Cloud Security Engineering
Security in cloud environments is different
On-premise security thinking does not map cleanly to cloud. Perimeters are fuzzy, identities replace network boundaries as the primary control point, and misconfigurations in a web console can expose data within seconds. This course addresses those differences directly rather than applying traditional security frameworks onto cloud infrastructure.
Coverage across two major platforms
Examples and labs span both AWS and Azure because most organizations use at least one of them, and the concepts transfer even where the services have different names. You will configure IAM policies with least-privilege principles, set up network segmentation with security groups and NSGs, enable logging and alerting, and work through a simulated incident involving a misconfigured storage bucket.
Who this is designed for
Security engineers moving into cloud roles, cloud engineers who want to take ownership of security rather than delegating it entirely, and DevOps practitioners working in regulated industries will find the material relevant. Some prior cloud experience is expected, roughly equivalent to an associate-level certification or six months of hands-on work.
Instructor Daryna Kovalchuk spent four years on a cloud security team before building this course. The labs reflect real misconfiguration patterns she encountered during that work.
— Cloud infrastructure decisions made without understanding the fundamentals tend to cost far more than the course itself.
Security in cloud environments is different
On-premise security thinking does not map cleanly to cloud. Perimeters are fuzzy, identities replace network boundaries as the primary control point, and misconfigurations in a web console can expose data within seconds. This course addresses those differences directly rather than applying traditional security frameworks onto cloud infrastructure.
Coverage across two major platforms
Examples and labs span both AWS and Azure because most organizations use at least one of them, and the concepts transfer even where the services have different names. You will configure IAM policies with least-privilege principles, set up network segmentation with security groups and NSGs, enable logging and alerting, and work through a simulated incident involving a misconfigured storage bucket.
Who this is designed for
Security engineers moving into cloud roles, cloud engineers who want to take ownership of security rather than delegating it entirely, and DevOps practitioners working in regulated industries will find the material relevant. Some prior cloud experience is expected, roughly equivalent to an associate-level certification or six months of hands-on work.
Instructor Daryna Kovalchuk spent four years on a cloud security team before building this course. The labs reflect real misconfiguration patterns she encountered during that work.
Program
Learning path
- Week 1-2 - Identity and access: IAM deep dive, role federation, service accounts, privilege escalation paths
- Week 3 - Network security: VPC/VNet design, security groups, NACLs, private endpoints, firewall rules
- Week 4 - Data protection: encryption key management, KMS vs customer-managed keys, S3 and Blob storage policies
- Week 5 - Logging and detection: CloudTrail, Azure Monitor, GuardDuty, Defender for Cloud, alert configuration
- Week 6 - Vulnerability and compliance: cloud security posture management tools, CIS benchmarks, automated remediation
- Week 7 - Incident response: simulated breach scenario, evidence collection, containment steps, post-incident review
- Week 8 - Capstone: security review of a provided architecture with written findings report
Each week includes a lab exercise using real cloud accounts with guided teardown instructions to avoid unexpected charges.
Duration
8 weeks
Cloud SecurityInvestment
One-time payment, certificate upon completion
9200 UAH