Senior Cloud Detection Engineer

Deloitte•Tampa, FL
•Hybrid

About The Position

Our current cloud security tooling is a genuinely wide, still-evolving mix — cloud-native platforms, CNAPP tooling, and classic SIEM — with real room to bring more coherence to it, and a real appetite to bring AI into how we build, detect, and analyze. If designing the telemetry, data, and infrastructure that a global organization depends on to detect and respond to threats across a multi-cloud environment sounds like a good problem to work on, read on to learn about an opportunity on the Cloud Defensive Operations team within Deloitte's Global Cloud Security (GCS) organization. As a Cloud Defense Security Engineer, you'll design, build, and directly manage the cloud security telemetry, monitoring, and alerting infrastructure that underpins how Deloitte's global cloud platform — used by Member Firms worldwide — is defended. GCS builds the platform-level capabilities that our Cyber Defense team relies on to see, understand, and respond to what's happening across the cloud — so your work has direct, foundational impact on Cyber, without the SOC or on-call rotation that usually comes with it. This role is anchored in strong, hands-on technical execution across AWS, Azure, and/or GCP. The ability to collaborate across teams and contribute to strategy matters too, but it's something we'll help you build over time rather than expect on day one. This role reports to the Cloud Defensive Operations Manager.

Requirements

  • BACHELOR'S DEGREE OR EQUIVALENT EXPERIENCE, PLUS 5+ YEARS IN SOFTWARE ENGINEERING, CLOUD ENGINEERING, OR DATA ENGINEERING
  • HANDS-ON, MULTI-CLOUD EXPERIENCE (AWS, AZURE, AND/OR GCP), INCLUDING DIRECTLY MANAGING CLOUD SECURITY INFRASTRUCTURE SUCH AS LOGGING AND ALERTING
  • PROGRAMMING AND INFRASTRUCTURE AS CODE EXPERIENCE (E.G., PYTHON, TERRAFORM, OR SIMILAR)
  • SOME EXPERIENCE WITH DATA MODELING OR CORRELATING DATA ACROSS SYSTEMS, AND COMMUNICATING WITH STAKEHOLDERS OUTSIDE YOUR IMMEDIATE TEAM — DEPTH ISN'T REQUIRED, BUT THIS SHOULDN'T BE UNCHARTED TERRITORY
  • MUST BE LEGALLY AUTHORIZED TO WORK IN THE UNITED STATES WITHOUT EMPLOYER SPONSORSHIP, NOW OR IN THE FUTURE

Nice To Haves

  • BROADER AUTOMATION, SCRIPTING, OR IAC EXPERIENCE (TERRAFORM, BICEP, PULUMI); FAMILIARITY WITH UNIFIED DATA PLATFORMS, DATA MODELING, DATA SCIENCE, OR REPORTING/BI TOOLS SUCH AS POWER BI
  • HANDS-ON EXPERIENCE WITH MAJOR SIEM OR LOG-ANALYTICS PLATFORMS — SPLUNK, MICROSOFT SENTINEL, OR GOOGLE SECOPS/CHRONICLE — AND QUERY AUTHORING IN KQL, SPL, OR SIMILAR CORRELATION LANGUAGES
  • EXPERIENCE WITH MAJOR CLOUD-NATIVE SECURITY PLATFORMS OR CNAPP TOOLING SUCH AS WIZ, PRISMA CLOUD, MICROSOFT DEFENDER FOR CLOUD, OR ORCA SECURITY.
  • EXPOSURE TO KUBERNETES/DOCKER SECURITY, AND AWARENESS OF FRAMEWORKS LIKE MITRE ATT&CK FOR CLOUD.
  • HANDS-ON USE OF AI TOOLS FOR BUILDING, ANALYZING, OR CORRELATING SECURITY DATA
  • AWS CERTIFIED SECURITY – SPECIALTY, MICROSOFT CERTIFIED: AZURE SECURITY ENGINEER ASSOCIATE (AZ-500), GOOGLE CLOUD PROFESSIONAL CLOUD SECURITY ENGINEER, CCSP, GIAC GCSA/GCDA, OR CERTIFIED KUBERNETES SECURITY SPECIALIST (CKS)
  • EXPERIENCE WITH SECURITY OPERATIONS, INCIDENT RESPONSE, OR CYBER DEFENSE AS A PARTNER TEAM.

Responsibilities

  • Contribute to an internal platform GCS builds to support Cyber Defense's cloud investigation, triage, and response.
  • Help bring cloud-native alerts, internal configuration guardrails, and our cloud-native application protection (CNAPP) service into a more unified view, in a landscape that's genuinely still evolving.
  • Explore how AI can change how we build, detect, and analyze — from AI-assisted engineering to AI-driven correlation across data sources.

Benefits

  • Deloitte is committed to providing reasonable accommodations for people with disabilities. If you require a reasonable accommodation to participate in the recruiting process, please direct your inquiries to the Global Call Center (GCC) at [email protected].
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service