Skip to content
BigTree108

Cloud security services

Cloud security services for AWS, Azure and Google Cloud: security assessments, CSPM and CNAPP roll-outs, IAM and access reviews, Kubernetes and container security, network and data protection, and cloud compliance baselines, with dedicated cloud security engineers for your team or cloud security projects delivered end to end.

Cloud security services we provide

  • Cloud security assessments

    A read-only review of your AWS, Azure or Google Cloud accounts against the CIS Foundations Benchmarks and the security pillar of each provider’s Well-Architected Framework, covering identity, network exposure, encryption, logging and backups, delivered as a written list of risks in order of impact.

  • CSPM and CNAPP roll-outs

    Wiz, Microsoft Defender for Cloud, Cortex Cloud, Orca or the open-source Prowler connected to every account and subscription, findings routed to the team that owns each resource, attack paths ranked by what is reachable from the internet, and every accepted risk recorded with an owner and an expiry date.

  • IAM and access reviews

    Unused roles, permissions and access keys found with IAM Access Analyzer, the Google Cloud IAM recommender and Entra ID access reviews, standing administrator rights replaced with just-in-time elevation through Entra Privileged Identity Management or Google Cloud Privileged Access Manager, and every human sign-in moved to single sign-on with phishing-resistant MFA.

  • Kubernetes and container security

    Clusters checked against the CIS Kubernetes Benchmark with kube-bench and Kubescape, images scanned in the registry and signed with Sigstore cosign, admission policies that refuse privileged or unsigned workloads, and Falco watching running containers for shells, unexpected connections and changed binaries.

  • Guardrails and policy as code

    Service control policies, Azure Policy and Google Cloud organisation policies that block public buckets, unencrypted disks and resources in unapproved regions, with Checkov or OPA policies in the pull request so a misconfiguration is caught before Terraform applies it.

  • Cloud network security

    Databases and storage reachable only through private endpoints, outbound traffic filtered, AWS WAF, Azure Web Application Firewall or Cloud Armor with DDoS protection in front of public services, and internal tools published through Identity-Aware Proxy, Entra Private Access or Cloudflare Access rather than a VPN.

  • Data protection and key management

    Sensitive data found in buckets and databases with Amazon Macie, Microsoft Purview or Sensitive Data Protection, encryption under customer-managed keys in KMS, Key Vault or Cloud KMS with rotation, and backups held in immutable vaults that a stolen administrator account cannot delete.

  • Secrets and workload identity

    Credentials moved out of code, variables and images into Secrets Manager, Key Vault, Secret Manager or HashiCorp Vault, secret scanning with push protection on every repository, and pipelines and services signing in through workload identity federation, so no long-lived key is left to leak.

  • Cloud compliance baselines

    Accounts measured continuously against CIS, NIST SP 800-53, PCI DSS or ISO 27001 control sets through AWS Config conformance packs, Azure Policy regulatory compliance and Security Command Center, with data kept in EU regions where GDPR or a customer contract requires it.

Hire cloud security engineers

  • Dedicated cloud security engineers

    Cloud security engineers who join your team full time, work in your tools and process, and report to your lead. You interview them; we carry the Ukrainian contract, payroll, invoicing and leave.

  • Cloud security projects

    A defined piece of cloud security with a scope, a fixed plan and a named lead on our side who owns the result and reports progress in your channels.

  • Ongoing cloud security

    Cloud security as a continuing service: the same people every month, a backlog you prioritise, and hours you can see in our portal and on the invoice.

The dedicated team page explains how specialists join your team, and the outsourcing page covers project delivery, take-overs and how we charge.

Who works on your cloud security

  • Cloud security engineers

    Posture, identity, network and data protection

  • Cloud and DevOps engineers

    Fixes written as Terraform and pipeline changes

  • Kubernetes security engineers

    Cluster benchmarks, admission policies and runtime detection

  • Penetration testers

    Attacks on cloud accounts and the applications in them

  • Security architects

    Landing zone, identity and network design reviews

How we work on cloud security

Work starts with read-only access through a role you create and can revoke, and every phase ends with findings ranked by what an attacker could reach. Fixes arrive as pull requests to your Terraform, Bicep or CDK code and your pipelines, so each change is reviewed, repeatable and does not drift back the next time someone edits a setting in the console.

Posture tools find the misconfiguration, a penetration test shows what an attacker can do with it, and security monitoring catches the attempt, so we connect the three: high-risk findings are retested after the fix, and the riskiest attack paths get a detection rule in your SIEM. Our own platform runs under the same rules: every resource in Terraform, GitHub Actions with federated credentials and actions pinned by hash, secrets only in Key Vault, deny-by-default firewalls and drift detection on a schedule.

Other cloud, DevOps and security services

Cloud, DevOps and security overview

Questions about cloud security

Which industries do your cloud security engineers work in?

Mostly fintech, banking and insurance, where cloud accounts sit inside PCI DSS and DORA scope; cybersecurity companies running their own products in the cloud; cloud, hosting and telecom providers; e-commerce and retail, protecting checkout and customer data; SaaS companies answering their customers’ security reviews; healthcare products that hold patient data; AI and data products with large data stores and model endpoints; and industrial and energy firms connecting plant data to the cloud.

Is a cloud security assessment the same as a penetration test?

No. An assessment reads your configuration from the inside with read-only access and finds what is misconfigured across every account. A penetration test attacks your applications and accounts from the outside, under written authorisation, to show what can actually be exploited. Many clients start with the assessment and follow with a test of the riskiest paths, and we run both.

Which CSPM or CNAPP tools do you work with?

Microsoft Defender for Cloud, AWS Security Hub and Google Security Command Center, which come with their clouds; Wiz, Cortex Cloud and Orca, which cover several clouds in one console; and the open-source Prowler, which runs the CIS checks without a licence. We roll out, tune and run whichever you choose, and keep the fixes in your infrastructure code.

How quickly can cloud security engineers start?

When the right cloud security engineer is available, the start is gated only by your interview and the NDA and IP assignment. Otherwise we run a search, which typically produces candidate profiles within two to three weeks, and nobody starts until you have said yes.

How do we hire cloud security engineers through BigTree108?

Tell us the work, the seniority and the hours you need. We propose one or two people with their profiles, you interview them the way you would interview your own hire, and you sign one agreement with BIG TREE 108 LLC and receive one invoice a month.

Who owns the work they produce?

You do. Every specialist has a signed contract with BigTree108 that assigns all work product to the company, and our agreement with you assigns it onward. Code, designs and documents are delivered into your own repositories and tools, not kept where only we can change them.

Need your cloud accounts reviewed?

Tell us which clouds you use, how many accounts or subscriptions you run and any audit or customer review you are preparing for. You get an answer within one business day: a scope for an assessment, a plan for the work, or candidate profiles.