Senior Cloud Security Consultant

JobSpace

Auckland

Hybrid

NZD 120,000 - 180,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible work policies
Wellness incentive
Up to 8 weeks flex leave per year
Gender-neutral parental leave

Job summary

EY in Auckland is seeking a Cloud Security Consultant to assess cloud security risks, strengthen controls and enable secure delivery of technology transformation programs. You will work with clients across Azure, AWS and GCP to shape secure architectures and DevSecOps practices.

This hybrid role in Tāmaki Makaurau offers collaboration with Solution Architects and governance forums, focusing on IAM, PAM and cloud governance while deepening expertise in security architecture and enterprise

Qualifications

  • Cloud security experience across enterprise environments.
  • Strong understanding of cloud security principles (Azure + AWS/GCP).
  • Experience reviewing cloud security configurations and controls.
  • Familiarity with cloud security tooling (Defender for Cloud, Security Hub, SCC, Prisma Cloud).
  • IAM and PAM experience with Azure AD/CID and privileged access controls.
  • Knowledge of security architectures, encryption, key management, and network security.

Responsibilities

  • Partner with business and project teams to assess solutions and ensure alignment with security standards and regulatory requirements.
  • Perform cloud security assessments, architecture reviews and configuration reviews across Azure, AWS and GCP.
  • Assess cloud-native security controls across IAM, networking, encryption, logging and data protection.
  • Review SADs to identify risks, gaps and improvement opportunities.
  • Conduct threat modelling using STRIDE and support secure-by-design outcomes.
  • Support IaC security reviews (Terraform, Bicep) and cloud governance.
  • Support CI/CD integration of security controls and DevSecOps practices.
  • Conduct third-party security assessments (vendor, SaaS, technology risk).
  • Collaborate across IAM, PAM, Vulnerability Management, Cloud Security and GRC functions.

Skills

Cloud security assessments
Azure security
AWS or GCP security
IAM/PAM security
DevSecOps
Threat modelling
IaC security (Terraform/Bicep)
Security governance
Security reporting
Kubernetes security (desirable)

Tools

Defender for Cloud
AWS Security Hub
Security Command Center
Prisma Cloud
Terraform
Bicep
SAST
SCA

Job description

Location: Auckland Other locations: Primary Location Only Salary: Competitive Date: 25 Aug 2026

At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. With your contribution and my contribution, together we will thrive. This is a hybrid position is based in our Tāmaki Makaurau (Auckland). Join a growing Cyber Security team helping organisations navigate an increasingly complex threat landscape and securely deliver cloud services, enterprise platforms, technology solutions and business transformation initiatives. As a Cloud Security Consultant, you will work with clients to assess security risks, strengthen cloud security capabilities and support the secure delivery of technology transformation programs. You will provide practical security advice across cloud, identity, network, application and enterprise security domains while helping organisations improve their security posture and resilience. This opportunity is ideal for a cyber security professional with 4-6 years' experience supporting enterprise cloud environments and technology transformation initiatives. You will have the opportunity to deepen your expertise across cloud security, secure architecture, identity and access management and modern security practices including DevSecOps and cloud governance. Working closely with Solution Architects, Security Architects, Principal Architects and engineering teams, you will assess enterprise platforms, solutions and services to identify risks, recommend improvements and support secure business outcomes.

Your key responsibilities include:

  • Partner with business and project teams to assess solutions and ensure alignment with security standards, policies and regulatory requirements.
  • Perform cloud security assessments, architecture reviews and configuration reviews across Microsoft Azure, AWS and Google Cloud Platform (GCP).
  • Assess cloud-native security controls across identity, networking, encryption, logging, monitoring, access management and data protection domains.
  • Review solution architectures and Solution Architecture Documents (SADs) to identify security risks, control gaps and opportunities for improvement.
  • Conduct threat modelling activities using established methodologies such as STRIDE and support secure-by-design outcomes.
  • Assess Infrastructure as Code (IaC) implementations, including Terraform, Bicep and cloud-native deployment templates, to identify security risks and misconfigurations.
  • Support the integration of security controls into CI/CD pipelines and DevSecOps practices.
  • Conduct third-party security assessments, including vendor, SaaS and technology risk reviews.
  • Collaborate across Identity and Access Management (IAM), Privileged Access Management (PAM), Vulnerability Management, Cloud Security and Governance, Risk and Compliance (GRC) functions.
  • Prepare high-quality security assessment reports containing clear findings, risk ratings and practical remediation recommendations.
  • Contribute to security governance forums, architecture review boards and transformation initiatives as required.

