Senior Cloud Security Consultant

EY

Auckland

Hybrid

NZD 120,000 - 180,000

Full time

4 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Career development
Flexible work
Wellness incentive & flex leave

Job summary

EY Auckland is seeking a Cloud Security Consultant to join a hybrid team focused on securing cloud implementations and transforming technology delivery. The role requires 4–6 years supporting enterprise cloud environments and a hands‑on approach to security across cloud platforms.

You will work with Solution Architects and engineering teams to identify risks, propose improvements, and drive secure business outcomes while fostering strong stakeholder engagement in a dynamic consulting environment.

Qualifications

  • 4–6 years of enterprise cloud security experience.
  • Experience in cloud risk assessments and security controls.
  • Knowledge of cloud platforms (Azure/AWS/GCP) and security tooling.
  • Ability to communicate risks to technical and non-technical stakeholders.

Responsibilities

  • Partner with teams to align solutions with security standards and regulatory requirements.
  • Perform cloud security assessments and architecture reviews across Azure, AWS, and GCP.
  • Assess cloud-native controls across IAM, networking, encryption, logging, and data protection.
  • Review architecture documents to identify risks and improvement opportunities.
  • Conduct threat modelling using STRIDE and support secure-by-design outcomes.
  • Evaluate IaC (Terraform, Bicep) for security risks and misconfigurations.
  • Support integration of security controls into CI/CD and DevSecOps.
  • Perform third‑party security assessments and risk reviews.
  • Collaborate across IAM, PAM, Vulnerability Management, GRC functions.
  • Prepare reports with findings and remediation recommendations.
  • Contribute to governance forums and transformation initiatives.

Skills

Cloud security
IAM/PAM
DevSecOps
Threat modelling
Security architecture
OWASP Top 10
Communication

Tools

Azure
AWS
GCP

Job description

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.

Join EY and help to build a better working world.

Nāu te rourou, nāku te rourou, ka ora ai te iwi

With your contribution and my contribution, together we will thrive.

Hei Oranga Iwi | The opportunity

This is a hybrid position is based in our Tāmaki Makaurau (Auckland)

Join a growing Cyber Security team helping organisations navigate an increasingly complex threat landscape and securely deliver cloud services, enterprise platforms, technology solutions and business transformation initiatives.

As a Cloud Security Consultant, you will work with clients to assess security risks, strengthen cloud security capabilities and support the secure delivery of technology transformation programs. You will provide practical security advice across cloud, identity, network, application and enterprise security domains while helping organisations improve their security posture and resilience.

This opportunity is ideal for a cyber security professional with 4-6 years' experience supporting enterprise cloud environments and technology transformation initiatives. You will have the opportunity to deepen your expertise across cloud security, secure architecture, identity and access management and modern security practices including DevSecOps and cloud governance.

Working closely with Solution Architects, Security Architects, Principal Architects and engineering teams, you will assess enterprise platforms, solutions and services to identify risks, recommend improvements and support secure business outcomes.

Your key responsibilities
  • Partner with business and project teams to assess solutions and ensure alignment with security standards, policies and regulatory requirements.
  • Perform cloud security assessments, architecture reviews and confifiguration reviews across Microsoft Azure, AWS and Google Cloud Platform (GCP).
  • Assess cloud-native security controls across identity, networking, encryption, logging, monitoring, access management and data protection domains.
  • Review solution architectures and Solution Architecture Documents (SADs) to identify security risks, control gaps and opportunities for improvement.
  • Conduct threat modelling activities using established methodologies such as STRIDE and support secure-by-design outcomes.
  • Assess Infrastructure as Code (IaC) implementations, including Terraform, Bicep and cloud-native deployment templates, to identify security risks and misconfifigurations.
  • Support the integration of security controls into CI/CD pipelines and DevSecOps practices.
  • Conduct third-party security assessments, including vendor, SaaS and technology risk reviews.
  • Collaborate across Identity and Access Management (IAM), Privileged Access Management (PAM), Vulnerability Management, Cloud Security and Governance, Risk and Compliance (GRC) functions.
  • Prepare high-quality security assessment reports containing clear fifindings, risk ratings and practical remediation recommendations.
  • Contribute to security governance forums, architecture review boards and transformation initiatives as required.
Skills and attributes for success
Cloud Security
  • Experience conducting cloud security assessments, architecture reviews and risk assessments across enterprise environments.
  • Strong understanding of cloud security principles across Microsoft Azure and at least one of AWS or GCP.
  • Hands-on experience reviewing cloud security confifigurations and security controls.
  • Familiarity with cloud security tooling such as Microsoft Defender for Cloud, AWS Security Hub, Security Command Center, Prisma Cloud or similar solutions.
Identity and Access Security
  • Experience with Identity and Access Management (IAM) and Privileged Access Management (PAM) solutions.
  • Experience with technologies such as Microsoft Entra ID, CyberArk, SailPoint or equivalent platforms.
Security Architecture and Engineering
  • Experience identifying and assessing security controls and compensating controls across enterprise solutions.
  • Understanding of network security, segmentation, encryption, key management and secure architecture principles.
  • Experience with Infrastructure as Code security reviews and cloud governance practices.
  • Exposure to container and Kubernetes security concepts is desirable.
Application Security and DevSecOps
  • Understanding of application security practices and frameworks including OWASP Top 10.
  • Experience with security testing approaches such as SAST, SCA and threat modelling.
  • Exposure to DevSecOps practices and secure CI/CD pipelines is desirable.
Security Frameworks and Standards
  • Working knowledge of industry frameworks and standards such as: NIST Cybersecurity Framework (CSF), ISO 27001 and ISO 27017, CIS Benchmarks
Consulting and Communication
  • Excellent report writing and documentation skills.
  • Strong stakeholder engagement and communication capabilities.
  • Ability to clearly articulate technical risks and recommendations to a variety of audiences.
  • Experience supporting large-scale technology transformation and integration initiatives.
Certifications
  • AZ-500 Microsoft Azure Security Engineer Associate
  • CCSP Certified Cloud Security Professional
  • CCSK Certifificate of Cloud Security Knowledge
  • AWS Security Specialty
  • Google Professional Cloud Security Engineer
What we offer you

