Updated for 2026

Cloud Security Engineer
Resume Example

A proven resume structure for cloud security engineer roles that highlights cloud-native security controls, infrastructure hardening, and compliance automation.

ATS Score
90
Excellent
Keywords · Impact · Format
Build Your Resume With This Template

Camille Fontaine

San Francisco, CA  |  [email protected]  |  (555) 812-4506  |  linkedin.com/in/camillefontaine
Summary

Cloud security engineer with 5 years of experience securing AWS and Azure environments spanning 1,200+ cloud resources across 8 production accounts. Reduced cloud security findings by 64% through infrastructure-as-code policy enforcement and achieved SOC 2 Type II compliance 3 months ahead of schedule.

Technical Skills
Cloud Security: AWS Security Hub, Azure Defender, GuardDuty, IAM policies, network segmentation, container security, secrets management
Infrastructure & Tools: Terraform, CloudFormation, Kubernetes, Docker, Prisma Cloud, Prowler, Checkov
Compliance & Frameworks: SOC 2, CIS AWS Benchmark, NIST 800-53, FedRAMP, cloud security posture management
Experience
Cloud Security Engineer - Nimbus Technologies
  • Secure 1,200+ cloud resources across 8 AWS production accounts, maintaining a 98.5% compliance score against CIS AWS Benchmark through continuous automated scanning with Prowler
  • Reduced cloud security findings by 64% in 12 months by implementing Checkov and Terraform Sentinel policies that blocked 340+ misconfigured deployments at the CI/CD pipeline stage
  • Led SOC 2 Type II certification for cloud infrastructure, remediating 42 control gaps across 6 service categories and achieving certification 3 months ahead of the planned timeline
  • Designed network segmentation architecture across 5 VPCs that reduced lateral movement attack surface by 78%, validated through 2 third-party penetration tests with zero critical findings
Security Engineer - Stratos Cloud Services
  • Managed AWS Security Hub and GuardDuty across 4 accounts with 650 resources, triaging 120+ findings weekly and achieving 95% remediation within 72-hour SLA
  • Implemented HashiCorp Vault for secrets management across 28 microservices, eliminating 100% of hardcoded credentials and rotating 450+ secrets on automated 30-day cycles
  • Built 16 custom AWS Config rules that detected IAM policy violations, S3 bucket misconfigurations, and encryption gaps, catching 230 issues before production deployment
  • Containerized security scanning into CI/CD pipelines using Trivy and Snyk, reducing container image vulnerabilities by 52% across 35 production Kubernetes workloads
Education
B.S. in Computer Engineering - University of California, Berkeley
Build Your Resume With This Template

Free to start. No credit card required.

Why This Resume Works

1
Cloud Resource Count Defines Scope

Citing 1,200+ resources across 8 accounts establishes multi-account enterprise experience, which is the primary differentiator between junior cloud security work and engineering-level responsibility.

2
Shift-Left Security Demonstrates Modern Practices

Blocking 340+ misconfigurations at the CI/CD stage shows proactive security engineering rather than reactive monitoring, aligning with how modern cloud security teams operate.

3
Compliance Achievement Has Clear Business Value

Completing SOC 2 Type II certification 3 months early translates directly to revenue enablement since many enterprise sales depend on compliance certifications.

Section-by-Section Breakdown

Summary

Specify cloud providers (AWS, Azure, GCP), resource count, and account count to establish multi-cloud or multi-account scale. Lead with your strongest compliance or risk reduction metric.

Skills

Name cloud-native security tools (Security Hub, GuardDuty, Azure Defender) alongside IaC tools (Terraform, Checkov). ATS systems match on exact service names, not generic categories.

Experience

Quantify resources secured, misconfigurations prevented, compliance scores, and remediation timelines. Cloud security hiring managers need to see both scale and speed.

Education

Feature AWS Security Specialty, Azure Security Engineer, or CCSP certifications prominently. Cloud security certifications often carry more weight than degree specifics.

Key Skills for Cloud Security Engineer Resumes

Based on analysis of thousands of job postings, these are the most frequently required skills:

AWS Security Azure Security Cloud Security Posture Management Infrastructure as Code Security Terraform Kubernetes Security Container Security IAM Policy Design Network Segmentation Secrets Management Prisma Cloud AWS Security Hub GuardDuty SOC 2 Compliance CIS Benchmarks CI/CD Pipeline Security

Common Mistakes on Cloud Security Engineer Resumes

  • No Cloud Provider Specificity - Saying cloud security without naming AWS, Azure, or GCP leaves ambiguity about your actual platform experience. Hiring managers need to know which clouds you have secured.
  • Missing Resource or Account Scale - Cloud security complexity scales with resource count and account structure. Without these numbers, a hiring manager cannot assess if your experience matches their environment.
  • No IaC Security Practices - Modern cloud security is shifting left. A resume without Terraform, CloudFormation, or policy-as-code experience signals a reactive approach that most teams have moved beyond.
  • Omitting Compliance Certifications Achieved - SOC 2, FedRAMP, and ISO 27001 are business enablers. Not mentioning which compliance frameworks you helped achieve misses the revenue impact of your security work.
  • Listing Monitoring Without Prevention - Only describing alert triage without mentioning proactive controls like network segmentation, policy enforcement, or automated remediation suggests a monitoring-only skill set.

Related Guides

Ready to build yours?

Upload your existing resume or start fresh. Get an ATS score and AI-powered suggestions in 30 seconds.

More Resume Examples