Home Disciplines Cloud security
CLOUD SECURITY
Cloud security recruitment
Cloud security is the most oversubscribed brief in the market and the one most often written wrong. Employers ask for cloud experience; what they usually need is an engineer who can build guardrails in code and argue with a platform team. Those are different people.
What we place
- CLOUD SECURITY ENGINEER
- Builds and operates controls in AWS, Azure or GCP — identity, network, logging, guardrails, all of it in code.
- DEVSECOPS ENGINEER
- Security in the pipeline: scanning, policy as code, secrets management, and the workflow negotiations that come with it.
- CONTAINER & KUBERNETES
- Cluster hardening, admission control, workload identity and runtime security. A genuine specialism, not a bullet point.
- CLOUD SECURITY ARCHITECT
- Landing zones, tenancy models and reference patterns. Covered in more depth on our architecture page.
- CSPM / POSTURE
- Owns posture tooling and, more importantly, drives the remediation it generates through other teams.
- CLOUD IDENTITY
- Entitlement management, cross-account access and workload identity — where cloud security and IAM meet.
How we screen
The screen is practical. We ask what a candidate has built, in which account structure, with what tooling, and what broke. People who have genuinely done the work talk about drift, exceptions and the pull request nobody would approve. People who have read about it talk in service names.
We also test collaboration, because cloud security roles fail on it more than on skill. The job involves telling platform engineers their pipeline is now slower. We ask how someone has landed an unpopular control without a mandate, and the answer is usually decisive.
The market, honestly
Demand outstrips supply in both markets and it is the clearest example of remote competition affecting South African employers: a Cape Town cloud security engineer can be hired by a European company at European rates without leaving home. Local employers who insist on five days in an office are choosing from a much smaller pool than they think.
Certification inflation is heavy here. AWS and Azure security certifications are cheap to accumulate and tell you little; we weight demonstrable infrastructure-as-code work far higher, and we will say when a certified candidate has never held production access.
A brief asking for deep AWS, deep Azure, Kubernetes and Terraform at mid-level pay is describing three people. We would rather rank the priorities with you than search for two months.
Where we recruit
Cape Town and Johannesburg across South Africa, and London and the wider United Kingdom.
Common questions
Do you recruit for AWS, Azure and GCP?
All three. Azure dominates enterprise briefs in both markets, AWS dominates product and fintech, and GCP appears occasionally. Multi-cloud depth in one candidate is rare and worth paying for.
Is cloud security the same as DevSecOps?
They overlap heavily and the titles are used interchangeably. Cloud security tends to centre on the environment and its controls; DevSecOps centres on the pipeline and developer workflow. We clarify which the role weights before advertising.
Can you find Kubernetes security specialists?
Yes, though the pool is small. Most candidates have cluster exposure rather than security depth, and we are explicit about which we are presenting.
How does remote hiring affect cloud security salaries in South Africa?
Materially. Strong cloud security engineers in South Africa routinely have offshore offers in stronger currencies. Employers competing for them need either genuine flexibility or a package that acknowledges the competition.
Related disciplines
Talk to us about your search
A short conversation is usually enough to tell you whether we can help.