School of Cybersecurity · Advanced

Cloud Security Engineering Course

Secure cloud identities, networks, data, workloads and delivery pipelines - then investigate and respond to cloud attacks.

Talk to an advisor on WhatsApp
Cloud Security Engineering course illustration at Brightnest AI Academy
Cloud Security Architecture and Shared ResponsibilityCloud IAM and Privileged AccessNetwork and Perimeter SecurityData, Secrets and Key Security
Cloud architecture toolsAWSAzureGCP IAM conceptsCloud network
Duration10–12 weeks78 hours
Batch startsConfirm with admissionsOpen for registration
Learning formatLive mentor-led instruction, guided labs, assignments, feedback and project reviewsLive online / classroom
Curriculum8 modulesLabs and assessed capstone
Portfolio2 projectsPlus module evidence
LevelAdvancedCourse level
PathwayCybersecurity EngineerRelated career pathway

How you will learn

Live instructor-led sessions that connect concepts to real workplace decisions.
Guided labs and workshops in every module.
Assignments, checkpoints and practical feedback.
Portfolio documentation, demonstrations and capstone review.
Access to recordings and LMS resources according to the published batch policy.
Career preparation based on completed work and target roles.
Course curriculum

What you will learn, module by module

Secure cloud workloads, identities, networks, data and DevSecOps pipelines. Progress from Cloud Security Architecture and Shared Responsibility to Governance, Compliance and Cloud Security Capstone through guided labs, assessed projects, and portfolio evidence.

01Module 1 · 6 hoursCloud Security Architecture and Shared ResponsibilityThreat-model a cloud application and identify responsibility/control ownership.
Topics you will cover
  • Cloud service models
  • Shared responsibility
  • Threat modelling
  • Landing zones
  • Multi-account/subscription/project strategy
  • Zero trust principles
Tools and platforms
Cloud architecture tools
Portfolio evidence
Cloud threat model
Assessment
Architecture case
02Module 2 · 10 hoursCloud IAM and Privileged AccessRedesign an overprivileged cloud IAM model and implement least-privilege roles in a lab.
Topics you will cover
  • Cloud identities
  • Roles/policies
  • Least privilege
  • Workload identities
  • Federation
  • MFA
  • Privileged access
Tools and platforms
AWS/Azure/GCP IAM concepts
Portfolio evidence
Cloud IAM control matrix
Assessment
IAM lab
03Module 3 · 8 hoursNetwork and Perimeter SecurityDesign secure network segmentation for a three-tier cloud workload.
Topics you will cover
  • VPC/VNet design
  • Segmentation
  • Private endpoints
  • Security groups/NSGs/firewalls
  • WAF
  • DDoS concepts
  • Egress controls
Tools and platforms
Cloud network/security services
Portfolio evidence
Secure cloud network diagram
Assessment
Network design review
04Module 4 · 8 hoursData, Secrets and Key SecurityImplement a secrets and encryption strategy for application/data services.
Topics you will cover
  • Classification
  • Encryption
  • KMS/key vaults
  • Secrets management
  • Rotation
  • Storage policies
  • Database controls
Tools and platforms
KMS/Key Vault/Secret Manager concepts
Portfolio evidence
Cloud data protection design
Assessment
Data security lab
05Module 5 · 10 hoursWorkload, Container and Serverless SecurityAssess a containerised workload and design preventive/detective controls.
Topics you will cover
  • VM hardening
  • Images
  • Containers
  • Kubernetes security concepts
  • Serverless permissions
  • Runtime controls
  • Supply chain
Tools and platforms
Container scanner concepts, Kubernetes security controls
Portfolio evidence
Cloud workload hardening plan
Assessment
Workload review
06Module 6 · 10 hoursDevSecOps, CSPM and Cloud PostureAdd IaC/container scanning and posture checks to a deployment pipeline.
Topics you will cover
  • IaC scanning
  • Policy-as-code
  • CI/CD security
  • CSPM/CNAPP concepts
  • Misconfiguration detection
  • Compliance mapping
  • Remediation workflows
Tools and platforms
Terraform, CI/CD, CSPM/CNAPP concepts
Portfolio evidence
Secure cloud deployment pipeline
Assessment
DevSecOps lab
07Module 7 · 10 hoursCloud Detection, Incident Response and ForensicsInvestigate a simulated cloud account compromise and execute a response playbook.
Topics you will cover
  • Cloud audit logs
  • Identity events
  • Workload telemetry
  • Detection use cases
  • Compromised credentials
  • Isolation
  • Snapshots
Tools and platforms
Cloud audit/monitoring logs, SIEM concepts
Portfolio evidence
Cloud incident response report
Assessment
Cloud IR practical
08Module 8 · 16 hoursGovernance, Compliance and Cloud Security CapstoneSecure an end-to-end cloud application and present architecture, controls, detections and incident plan.
Topics you will cover
  • Control frameworks
  • Policies
  • Continuous compliance
  • Risk
  • Third parties
  • Data residency
  • Architecture review
Tools and platforms
AWS/Azure/GCP security services, IaC, SIEM concepts
Portfolio evidence
Cloud security architecture portfolio
Assessment
Capstone defence
Applied portfolio

Projects you will build

2 portfolio projects plus module evidence

Portfolio project 1

Secure Cloud Application Blueprint

Harden IAM, network, data, workloads and CI/CD for a cloud application.

