Cloud security services
Cloud security services for AWS, Azure and Google Cloud: security assessments, CSPM and CNAPP roll-outs, IAM and access reviews, Kubernetes and container security, network and data protection, and cloud compliance baselines, with dedicated cloud security engineers for your team or cloud security projects delivered end to end.
Cloud security services we provide
Cloud security assessments
A read-only review of your AWS, Azure or Google Cloud accounts against the CIS Foundations Benchmarks and the security pillar of each provider’s Well-Architected Framework, covering identity, network exposure, encryption, logging and backups, delivered as a written list of risks in order of impact.
CSPM and CNAPP roll-outs
Wiz, Microsoft Defender for Cloud, Cortex Cloud, Orca or the open-source Prowler connected to every account and subscription, findings routed to the team that owns each resource, attack paths ranked by what is reachable from the internet, and every accepted risk recorded with an owner and an expiry date.
IAM and access reviews
Unused roles, permissions and access keys found with IAM Access Analyzer, the Google Cloud IAM recommender and Entra ID access reviews, standing administrator rights replaced with just-in-time elevation through Entra Privileged Identity Management or Google Cloud Privileged Access Manager, and every human sign-in moved to single sign-on with phishing-resistant MFA.
Kubernetes and container security
Clusters checked against the CIS Kubernetes Benchmark with kube-bench and Kubescape, images scanned in the registry and signed with Sigstore cosign, admission policies that refuse privileged or unsigned workloads, and Falco watching running containers for shells, unexpected connections and changed binaries.
Guardrails and policy as code
Service control policies, Azure Policy and Google Cloud organisation policies that block public buckets, unencrypted disks and resources in unapproved regions, with Checkov or OPA policies in the pull request so a misconfiguration is caught before Terraform applies it.
Cloud network security
Databases and storage reachable only through private endpoints, outbound traffic filtered, AWS WAF, Azure Web Application Firewall or Cloud Armor with DDoS protection in front of public services, and internal tools published through Identity-Aware Proxy, Entra Private Access or Cloudflare Access rather than a VPN.
Data protection and key management
Sensitive data found in buckets and databases with Amazon Macie, Microsoft Purview or Sensitive Data Protection, encryption under customer-managed keys in KMS, Key Vault or Cloud KMS with rotation, and backups held in immutable vaults that a stolen administrator account cannot delete.
Secrets and workload identity
Credentials moved out of code, variables and images into Secrets Manager, Key Vault, Secret Manager or HashiCorp Vault, secret scanning with push protection on every repository, and pipelines and services signing in through workload identity federation, so no long-lived key is left to leak.
Cloud compliance baselines
Accounts measured continuously against CIS, NIST SP 800-53, PCI DSS or ISO 27001 control sets through AWS Config conformance packs, Azure Policy regulatory compliance and Security Command Center, with data kept in EU regions where GDPR or a customer contract requires it.
Hire cloud security engineers
Dedicated cloud security engineers
Cloud security engineers who join your team full time, work in your tools and process, and report to your lead. You interview them; we carry the Ukrainian contract, payroll, invoicing and leave.
Cloud security projects
A defined piece of cloud security with a scope, a fixed plan and a named lead on our side who owns the result and reports progress in your channels.
Ongoing cloud security
Cloud security as a continuing service: the same people every month, a backlog you prioritise, and hours you can see in our portal and on the invoice.
The dedicated team page explains how specialists join your team, and the outsourcing page covers project delivery, take-overs and how we charge.
Who works on your cloud security
Cloud security engineers
Posture, identity, network and data protection
Cloud and DevOps engineers
Fixes written as Terraform and pipeline changes
Kubernetes security engineers
Cluster benchmarks, admission policies and runtime detection
Penetration testers
Attacks on cloud accounts and the applications in them
Security architects
Landing zone, identity and network design reviews
How we work on cloud security
Work starts with read-only access through a role you create and can revoke, and every phase ends with findings ranked by what an attacker could reach. Fixes arrive as pull requests to your Terraform, Bicep or CDK code and your pipelines, so each change is reviewed, repeatable and does not drift back the next time someone edits a setting in the console.
Posture tools find the misconfiguration, a penetration test shows what an attacker can do with it, and security monitoring catches the attempt, so we connect the three: high-risk findings are retested after the fix, and the riskiest attack paths get a detection rule in your SIEM. Our own platform runs under the same rules: every resource in Terraform, GitHub Actions with federated credentials and actions pinned by hash, secrets only in Key Vault, deny-by-default firewalls and drift detection on a schedule.
Other cloud, DevOps and security services
AWS development
AWS development services: EKS and ECS containers, serverless, landing zones, migrations, databases, data platforms, Bedrock generative AI, security and cost optimisation, with dedicated AWS engineers or project delivery.
Google Cloud development
Google Cloud development services: Cloud Run and GKE, BigQuery, Firebase backends, Cloud SQL and AlloyDB, Gemini on Agent Platform, security and migrations, with dedicated Google Cloud engineers or project delivery.