Skills and attributes for success include:

  • Cloud Security Experience conducting cloud security assessments, architecture reviews and risk assessments across enterprise environments.
  • Strong understanding of cloud security principles across Microsoft Azure and at least one of AWS or GCP.
  • Hands-on experience reviewing cloud security configurations and security controls.
  • Familiarity with cloud security tooling such as Microsoft Defender for Cloud, AWS Security Hub, Security Command Center, Prisma Cloud or similar solutions.
  • Identity and Access Security Experience with Identity and Access Management (IAM) and Privileged Access Management (PAM) solutions.
  • Experience with technologies such as Microsoft Entra ID, CyberArk, SailPoint or equivalent platforms.
  • Security Architecture and Engineering Experience identifying and assessing security controls and compensating controls across enterprise solutions.
  • Understanding of network security, segmentation, encryption, key management and secure architecture principles.
  • Experience with Infrastructure as Code security reviews and cloud governance practices.
  • Exposure to container and Kubernetes security concepts is desirable.
  • Application Security and DevSecOps Understanding of application security practices and frameworks including OWASP Top 10.
  • Experience with security testing approaches such as SAST, SCA and threat modelling.
  • Exposure to DevSecOps practices and secure CI/CD pipelines is desirable.
  • Security Frameworks and Standards Working knowledge of industry frameworks and standards such as: NIST Cybersecurity Framework (CSF), ISO 27001 and ISO 27017, CIS Benchmarks
  • Consulting and Communication Excellent report writing and documentation skills. Strong stakeholder engagement and communication capabilities. Ability to clearly articulate technical risks and recommendations to a variety of audiences. Experience supporting large-scale technology transformation and integration initiatives.

Certifications The following certifications are highly desirable but not mandatory: AZ-500 Microsoft Azure Security Engineer Associate CCSP Certified Cloud Security Professional CCSK Certificate of Cloud Security Knowledge AWS Security Specialty Google Professional Cloud Security Engineer

What we offer you At EY, we'll fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Career development: At EY, your career is yours to shape! We'll develop you with future-focused skills and equip you with world-class experiences. Flexible work arrangements: Our flexible work policies empower you to balance your professional and personal life, fostering a culture of trust and autonomy. A comprehensive benefits package: From a yearly wellness incentive, to access to additional 8 weeks of flex leave per year, and family-friendly policies, including up to 26 weeks of gender-neutral paid parental leave, we cater to your diverse needs to help you thrive both personally and professionally.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Consultant
Senior Cloud Security Consultant

Ernst & Young Advisory Services Sdn Bhd • Auckland

Hybrid
NZD 120,000 - 180,000
Career development
Flexible work arrangements
Benefits package including extended p‑
Cyber Risk and Resilience - Senior Consultant - Cybersecurity
Cyber Risk and Resilience - Senior Consultant - Cybersecurity

JobSpace • Auckland

Hybrid
NZD 120,000 - 160,000
Flexible work arrangements
Wellness incentive
8 weeks flex leave per year
+1
Hybrid Cloud Security Consultant – Auckland
Hybrid Cloud Security Consultant – Auckland

Ernst & Young Advisory Services Sdn Bhd • Auckland

Hybrid
NZD 120,000 - 180,000
Career development
Flexible work arrangements
Benefits package including extended p‑
Hybrid Cloud Security Architect – Enterprise & DevSecOps
Hybrid Cloud Security Architect – Enterprise & DevSecOps

JobSpace • Auckland

Hybrid
NZD 120,000 - 180,000
Flexible work policies
Wellness incentive
Up to 8 weeks flex leave per year
+1
Cloud Security Consultant - Microsoft
Cloud Security Consultant - Microsoft

CyberCX NZ Ltd • New Zealand

Hybrid
NZD 90,000 - 140,000
Flexible hybrid work
Paid leave
Health discounts
+3
Security Operations Centre - SOC Manager- Cyber Security
Security Operations Centre - SOC Manager- Cyber Security

EY • Auckland

On-site
NZD 150,000 - 200,000
Flexible work arrangements
Comprehensive benefits package
Career development
+1
Expressions of Interest - Senior Consultant - Digital Risk - Risk Consulting
Expressions of Interest - Senior Consultant - Digital Risk - Risk Consulting

Ernst & Young Advisory Services Sdn Bhd • Auckland

On-site
NZD 90,000 - 150,000
Cyber Resilience Manager - Cybersecurity
Cyber Resilience Manager - Cybersecurity

JobSpace • Auckland

Hybrid
NZD 140,000 - 200,000
Flexible work arrangements
Wellness incentive
8 weeks of flex leave per year
+2
Senior Cyber Security Consultant
Senior Cyber Security Consultant

CyberCX • Wellington

On-site
NZD 120,000 - 180,000
Expressions of Interest - Senior Consultant - Digital Risk - Risk Consulting
Expressions of Interest - Senior Consultant - Digital Risk - Risk Consulting

EY • Auckland

Hybrid
NZD 120,000 - 180,000
Flexible work arrangements
Wellness incentive
8 weeks flex leave per year
+2