Threat model · IaC/security controls · logging · incident plan
Portfolio project 2

Cloud Compromise Investigation

Investigate a simulated compromised identity/workload and execute response.

Evidence timeline · containment steps · root cause · improvements
Course value

Why this course

Cloud security requires coordinated controls across identity, networks, workloads, data, pipelines, posture management, and incident investigation.

The curriculum progresses from Cloud Security Architecture and Shared Responsibility to Governance, Compliance and Cloud Security Capstone, with guided labs, assessments, and two portfolio projects: Secure Cloud Application Blueprint and Cloud Compromise Investigation.

Course fit

Who this course is for

Cloud, security and DevOps professionals specializing in cloud-security engineering.

AdvancedCybersecurity Engineer
PrerequisitesLearners should understand cloud and cybersecurity fundamentals. Prior exposure to AWS, Azure, or Google Cloud is helpful.
Practical capabilities

What you will be able to do

  • Threat-model a cloud application and identify responsibility/control ownership.
  • Redesign an overprivileged cloud IAM model and implement least-privilege roles in a lab.
  • Design secure network segmentation for a three-tier cloud workload.
  • Implement a secrets and encryption strategy for application/data services.
  • Assess a containerised workload and design preventive/detective controls.
  • Investigate a simulated cloud account compromise and execute a response playbook.
  • Secure an end-to-end cloud application and present architecture, controls, detections and incident plan.
Tools and platforms

Technology you will use in this course

Cloud architecture toolsAWSAzureGCP IAM conceptsCloud networksecurity servicesKMSKey VaultSecret Manager conceptsContainer scanner conceptsKubernetes security controlsTerraformCI/CDCSPMCNAPP concepts
Career relevance

Cybersecurity Engineer

This course supports the development of skills relevant to roles such as Cloud Security Engineer, DevSecOps Engineer, and Cloud Security Analyst. The strongest learner outcome is a portfolio that shows the problem, implementation, testing or evaluation, documentation and a clear explanation of decisions—not a certificate alone.

Course evidence and instruction

Academy advisor

Ranjeet Kumar

Advisor, Brightnest AI Academy · Innovation & Growth Leader

A technologist and data leader with 15+ years of experience applying data, artificial intelligence and machine learning to complex problems, scalable products and business growth.

What our learners say

Learner experience

The SOC project helped me practise alert triage, investigation notes, incident response and the professional reporting expected from analysts.
Arjun MehtaCybersecurity Learner · Security Operations Pathway

Industry and technology ecosystem

MicrosoftAmazon Web ServicesDeloitteTech MahindraTata Consultancy ServicesWipro
Course FAQs

Clear answers before you enrol

Secure cloud identities, networks, data, workloads and delivery pipelines - then investigate and respond to cloud attacks.

Is the Cloud Security Engineering course suitable for beginners?

This is an advanced-level course. Learners should understand cloud and cybersecurity fundamentals. Prior exposure to AWS, Azure, or Google Cloud is helpful.

What will I build during the course?

You will complete guided labs in every module and build two portfolio projects: Secure Cloud Application Blueprint and Cloud Compromise Investigation. Deliverables include working files or code, documentation, testing or evaluation evidence, and a final presentation.

Which tools and platforms are covered?

Key tools include Cloud architecture tools, AWS, Azure, GCP IAM concepts, Cloud network, security services, KMS, and Key Vault. Additional platforms are introduced in relevant modules through practical tasks, and the toolset may evolve as industry practice changes.

How long does the course take?

The course includes approximately 78 guided learning hours across 8 modules, normally delivered over 10–12 weeks depending on batch intensity and learner practice time.

Which career paths can this course support?

The curriculum supports the development of skills relevant to roles such as Cloud Security Engineer, DevSecOps Engineer, and Cloud Security Analyst. Career outcomes depend on prior experience, project quality, interview readiness and market conditions; employment is not guaranteed.

Will I receive mentor and career support?

The course includes live instruction, lab support, assignment feedback, project reviews and career preparation covering portfolio development, resume writing, LinkedIn profile improvement, and interview guidance.

Ready to start?

Ready to start your Cloud Security Engineering journey?

Review the full curriculum, experience a live class and confirm the right starting point before enrolling.

A-56, Sector-64, Noida, Uttar Pradesh – 201301