Kubernetes consulting
Kubernetes consulting and development: clusters on EKS, AKS, GKE and on premises, Helm, GitOps with Argo CD or Flux, cluster security, upgrades and GPU workloads, with dedicated Kubernetes engineers or project delivery.
DevOps and CI/CD
DevOps and CI/CD services: pipelines, Terraform infrastructure as code, observability, SRE and on-call, DevSecOps, platform engineering and FinOps, with dedicated DevOps and SRE engineers or ongoing DevOps work.
Cybersecurity and pentesting
Cybersecurity and penetration testing services: web, mobile, API, network and cloud pentests, secure code review, SOC and incident response, ISO 27001 and SOC 2, with dedicated security engineers or defined projects.
IT infrastructure
IT infrastructure and system administration services: Windows and Linux servers, networks, Microsoft 365 and Entra ID, virtualisation, backups and telecom, with dedicated system administrators or ongoing support.
Site reliability engineering
Site reliability engineering services: SLOs, OpenTelemetry observability, on-call and incident management, load testing, disaster recovery and chaos engineering, with dedicated SRE engineers or project delivery.
Platform engineering
Platform engineering services: internal developer platforms, Backstage portals, golden paths and templates, self-service infrastructure and Kubernetes platforms, with dedicated platform engineers or project delivery.
Cloud architecture
Cloud architecture and consulting services: designs for AWS, Azure and Google Cloud, migration plans, landing zones, Well-Architected reviews, resilience and cost, with dedicated cloud architects or project delivery.
FinOps
FinOps and cloud cost optimisation services: cost allocation, rightsizing, savings plans and reservations, Kubernetes, data and AI costs, budgets and anomaly alerts, with dedicated FinOps engineers or project delivery.
Terraform and IaC
Terraform and infrastructure as code services: Terraform and OpenTofu modules, imports, plan and apply pipelines, drift control, policy as code and Ansible, with dedicated Terraform engineers or project delivery.
Linux administration
Linux administration services: Ubuntu, Debian, RHEL, Rocky Linux and AlmaLinux servers set up, patched, hardened, monitored and backed up, and end-of-life upgrades, with dedicated Linux administrators or ongoing support.
Network engineering
Network engineering services: routing and switching, firewalls, SD-WAN and zero-trust access, cloud networking, Wi-Fi and automation on Cisco, Juniper and Fortinet, with dedicated network engineers or project delivery.
SOC and security monitoring
SOC as a service and security monitoring: managed SOC, SIEM deployment, log onboarding, detection engineering, EDR, threat hunting and incident response retainers, with dedicated SOC analysts or ongoing monitoring.
Security compliance
Security compliance and audit readiness: ISO 27001, SOC 2, GDPR, PCI DSS, HIPAA, NIS2 and DORA controls, gap assessments and audit evidence, with dedicated compliance engineers or a readiness project.
Questions about cloud security
Which industries do your cloud security engineers work in?
Mostly fintech, banking and insurance, where cloud accounts sit inside PCI DSS and DORA scope; cybersecurity companies running their own products in the cloud; cloud, hosting and telecom providers; e-commerce and retail, protecting checkout and customer data; SaaS companies answering their customers’ security reviews; healthcare products that hold patient data; AI and data products with large data stores and model endpoints; and industrial and energy firms connecting plant data to the cloud.
Is a cloud security assessment the same as a penetration test?
No. An assessment reads your configuration from the inside with read-only access and finds what is misconfigured across every account. A penetration test attacks your applications and accounts from the outside, under written authorisation, to show what can actually be exploited. Many clients start with the assessment and follow with a test of the riskiest paths, and we run both.
Which CSPM or CNAPP tools do you work with?
Microsoft Defender for Cloud, AWS Security Hub and Google Security Command Center, which come with their clouds; Wiz, Cortex Cloud and Orca, which cover several clouds in one console; and the open-source Prowler, which runs the CIS checks without a licence. We roll out, tune and run whichever you choose, and keep the fixes in your infrastructure code.
How quickly can cloud security engineers start?
When the right cloud security engineer is available, the start is gated only by your interview and the NDA and IP assignment. Otherwise we run a search, which typically produces candidate profiles within two to three weeks, and nobody starts until you have said yes.
How do we hire cloud security engineers through BigTree108?
Tell us the work, the seniority and the hours you need. We propose one or two people with their profiles, you interview them the way you would interview your own hire, and you sign one agreement with BIG TREE 108 LLC and receive one invoice a month.
Who owns the work they produce?
You do. Every specialist has a signed contract with BigTree108 that assigns all work product to the company, and our agreement with you assigns it onward. Code, designs and documents are delivered into your own repositories and tools, not kept where only we can change them.
Need your cloud accounts reviewed?
Tell us which clouds you use, how many accounts or subscriptions you run and any audit or customer review you are preparing for. You get an answer within one business day: a scope for an assessment, a plan for the work, or candidate profiles.