Cloud Security Engineering Course
Secure cloud identities, networks, data, workloads and delivery pipelines - then investigate and respond to cloud attacks.
Talk to an advisor on WhatsApp
How you will learn
What you will learn, module by module
Secure cloud workloads, identities, networks, data and DevSecOps pipelines. Progress from Cloud Security Architecture and Shared Responsibility to Governance, Compliance and Cloud Security Capstone through guided labs, assessed projects, and portfolio evidence.
01Module 1 · 6 hoursCloud Security Architecture and Shared ResponsibilityThreat-model a cloud application and identify responsibility/control ownership.
- Cloud service models
- Shared responsibility
- Threat modelling
- Landing zones
- Multi-account/subscription/project strategy
- Zero trust principles
- Tools and platforms
- Cloud architecture tools
- Portfolio evidence
- Cloud threat model
- Assessment
- Architecture case
02Module 2 · 10 hoursCloud IAM and Privileged AccessRedesign an overprivileged cloud IAM model and implement least-privilege roles in a lab.
- Cloud identities
- Roles/policies
- Least privilege
- Workload identities
- Federation
- MFA
- Privileged access
- Tools and platforms
- AWS/Azure/GCP IAM concepts
- Portfolio evidence
- Cloud IAM control matrix
- Assessment
- IAM lab
03Module 3 · 8 hoursNetwork and Perimeter SecurityDesign secure network segmentation for a three-tier cloud workload.
- VPC/VNet design
- Segmentation
- Private endpoints
- Security groups/NSGs/firewalls
- WAF
- DDoS concepts
- Egress controls
- Tools and platforms
- Cloud network/security services
- Portfolio evidence
- Secure cloud network diagram
- Assessment
- Network design review
04Module 4 · 8 hoursData, Secrets and Key SecurityImplement a secrets and encryption strategy for application/data services.
- Classification
- Encryption
- KMS/key vaults
- Secrets management
- Rotation
- Storage policies
- Database controls
- Tools and platforms
- KMS/Key Vault/Secret Manager concepts
- Portfolio evidence
- Cloud data protection design
- Assessment
- Data security lab
05Module 5 · 10 hoursWorkload, Container and Serverless SecurityAssess a containerised workload and design preventive/detective controls.
- VM hardening
- Images
- Containers
- Kubernetes security concepts
- Serverless permissions
- Runtime controls
- Supply chain
- Tools and platforms
- Container scanner concepts, Kubernetes security controls
- Portfolio evidence
- Cloud workload hardening plan
- Assessment
- Workload review
06Module 6 · 10 hoursDevSecOps, CSPM and Cloud PostureAdd IaC/container scanning and posture checks to a deployment pipeline.
- IaC scanning
- Policy-as-code
- CI/CD security
- CSPM/CNAPP concepts
- Misconfiguration detection
- Compliance mapping
- Remediation workflows
- Tools and platforms
- Terraform, CI/CD, CSPM/CNAPP concepts
- Portfolio evidence
- Secure cloud deployment pipeline
- Assessment
- DevSecOps lab
07Module 7 · 10 hoursCloud Detection, Incident Response and ForensicsInvestigate a simulated cloud account compromise and execute a response playbook.
- Cloud audit logs
- Identity events
- Workload telemetry
- Detection use cases
- Compromised credentials
- Isolation
- Snapshots
- Tools and platforms
- Cloud audit/monitoring logs, SIEM concepts
- Portfolio evidence
- Cloud incident response report
- Assessment
- Cloud IR practical
08Module 8 · 16 hoursGovernance, Compliance and Cloud Security CapstoneSecure an end-to-end cloud application and present architecture, controls, detections and incident plan.
- Control frameworks
- Policies
- Continuous compliance
- Risk
- Third parties
- Data residency
- Architecture review
- Tools and platforms
- AWS/Azure/GCP security services, IaC, SIEM concepts
- Portfolio evidence
- Cloud security architecture portfolio
- Assessment
- Capstone defence
Projects you will build
2 portfolio projects plus module evidence
Secure Cloud Application Blueprint
Harden IAM, network, data, workloads and CI/CD for a cloud application.
Threat model · IaC/security controls · logging · incident planCloud Compromise Investigation
Investigate a simulated compromised identity/workload and execute response.
Evidence timeline · containment steps · root cause · improvementsWhy this course
Cloud security requires coordinated controls across identity, networks, workloads, data, pipelines, posture management, and incident investigation.
The curriculum progresses from Cloud Security Architecture and Shared Responsibility to Governance, Compliance and Cloud Security Capstone, with guided labs, assessments, and two portfolio projects: Secure Cloud Application Blueprint and Cloud Compromise Investigation.
Who this course is for
Cloud, security and DevOps professionals specializing in cloud-security engineering.
What you will be able to do
- Threat-model a cloud application and identify responsibility/control ownership.
- Redesign an overprivileged cloud IAM model and implement least-privilege roles in a lab.
- Design secure network segmentation for a three-tier cloud workload.
- Implement a secrets and encryption strategy for application/data services.
- Assess a containerised workload and design preventive/detective controls.
- Investigate a simulated cloud account compromise and execute a response playbook.
- Secure an end-to-end cloud application and present architecture, controls, detections and incident plan.
Technology you will use in this course
Cybersecurity Engineer
This course supports the development of skills relevant to roles such as Cloud Security Engineer, DevSecOps Engineer, and Cloud Security Analyst. The strongest learner outcome is a portfolio that shows the problem, implementation, testing or evaluation, documentation and a clear explanation of decisions—not a certificate alone.
Course evidence and instruction
Ranjeet Kumar
Advisor, Brightnest AI Academy · Innovation & Growth LeaderA technologist and data leader with 15+ years of experience applying data, artificial intelligence and machine learning to complex problems, scalable products and business growth.
Learner experience
The SOC project helped me practise alert triage, investigation notes, incident response and the professional reporting expected from analysts.
Industry and technology ecosystem
Clear answers before you enrol
Secure cloud identities, networks, data, workloads and delivery pipelines - then investigate and respond to cloud attacks.
Is the Cloud Security Engineering course suitable for beginners?
This is an advanced-level course. Learners should understand cloud and cybersecurity fundamentals. Prior exposure to AWS, Azure, or Google Cloud is helpful.
What will I build during the course?
You will complete guided labs in every module and build two portfolio projects: Secure Cloud Application Blueprint and Cloud Compromise Investigation. Deliverables include working files or code, documentation, testing or evaluation evidence, and a final presentation.
Which tools and platforms are covered?
Key tools include Cloud architecture tools, AWS, Azure, GCP IAM concepts, Cloud network, security services, KMS, and Key Vault. Additional platforms are introduced in relevant modules through practical tasks, and the toolset may evolve as industry practice changes.
How long does the course take?
The course includes approximately 78 guided learning hours across 8 modules, normally delivered over 10–12 weeks depending on batch intensity and learner practice time.
Which career paths can this course support?
The curriculum supports the development of skills relevant to roles such as Cloud Security Engineer, DevSecOps Engineer, and Cloud Security Analyst. Career outcomes depend on prior experience, project quality, interview readiness and market conditions; employment is not guaranteed.
Will I receive mentor and career support?
The course includes live instruction, lab support, assignment feedback, project reviews and career preparation covering portfolio development, resume writing, LinkedIn profile improvement, and interview guidance.
Ready to start your Cloud Security Engineering journey?
Review the full curriculum, experience a live class and confirm the right starting point before enrolling.
