SOC analyst to Cloud security engineer

From SOC analyst to cloud security engineer

Yes, and the cloud alerts you already work are the bridge. You have read CloudTrail or Azure activity logs, chased impossible travel logins and seen a storage bucket go public. A cloud security engineer builds the guardrails that stop those alerts from firing in the first place.

The gap is mostly on the build side: writing IAM policies, reading and writing infrastructure as code, and scripting fixes. You can close most of it in a free-tier account while you are still in the SOC.

Talk to Carmen

Your AI career coach

Say it the way you’d say it to a friend. Carmen will ask what she needs to know.

Free, no sign-up to start.

$129,180 a year

Median pay for information security analysts, May 2025 (BLS has no separate cloud security category)

BLS Occupational Outlook Handbook

$132,410

Median for information security analysts in computer systems design and related services, May 2025

BLS Occupational Outlook Handbook

Five years of IT security experience and two or more years of hands-on experience securing AWS workloads

Recommended experience for AWS Certified Security Specialty

AWS

3+ years of industry experience, including more than 1 year designing and managing solutions on Google Cloud

Recommended experience for Google Professional Cloud Security Engineer

Google Cloud

What already carries over

  • Reading cloud audit logs

    You already know what a suspicious CloudTrail or Entra ID sign-in event looks like. Engineers use the same logs to design detections and to prove a guardrail is working.

  • Identity attack patterns

    Token theft, MFA fatigue and over-permissioned service accounts show up in your queue. In cloud security that knowledge drives least-privilege IAM design and conditional access rules.

  • Detection logic

    Your KQL or SPL queries translate to cloud-native detections and posture rules, such as flagging a security group that opens SSH to the internet.

  • Incident scoping in the cloud

    Knowing how to trace what a compromised key touched is exactly what a cloud engineer needs when designing logging, key rotation and blast radius limits.

  • Triage under noise

    Posture tools produce long lists of misconfigurations. You already know how to rank a queue by real risk, which is most of the job when working through cloud findings.

What to build

  • Hands-on cloud administration

    Open a free-tier account in the cloud your company uses. Build a small setup with a VPC or VNet, one VM, one storage bucket and one user, then lock each piece down and write down what you changed.

  • IAM policy design

    Write IAM policies by hand for three roles in your lab (read-only auditor, developer, CI pipeline), then test that each one cannot do what it should not. Keep the policies in a public Git repo.

  • Infrastructure as code

    Take an introductory Terraform or CloudFormation course and rebuild your lab from code. Add a free IaC scanner to the repo and fix what it flags.

  • Scripting fixes

    Write one Python script against your provider's SDK that finds and fixes a misconfiguration, such as a storage bucket with public access, and document it in the repo README.

  • A provider security certification, when you qualify

    AWS Certified Security Specialty and Google Professional Cloud Security Engineer both list recommended experience on their official pages. Microsoft retired its Azure Security Engineer Associate certification on August 31, 2026, so check Microsoft Learn for what replaces it before studying. ISC2's CCSP requires five years in IT, three of them in cybersecurity.

Your first 90 days

A starting plan. Carmen adjusts it to your hours, your savings and where you live.

  1. 1

    Days 1 to 30

    • Open a free-tier account in your company's main cloud and turn on audit logging on day one.
    • Build the small lab setup, then harden it: MFA on the root or admin account, no public storage, no open management ports.
    • Ask your cloud or platform team which misconfigurations they fix most often, and add those to your lab checklist.
  2. 2

    Days 31 to 60

    • Rebuild the lab in Terraform or CloudFormation and commit it to a public repo.
    • Write three least-privilege IAM roles and one Python remediation script, each with a short README.
    • Offer to help the cloud team with one real task at work, such as onboarding a cloud log source into the SIEM or tuning a cloud detection.
  3. 3

    Days 61 to 90

    • Write a one-page case study from your lab or work task: the risk, what you built, and how you tested it.
    • Rewrite your résumé so SOC bullets show cloud investigation and detection work, then add the repo link.
    • Apply for cloud security engineer and cloud security analyst roles, starting with internal openings, and practice explaining your IAM design choices out loud.

Your résumé, rewritten for cloud security engineer roles

Fill the blanks with your real numbers. Anything you cannot back up, leave out.

Before

Investigated suspicious login alerts in Microsoft Sentinel.

After

Investigated ___ Entra ID identity alerts in Microsoft Sentinel, including impossible travel and token misuse, and recommended conditional access changes to the cloud team.

Before

Escalated AWS GuardDuty findings to the cloud team.

After

Triaged ___ AWS GuardDuty findings, traced affected IAM roles through CloudTrail, and documented least-privilege fixes for ___ over-permissioned roles.

Before

Created and tuned SIEM correlation rules.

After

Built and tuned ___ cloud detections for misconfiguration and credential abuse, reducing false positives by ___%.

Sample conversation

Planning the move with Carmen

Carmen asks before she suggests. An illustrative example, not a real person.

Half my alerts are AWS now and I want to be the one fixing them.

That is a good sign you are ready. Have you ever written an IAM policy yourself, or only read them during investigations?

Only read them. I don't know Terraform either.

Then a free-tier lab built from Terraform is your first project. Want to plan the first two weeks of it around the GuardDuty findings you see most?

Map your own move to cloud security engineer

Carmen’s team maps what carries over from your actual work, then drafts the story of your switch.

Questions & answers

How long does it take to go from SOC analyst to cloud security engineer?
It depends on how much cloud work already reaches your queue, whether your company has a cloud team you can help, and how much lab time you can put in outside shifts. There is no standard timeline, and many people pass through a cloud security analyst role first.
Which cloud should a SOC analyst learn first?
The one your company runs, because you can practice on real logs and ask the platform team questions. After that, pick whichever cloud appears most often in the postings you want.
Do I need a cloud certification to move from SOC to cloud security?
It helps in many postings, and a public lab repo often counts as much in interviews. AWS and Google both publish recommended experience for their security certifications, so read those pages first. Microsoft retired its Azure Security Engineer Associate certification on August 31, 2026.
Do cloud security engineers need to code?
Most postings ask for scripting, usually Python, and infrastructure as code such as Terraform. You do not need to be a software engineer, but you need to read and change the code that defines the environment.

Other moves for security analysts