📊 Stat of the Week

Cloud security is now the number two skills gap on security teams worldwide at 36%, behind only AI, yet just 34% of cybersecurity professionals say they have significant cloud security knowledge.

Source: ISC2 2026 Cybersecurity Workforce Study, cloud security deep dive.

What it means for you: Two-thirds of the people already inside cyber cannot confidently secure the cloud. That is not a crowded lane. That is an open door, and it pays a premium to anyone who can prove they have actually done the work.

Hey everyone,

Welcome back to The Career Compass.

This week, Cisco warned that attackers are actively exploiting a flaw in its Catalyst SD-WAN Manager with no patch available, and the affected list reads like a cloud brochure: on-prem, Cloud-Pro, Cisco-managed cloud, and the government FedRAMP cloud. A few days earlier, a self-spreading worm called Miasma hit 73 Microsoft repositories, including Azure and Azure-Samples. Notice the pattern? The breaches everyone is reading about now live in, or move through, the cloud. And the people who can actually secure the cloud are the ones hiring managers keep telling me they cannot find. Let's get into it.

How to Break Into Cloud Security in 2026

Here's the thing. Most people trying to get into cyber are still firing resumes at SOC analyst roles, where they are competing with five hundred other applicants for the same seat. Meanwhile, cloud security sits right next to it, paying more, hiring harder, and getting almost no attention from beginners. That gap is the whole opportunity.

The numbers back it up. The ISC2 2026 Workforce Study puts cloud security as the second biggest skills gap on the planet, behind only AI. Job postings asking for cloud security skills have grown around 28 percent year on year. And here in Australia, a cloud security engineer averages about $137,000, with the range running from roughly $120,000 at the entry end to nearly $200,000 at the top, and senior roles sitting around $175,000. That is not a niche. That is one of the best paid corners of the whole field.

Let's be honest. The reason most beginners skip it is that cloud security sounds intimidating. AWS, Azure, IAM policies, Terraform, container security. It reads like you need to be a senior engineer before you start. You don't. You need to understand a handful of fundamentals deeply, and you need to prove it in public.

Here's the kind of profile that works. Picture a systems administrator at a managed service provider, mid-thirties, with no security title on the resume. Over about seven months they pass the AWS Cloud Practitioner and then the Solutions Architect Associate, build a small public lab on a free-tier account where they create insecure setups and fix them on GitHub, and post one cloud misconfiguration lesson a week on LinkedIn. That is exactly the candidate who gets pulled into a cloud security role, and the thing that gets them hired is not the certs. It is that they can show the work instead of just talking about it.

Here is the path I would follow if I were breaking into cloud security today.

  1. Get cloud-fluent before you try to get cloud-secure. You cannot protect what you do not understand. Start with AWS Cloud Practitioner or Azure Fundamentals (AZ-900), then move to the Solutions Architect Associate. Skip the AWS Security Specialty for now. It is a brilliant cert, but it is built for people with years of hands-on cloud experience, not beginners. Walk before you run.

  2. Build a free-tier lab and break things on purpose. Open a free-tier AWS or Azure account today. Create a deliberately public storage bucket, an over-permissioned IAM role, an open security group. Then hunt those mistakes down and fix them. Free tools like Prowler and ScoutSuite will scan your account and hand you a list of findings. Fixing real misconfigurations is the actual job, so do the actual job before anyone pays you for it.

  3. Master misconfiguration hunting, because that is where the breaches really happen. Most cloud incidents are not exotic zero-days. They are a public bucket, a leaked key, a role with far too much access. Go deep on least-privilege IAM, storage exposure, and network rules. If you want a vendor-neutral foundation, the CCSK from the Cloud Security Alliance has a low barrier to entry and covers the concepts that apply across every cloud.

  4. Map your existing background onto the cloud. This is the step career changers miss. Sysadmins, network engineers, help desk veterans, DevOps people, even GRC and audit folks all carry skills that transfer straight into cloud security. Identity, networking, change control, risk. Do not start from zero. Take what you already know and reframe it in cloud language.

Recruiter's Take: In Australia right now, the cloud talent shortage is so real that I will happily put forward a sysadmin or DevOps person with one solid cloud cert and a public lab over a fresh graduate with a security degree and nothing hands-on. Pick one platform and go deep. AWS dominates Australian enterprise, while Azure rules most of the public sector and government, so check the job ads in your city before you choose. One cloud, proven properly, beats three clouds you have only read about.

  • Cisco Catalyst SD-WAN Manager flaw under active attack, no patch yet (CVE-2026-20245). The affected list spans on-prem and three cloud deployment types. Career angle: this is exactly the work cloud and network security people get paid to handle, and incidents like this are why the roles keep multiplying.

  • Miasma worm hits 73 Microsoft repositories, including Azure. A self-spreading supply chain attack forced GitHub to disable access to dozens of repos. Career angle: cloud and software supply chain security is becoming its own specialism. If you can speak to both, you are rare and valuable.

