Cloud Security

Wishlist Share
Share Course
Page Link
Share On Social Media

About Course

This hands-on course provides a comprehensive dive into securing cloud environments on Amazon Web Services (AWS). Designed for engineers, security professionals, and cloud practitioners, the course covers everything from foundational AWS security principles to advanced threat detection, compliance automation, and real-world incident response strategies.

You’ll gain practical skills in identity and access management (IAM), network security, encryption, logging, monitoring, and cloud-native security services such as AWS Security Hub, GuardDuty, Config, CloudTrail, Macie, and Inspector. The course also explores modern practices like Infrastructure as Code (IaC) security using Terraform and DevSecOps pipeline integration.

Whether you’re looking to implement security guardrails, pass an audit, or respond to live cloud threats, this course will equip you with the tools and techniques to build and maintain a secure AWS environment.

By the end of the course, you will be able to:

  • Design and implement secure AWS architectures aligned with the AWS Well-Architected Framework.

  • Configure and enforce IAM policies, least privilege, and MFA.

  • Use AWS-native tools for threat detection, logging, and compliance (e.g., GuardDuty, Security Hub, Config, CloudTrail).

  • Apply encryption best practices for data at rest and in transit.

  • Automate security checks and remediation using Terraform and Lambda.

  • Integrate cloud security into CI/CD pipelines (DevSecOps).

  • Align cloud configurations with compliance frameworks like NIST 800-53, PCI DSS, SOC 2, and CIS Benchmarks.

  • Build real-time alerting and incident response workflows using CloudWatch, EventBridge, and third-party tools.

Who Should Enroll:

  • Cloud Security Engineers

  • DevOps and Site Reliability Engineers (SREs)

  • IT and Security Analysts

  • Professionals preparing for the AWS Certified Security – Specialty exam

  • Anyone looking to strengthen their AWS security posture

Show More

What Will You Learn?

  • How to architect secure workloads in AWS using the Well-Architected Framework
  • Best practices for IAM, roles, policies, and MFA enforcement
  • Implementing network security: VPC, Security Groups, NACLs, and VPNs
  • Logging, monitoring, and alerting using CloudTrail, Config, GuardDuty, and Security Hub
  • Data protection using encryption with KMS and S3 bucket policies
  • Automating security guardrails using Terraform and AWS Config Rules
  • Integrating DevSecOps practices into CI/CD pipelines
  • Achieving compliance with NIST 800-53, PCI DSS, SOC 2, and CIS Benchmarks
  • Responding to cloud incidents using AWS-native tools and log analysis
  • Preparing for AWS Certified Security – Specialty exam (optional focus)

Course Content

Course Orientation + Introduction to Cloud Security

AWS Core Services + Core AWS Security Services (IAM, KMS, GuardDuty, CloudTrail, WAF, Config, Security Hub)

AWS CLI, Console, and Organizations (Landing Zones)

Secure VPC Design + Subnets, Security Groups

Network ACLs, Route Tables, and Zero Trust Concepts

AWS KMS & Encryption Across Services (S3, RDS, EBS)

Secrets Management: AWS Secrets Manager & Vault

Monitoring & Logging: CloudTrail, CloudWatch, GuardDuty

CSPM Tools: Wiz, Orca, Wazuh + AWS Inspector & Macie

Disaster Recovery & Business Continuity in AWS

Infrastructure as Code Security: Terraform, tfsec, Checkov

DevSecOps Pipelines (GitHub Actions, CodePipeline) + Secrets Scanning

SAST & DAST: SonarQube, ZAP, OWASP Top 10

Container & Kubernetes Security: Trivy, Sysdig, Admission Control

Runtime Security + Threat Detection (Falco, Sysdig)

Threat Modeling: STRIDE, DREAD, MITRE ATT&CK

Intro to Penetration Testing & Cloud Exploits

Governance, Risk, and Compliance (GRC) in Cloud

Audit & Continuous Compliance with AWS Config

AI/ML Security: Model Poisoning, SageMaker Hardening

SBOM, SLSA, and Software Supply Chain Security

Privacy & Data Residency Laws (GDPR, HIPAA, CCPA)

Review & Practice: Secure Cloud Architecture Walkthrough

Capstone Project Launch + Team Assignment

Capstone Build: Secure App w/ IaC + DevSecOps + Monitoring

Capstone Build: Logging, Alerting, and Threat Modeling

Capstone Finalization: Pen Testing + Compliance Mapping

Capstone Presentations & Peer Reviews

Final Q&A + Feedback Session + Certification Guidance

Make-up Session / Open Lab / Guest Speaker (Optional)

Graduation & Closing Ceremony

Student Ratings & Reviews

No Review Yet
No Review Yet