Job Requisition ID: 41886
Reporting to the Director of SOC Engineering, you will own our managed cloud security capability end to end: the Wiz practice that underpins our Managed Cloud Detection and Response service, the proactive posture and secure development work that sits on top of it, and the vulnerability management service delivered alongside. You are both the product owner for cloud security and the lead of the small team that delivers it.
On a given day you might scope a new client's onboarding across their AWS, Azure and GCP organisations, review a Terraform change that promotes detection content into a client's Wiz tenant, work the posture backlog with an engineer to turn a toxic combination into a prioritised client action with a due date, agree a containment playbook and the authorisation that goes with it, walk a SOC analyst through the identity path behind a cloud detection, sit with a pursuit team to qualify a deal and size the retained hours, or run the quarterly service review where you explain to a client's security leadership why their exposure trend moved.
A large part of the job is holding the boundary that makes the service deliverable: what belongs in the 24x7 detection stream with an SLA against it, what is paid posture engineering, and what stays with the client to remediate. You will move comfortably between building in a client tenant, reviewing other engineers' work, and stepping back to make the service and design calls.
This is a build role as much as a run role. The service is defined but young, so you will take it from a catalogue entry to a repeatable, priced, evidenced service with reference engagements behind it.
About the team
You will join a small, high impact engineering team that builds and runs the platforms and services behind our managed security offerings. Cloud security and exposure is a new, deliberately small team: you plus two engineers with AWS and Azure depth, backed by a much wider bench of SIEM and XDR engineers who carry cloud security as a secondary skill and flex in when an onboarding or a large posture programme needs the numbers. Building that bench, including the first certified cohort and the path that keeps it current, is part of the role rather than a nice to have.
Our culture is straightforward and down to earth, more t-shirts and jeans than suits, and we care a lot about getting the engineering right. You will work closely with the 24x7 SOC that triages cloud detections, the detection engineering function that authors content, the platform engineering team that runs our own cloud, and the pursuit and product teams who take the offer to market.
Enough about us, let's talk about you
Strong hands-on experience across at least two of AWS, Azure and GCP at organisation or tenant scope, including identity and access, control plane logging, networking, and container or serverless workloads
Practical experience with Wiz or a comparable CNAPP / cloud detection and response platform, covering posture management, cloud entitlements, data security posture and threat detection
Solid understanding of how attacks play out in cloud environments, including identity abuse, control plane attacks, metadata risk, Kubernetes and container runtime activity, and data exfiltration paths
Proven capability with Terraform, Git-based change control, CI/CD pipelines and automation, including the judgement to build against vendor APIs where supported tooling is limited
Experience implementing or managing detection content and integrating cloud telemetry into SIEM, SOAR, EDR or ITSM workflows
Experience leading a managed or client-facing service, including ownership of scope boundaries, SLAs, onboarding, reporting, continuous improvement and commercial discussions
Confidence leading and developing engineers, setting standards, reviewing technical work constructively, and building capability across a wider delivery bench
Nice to have: experience with Rapid7, Qualys, Tenable, Microsoft Defender for Vulnerability Management, AWS Inspector, secure development controls, sovereign or regulated environments, managed services, or platform migrations
Why Deloitte?
At Deloitte, we focus our energy on interesting and impactful work. We’re always learning, innovating and setting the standard; making a positive difference to our clients and our society. We putcoaching at the heart of what we do, helping our people grow their careers in any direction – whether it be up, moving into something new, or even moving across the world.
We embrace diversity, equity and inclusion. We have a diverse collection of people from different backgrounds, with different experiences, gender identities, abilities and thinking styles. What binds us together is a shared commitment to value everyone’s perspective and to cultivate inclusion; so that our work environment is a safe space we can all belong.
We value in-person connection with our clients and our colleagues. We offer several ways for you to work flexibly so that you can serve your clients, stay connected with your team, and manage your personal priorities.
We help you live and work well. To support your personal and professional life, we offer a range of perks and benefits, including retail discounts, wellbeing leave, paid volunteering days, twelve flexible working options, market-leading parental leave and return to work support package.
Next Steps
Sound like the sort of role for you? Apply now, we’d love to hear from you!
#LI-Hybrid
By applying for this job, you’ll be assessed against the Deloitte Talent Standards. We’ve designed these standards so that you can grow in your career, and we can provide our clients with a consistent and exceptional Deloitte employee experience globally. The preferred candidate will be subject to background screening by Deloitte or by their external third-party provider.

Deloitte drives progress. Our firms around the world help clients become leaders wherever they choose to compete. Deloitte invests in outstanding people of diverse talents and backgrounds and empowers them to achieve more than they could elsewhere. Our work combines advice with action and integrity. We believe that when our clients and society are stronger, so are we.
Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited (“DTTL”), its global network of member firms, and their related entities. DTTL (also referred to as “Deloitte Global”) and each of its member firms are legally separate and independent entities. DTTL does not provide services to clients. Please see www.deloitte.com/about to learn more.
The content on this page contains general information only, and none of Deloitte Touche Tohmatsu Limited, its member firms, or their related entities (collectively the “Deloitte Network”) is, by means of this publication, rendering professional advice or services. Before making any decision or taking any action that may affect your finances or your business, you should consult a qualified professional adviser. No entity in the Deloitte Network shall be responsible for any loss whatsoever sustained by any person who relies on content from this page.