Cloud Security Engineer
Protect cloud infrastructure: identity, network boundaries, data protection and detection across AWS, Azure or Google Cloud.
Consistently in demand because nearly every organisation runs production workloads in the cloud.
Day to day
- •Review IAM policies and remove excess access
- •Build guardrails and detections as code
- •Respond to misconfiguration and credential alerts
- •Advise teams on secure architecture
Start from: Basic networking and Linux
Loading your lab progress…
- 1
Linux, networking and scripting
4–6 weeksBe comfortable on the systems cloud workloads run on.
Linux administration
Most cloud compute is Linux; investigation happens at the shell.
TCP/IP, DNS and TLS
Network controls and most detections are reasoned about at this layer.
Python or Bash automation
Security at cloud scale is automated or it does not happen.
Certifications
- CompTIA Security+ · CompTIA
Portfolio project
Script a report of open ports, users and outdated packages across a set of Linux machines.
- 2
Cloud platform fundamentals
6–8 weeksBuild and operate real workloads on one provider.
Identity and access management
Identity is the primary cloud perimeter; most incidents involve over-broad access.
Virtual networks and security groups
Segmentation limits how far an attacker moves.
Storage and encryption
Public buckets and unencrypted data remain common breach causes.
Certifications
Portfolio project
Deploy a three-tier app with private subnets, least-privilege roles and encrypted storage, documented as a diagram.
- 3
Detection and response
4–6 weeksNotice attacks and contain them quickly.
Cloud audit logging
You cannot investigate what was never logged.
Detection engineering
Turning attacker behaviour into alerts is a core deliverable.
Incident response playbooks
The first hour of a credential leak decides the damage.
Certifications
- AWS Certified Security – Specialty · Amazon Web Services
Portfolio project
Simulate a leaked access key, detect it from logs, and write the containment runbook.
- 4
Guardrails at scale
4 weeksPrevent whole classes of mistakes across an organisation.
Infrastructure as code security
Catching a misconfiguration in review is far cheaper than in production.
Organisation-wide policies
Preventive controls stop mistakes no individual review would catch.
Cloud security architecture
Senior roles are judged on design decisions, not tickets closed.
Certifications
- Certified Cloud Security Professional · ISC2Practise
Portfolio project
Write policy-as-code checks that block public storage and wildcard IAM in a CI pipeline.
Finish line
Prove you're ready to apply
20 workplace scenarios. Reach 80% with no area below 60% for a job-ready signal.
Take the readiness exam
Certification requirements, prices and exam formats change. Always confirm on the issuer's site, linked from the certifications page.