  • An AI agent uncovered 21 zero-day bugs in FFmpeg, and Chrome shipped a record 429 security fixes in one release (June 2026). The FFmpeg flaws were found by an autonomous agent that scanned around 1.5 million lines of code for roughly $1,000. Career angle: if you worry AI is shrinking entry-level cyber, look closer. It is surfacing flaws faster than anyone can fix them, so demand is rising for the people who can verify, prioritise, and remediate.

  • FIFA World Cup 2026 scams already live, FBI warns, days before kickoff. Researchers tracked more than 4,300 fake FIFA domains. Career angle: every major event spins up fraud, threat intelligence, and brand protection work. Timely, real, and a great topic to write about if you are building a portfolio.

🎬 Video of the Week

No Experience? Build a GRC Analyst Portfolio With These 5 Projects

After my beginner cybersecurity portfolio review video, a lot of you asked for role-specific breakdowns, and GRC kept coming up. So this is the practical follow-up: not another generic roadmap, but a simple proof plan you can use on your CV, LinkedIn, and in interviews. I cover why generic portfolios do not work for GRC, what entry-level candidates actually need to prove, and how to build a cyber risk register, review a security policy, run an Essential Eight or ISO 27001 mini gap assessment, write an audit-style finding, and turn it all into interview evidence.

New videos every week on cybersecurity careers, certifications, and what recruiters actually want.

Build a GRC Portfolio That Gets Interviews

Here's the thing that ties this whole issue together. Whether you are aiming at cloud security or GRC, nobody hires the resume that says "I'm interested." They hire the one who shows the work. That is exactly what this week's video walks through for GRC. If that is your lane, here are the five projects to build.

  1. A cyber risk register. Pick a small fictional business, list ten realistic risks, score each by likelihood and impact, and note a treatment. This one document shows you understand how risk actually gets managed, not just defined.

  2. A security policy review. Take a free template policy, mark it up like a reviewer, and write half a page on what is missing and why. It proves you can read a control and think critically about it.

  3. An Essential Eight or ISO 27001 mini gap assessment. Run a small organisation against the ACSC Essential Eight or a handful of ISO 27001 controls and document the gaps. The Australian angle here is gold, because local hiring managers know the Essential Eight cold.

  4. An audit-style finding. Write up one finding the way an auditor would: condition, criteria, cause, risk, recommendation. Most beginners have never seen this format, so showing it instantly signals you have done the homework.

  5. An interview evidence pack. Turn the four artifacts above into short stories you can tell on the spot. "Here is a gap assessment I built, here is what I found, here is what I would fix first." That is the moment you stop sounding like a beginner.

Watch the full walk-through in the video above, then build one this weekend.

Quick Wins

  1. Open a free-tier AWS or Azure account today and turn on activity logging (CloudTrail in AWS, Activity Log in Azure). Spend twenty minutes clicking through the security console.

  2. Run a free Prowler or ScoutSuite scan against that account and screenshot your top three findings. That is your first piece of proof of work.

  3. Search "cloud security engineer" on SEEK or LinkedIn in your city, save five real job ads, and list every skill and cert that shows up more than once. That is your study plan, written by the market.

🎯 Weekly Challenge

In the next 60 minutes: spin up a free-tier cloud account, deliberately create one public storage bucket, run a scan to detect it, then lock it down. Write a 150-word LinkedIn post explaining what you found, why it was a risk, and how you fixed it. One bucket, one fix, one post. That single post will tell a recruiter more about you than a page of certifications.

New Tool: The Cyber Career Path Explorer

Not sure whether cloud security, GRC, or something else is your lane? That is exactly why I built the free Cyber Career Path Explorer. It maps the major cyber career paths against the salary bands, the certifications that actually matter, and the proof-of-work projects that get you hired, all drawn from 15+ years of recruiting. Pick a path, see what it pays, and get the exact certs and projects to aim at next. It is completely free. Explore your cyber career path here.

From the Desk: Cybersecurity Job-Ready Blueprint

If cloud security is the lane you are eyeing, the Blueprint takes the guesswork out of the first ninety days: which cloud cert to start with, how to turn a free-tier lab into proof of work a recruiter will actually open, and how to position a non-security background so it reads as an advantage. It is a step-by-step guide built from 15+ years of placing candidates into cybersecurity roles, and it covers the exact path from zero to job-ready: which certs to get first, how to build proof of work, how to write a resume that gets past ATS, and how to approach applications like a recruiter. Get the Cybersecurity Job-Ready Blueprint here.

I purchased Luke’s “Cyber Job-Ready Blueprint” when it was first released. One of the first things that impressed me is that, early on, Luke provides three “quick wins” before even diving into the materials.

The ebook is very organized and straight to the point. No opinions. He deals with the mistakes commonly made by those breaking into cybersecurity. This is key, because it addresses mindset, which is huge and often one of the toughest things a job seeker or career pivoter has to overcome. Luke deals with it head-on.

It covers all cyber domains and has something for everyone, and it breaks down exactly what you should be doing week by week.

I highly recommend this book for anyone wanting to pivot into any domain of cybersecurity!

J. Smith

As always, keep levelling up your career.

See you in a fortnight.
Luke
Career Coach | Cybersecurity Recruiter

Subscribe here to get The Career Compass every fortnight.

Keep Reading