governance, operating models, control frameworks, and risk management
  • Assessing existing cloud environments against security baselines such as CIS, NIST, ISO, CAF, and cloud provider best practices
  • Helping clients optimize their digital and technical security controls across multiple layers of the cloud architecture stack
  • Using security architecture to define and support broader security transformation programs
  • Delivering automation of security controls, security posture reporting, and risk dashboards where relevant
  • Supporting small and medium-sized engagements independently and participating as a key team member in larger transformation programs
  • Supporting presales, proposal development, and business development activities
  • Building constructive and trusted relationships with clients, both at technical and senior stakeholder level
  • Acting as a trusted advisor and role model for quality, integrity, and risk management practices
  • Contributing to the continued development of KPMG’s cloud security services and professional network
The Person

We are looking for someone with a strong track record in cloud security architecture and consulting, with the ability to combine hands‑on technical experience with strong client advisory skills.

The Ideal Candidate Should Have
  • Proven experience in cloud security architecture, preferably with strong hands‑on experience in Microsoft Azure and Microsoft 365
  • Practical experience with secure cloud migration, lift‑and‑shift scenarios, and Azure landing zone design or implementation
  • Strong understanding of Azure landing zone security, including management groups, subscriptions, RBAC, Azure Policy, Defender for Cloud, logging, network security, private endpoints, Key Vault, backup, and workload protection
  • Experience assessing, designing, or implementing security controls across multiple layers of the IT architecture stack
  • Strong knowledge of Identity and Access Management, including Microsoft Entra ID, Conditional Access, Privileged Identity Management, workload identities, and identity governance
  • Experience with cloud security assessments, security configuration reviews, privacy and regulatory risk assessments, and control framework mapping
  • Experience with DevSecOps concepts, infrastructure‑as‑code, policy‑as‑code, security automation, and continuous control monitoring is highly desirable
  • Experience delivering cybersecurity services in a commercial or consulting environment
  • Experience in one or more cloud service provider environments: Microsoft Azure, AWS, OCI, or GCP
  • Ability to analyze complex problems, identify core issues, and recommend practical and proportionate solutions
  • Ability to communicate clearly with both technical teams and senior stakeholders
  • Ability to translate complex cybersecurity topics into clear business risk, impact, and remediation advice
  • Ability to work at sustained levels of high intensity while maintaining quality, structure, and professionalism
  • Previous Big4 experience is a must for this role
Qualifications And Certifications

The candidate should ideally have a combination of cloud, security, and architecture certifications. We do not expect every candidate to hold all certifications, but one or more of the following would be highly valued.

  • Microsoft Certified: Cybersecurity Architect Expert – SC-100
  • Microsoft Certified: Cloud and AI Security Engineer Associate – SC-500
  • Microsoft Certified: Identity and Access Administrator Associate – SC-300
  • Microsoft Certified: Information Security Administrator Associate – SC-401
  • Microsoft Azure architecture or administrator certifications such as AZ-104 or AZ-305 are also beneficial
  • AWS Certified Security – Specialty
  • AWS Certified Solutions Architect – Professional
  • Google Cloud Professional Cloud Security Engineer
  • CISSP, CISM, CCSP, or comparable cybersecurity experience
  • SABSA, TOGAF, or comparable architecture experience is preferred

Requirements:

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Consultant - Cloud Security Architect
Senior Consultant - Cloud Security Architect

KPMG Fakhro • Dubai

On-site
AED 250,000 - 450,000
Security Architect
Security Architect

Good co India • United Arab Emirates

On-site
AED 350,000 - 600,000
Azure Cloud Architect
Azure Cloud Architect

Good co India • United Arab Emirates

On-site
AED 350,000 - 700,000
Cloud Security Engineer
Cloud Security Engineer

Good co India • United Arab Emirates

On-site
AED 240,000 - 420,000
Azure Solution Architect
Azure Solution Architect

Good co India • United Arab Emirates

On-site
AED 180,000 - 260,000
Cloud Security Specialist
Cloud Security Specialist

iConnect IT Business Solutions DMCC • Dubai

On-site
AED 300,000 - 420,000
Cloud Solutions Architect
Cloud Solutions Architect

Good co India • United Arab Emirates

On-site
AED 240,000 - 420,000
Cloud Security Engineers (Azure + DevSecOps + Agentic Systems)
Cloud Security Engineers (Azure + DevSecOps + Agentic Systems)

Hiredge Solutions • Dubai

On-site
AED 330,000 - 441,000
Cyber Security Lead
Cyber Security Lead

Good co India • United Arab Emirates

On-site
AED 420,000 - 840,000
Cybersecurity Expert
Cybersecurity Expert

Astra Tech • Abu Dhabi

On-site
AED 300,000 - 540,000