At EY, we’ll fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams.

  • Career development: At EY, your career is yours to shape! We’ll develop you with future-focused skills and equip you with world-class experiences www.ey.com/nz/careerdevelopment
  • Flexible work arrangements: Our flexible work policies empower you to balance your professional and personal life, fostering a culture of trust and autonomy.
  • A comprehensive benefits package: From a yearly wellness incentive, to access to additional 8 weeks of flex leave per year, and family-friendly policies, including up to 26 weeks of gender-neutral paid parental leave, we cater to your diverse needs to help you thrive both personally and professionally www.ey.com/nz/benefits

Inclusiveness is core to who we are and how we work together, driving value for our people and for our business. We encourage applications from people of all ages, nationalities, abilities, cultures, sexual orientations, and gender identities and are committed to providing an equitable and barrier free recruitment experience for all. We encourage you to share any support and adjustments you need to be your best and participate equitably in our recruitment process. We understand sharing your needs with us can be daunting, so if you have questions before or during your application, we welcome you to get in touch at contactrecruitment@au.ey.com or +64 9 300 7044 (option 2). Anything you tell us will be kept completely confidential.

EY | Building a better working world

Our preferred applicant will be required to undertake employment screening by EY or our external third-party provider.

© 2026 Ernst & Young New Zealand. A member firm of Ernst & Young Global Limited. All Rights Reserved.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Consultant
Senior Cloud Security Consultant

Ernst & Young Advisory Services Sdn Bhd • Auckland

Hybrid
NZD 120,000 - 180,000
Career development
Flexible work arrangements
Benefits package including extended p‑
Senior Cloud Security Consultant
Senior Cloud Security Consultant

JobSpace • Auckland

Hybrid
NZD 120,000 - 180,000
Flexible work policies
Wellness incentive
Up to 8 weeks flex leave per year
+1
Cyber Risk and Resilience - Senior Consultant - Cybersecurity
Cyber Risk and Resilience - Senior Consultant - Cybersecurity

JobSpace • Auckland

Hybrid
NZD 120,000 - 160,000
Flexible work arrangements
Wellness incentive
8 weeks flex leave per year
+1
Security Operations Centre - SOC Manager- Cyber Security
Security Operations Centre - SOC Manager- Cyber Security

EY • Auckland

On-site
NZD 150,000 - 200,000
Flexible work arrangements
Comprehensive benefits package
Career development
+1
Expressions of Interest - Senior Consultant - Digital Risk - Risk Consulting
Expressions of Interest - Senior Consultant - Digital Risk - Risk Consulting

EY • Auckland

Hybrid
NZD 120,000 - 180,000
Flexible work arrangements
Wellness incentive
8 weeks flex leave per year
+2
Expressions of Interest - Senior Consultant - Digital Risk - Risk Consulting
Expressions of Interest - Senior Consultant - Digital Risk - Risk Consulting

Ernst & Young Advisory Services Sdn Bhd • Auckland

On-site
NZD 90,000 - 150,000
Cyber Resilience Manager - Cybersecurity
Cyber Resilience Manager - Cybersecurity

JobSpace • Auckland

Hybrid
NZD 140,000 - 200,000
Flexible work arrangements
Wellness incentive
8 weeks of flex leave per year
+2
Expression of Interest: Consulting in EY's Defence and National Security practice
Expression of Interest: Consulting in EY's Defence and National Security practice

Ernst & Young Advisory Services Sdn Bhd • Wellington

On-site
NZD 90,000 - 130,000
Flexible work arrangements
Wellness incentives
Gender-neutral parental leave
Senior Cloud Security Consultant – Hybrid (Auckland)
Senior Cloud Security Consultant – Hybrid (Auckland)

EY • Auckland

Hybrid
NZD 120,000 - 180,000
Career development
Flexible work
Wellness incentive & flex leave
Senior Consultant - People Consulting
Senior Consultant - People Consulting

Ernst & Young Advisory Services Sdn Bhd • Auckland

On-site
NZD 100,000 - 140,000