Cloud
Security
—
Technical
Skills
01
Cloud
platform
security
architecture
AWS
,
Azure
,
GCP
,
landing
zones
,
guardrails
02
Identity
&
access
management
Federation
,
least
privilege
,
secrets
,
PAM
03
Network
,
perimeter
&
Zero
Trust
VPC
design
,
segmentation
,
SASE
,
mTLS
04
Data
protection
&
cryptography
KMS
,
HSM
,
PKI
,
classification
,
DLP
05
Kubernetes
,
container
&
workload
security
Admission
control
,
runtime
,
image
scanning
06
Cloud
security
posture
&
vulnerability
management
CSPM
,
CIEM
,
CNAPP
,
CVE
triage
,
pentesting
07
DevSecOps
&
application
security
SAST
,
DAST
,
IaC
scanning
,
SBOM
,
CI
/
CD
08
Detection
,
monitoring
&
incident
response
SIEM
,
SOAR
,
detection
-
as
-
code
,
forensics
09
Governance
,
risk
&
compliance
NIST
,
ISO
27001,
SOC
2,
PCI
DSS
,
FedRAMP
10
Automation
,
IaC
&
scripting
Terraform
,
Python
,
Go
,
policy
-
as
-
code
11
Threat
modeling
&
secure
design
review
STRIDE
,
attack
paths
,
architecture
review
12
Certifications
&
framework
fluency
CCSP
,
CISSP
,
AWS
Security
,
AZ
-500,
PCSE
SKILLS
BY
DOMAIN
11
domains
· 180+
specific
competencies
01
Cloud
Platforms
&
Security
Architecture
Designing
secure
landing
zones
,
account
structures
,
and
organizational
guardrails
across
hyperscale
and
hybrid
estates
.
AWS
Microsoft
Azure
Google
Cloud
Platform
Oracle
Cloud
Infrastructure
Alibaba
Cloud
Multi
-
cloud
&
hybrid
architecture
AWS
Organizations
&
Control
Tower
Azure
Landing
Zones
&
Management
Groups
GCP
Organization
Policy
&
Folders
Service
Control
Policies
Hub
-
and
-
spoke
network
topology
Well
-
Architected
Security
Pillar
Cloud
migration
security
review
Shared
responsibility
model
1 / 4
02
Identity
,
Access
&
Secrets
Management
Federating
identity
and
enforcing
least
privilege
at
both
human
and
machine
scale
.
IAM
policy
authoring
RBAC
&
ABAC
Least
-
privilege
design
OIDC
OAuth
2.0
SAML
2.0
SCIM
provisioning
MFA
&
FIDO
2
passkeys
Conditional
Access
Privileged
Access
Management
Just
-
in
-
time
access
Workload
identity
federation
HashiCorp
Vault
AWS
Secrets
Manager
Azure
Key
Vault
Secrets
rotation
automation
Entitlement
reviews
&
recertification
Cross
-
account
role
assumption
03
Network
,
Perimeter
&
Zero
Trust
Segmenting
cloud
networks
and
shifting
perimeter
controls
toward
identity
-
aware
access
.
VPC
/
VNet
design
Security
groups
&
NACLs
AWS
Network
Firewall
Azure
Firewall
Next
-
generation
firewalls
(
Palo
Alto
,
Fortinet
)
Web
Application
Firewall
DDoS
mitigation
(
Cloudflare
,
AWS
Shield
)
Zero
Trust
Network
Access
SASE
&
SSE
CASB
mTLS
TLS
1.3 &
cipher
suites
IPsec
VPN
&
Direct
Connect
/
ExpressRoute
PrivateLink
&
private
endpoints
DNS
security
&
DNSSEC
Microsegmentation
(
Illumio
,
Guardicore
)
04
Data
Protection
&
Cryptography
Protecting
data
at
rest
,
in
transit
,
and
in
use
with
managed
key
infrastructure
and
classification
controls
.
AWS
KMS
Azure
Key
Vault
HSM
Cloud
HSM
Envelope
encryption
Customer
-
managed
keys
Key
rotation
&
crypto
agility
PKI
&
certificate
lifecycle
management
ACME
certificate
automation
Data
classification
&
tagging
Data
Loss
Prevention
Tokenization
&
format
-
preserving
encryption
Confidential
computing
Data
residency
&
sovereignty
controls
Backup
encryption
&
immutability
Secure
data
sharing
&
masking
05
Kubernetes
,
Container
&
Workload
Security
Hardening
orchestration
platforms
and
runtime
workloads
against
escape
,
lateral
movement
,
and
supply
-
chain
compromise
.
Kubernetes
RBAC
Pod
Security
Standards
Admission
control
OPA
Gatekeeper
Kyverno
Runtime
threat
detection
(
Falco
,
Aqua
,
Sysdig
)
Image
scanning
(
Trivy
,
Grype
,
Snyk
)
Registry
&
artifact
hardening
Service
mesh
mTLS
(
Istio
,
Linkerd
)
Container
sandboxing
(
gVisor
,
Kata
)
Serverless
&
Lambda
security
VM
&
OS
hardening
CIS
Benchmarks
Immutable
infrastructure
Node
pool
isolation
2 / 4
06
Cloud
Security
Posture
&
Vulnerability
Management
Continuously
measuring
misconfiguration
,
exposure
,
and
exploitable
paths
across
cloud
estates
.
CSPM
CWPP
CIEM
CNAPP
Attack
path
analysis
Agentless
&
agent
-
based
scanning
Drift
&
misconfiguration
detection
Wiz
Prisma
Cloud
Orca
Security
AWS
Security
Hub
Microsoft
Defender
for
Cloud
Tenable
&
Nessus
Qualys
Rapid
7
CVE
/
CVSS
/
EPSS
triage
External
attack
surface
management
Cloud
penetration
testing
Red
team
&
purple
team
exercises
07
DevSecOps
&
Application
Security
Embedding
security
controls
into
build
pipelines
and
verifying
software
provenance
end
to
end
.
SAST
DAST
IAST
Software
composition
analysis
IaC
scanning
(
Checkov
,
tfsec
,
KICS
)
Secret
scanning
(
Gitleaks
,
TruffleHog
)
SBOM
generation
(
CycloneDX
,
SPDX
)
SLSA
supply
-
chain
levels
Artifact
signing
(
Sigstore
,
Cosign
)
CI
/
CD
pipeline
hardening
GitHub
Actions
&
GitLab
CI
security
OWASP
Top
10
OWASP
API
Security
Top
10
API
gateway
authentication
Secure
code
review
Threat
modeling
in
design
reviews
08
Detection
,
Monitoring
&
Incident
Response
Building
telemetry
pipelines
,
high
-
fidelity
detections
,
and
rehearsed
response
procedures
for
cloud
-
native
incidents
.
SIEM
engineering
(
Splunk
,
Sentinel
,
Elastic
)
SOAR
playbook
automation
Detection
-
as
-
code
Sigma
rules
AWS
GuardDuty
&
CloudTrail
Microsoft
Defender
XDR
Google
Security
Command
Center
Cloud
log
pipelines
&
retention
MITRE
ATT
&
CK
for
Cloud
Threat
hunting
Digital
forensics
&
evidence
handling
Containment
&
eradication
Credential
revocation
&
key
rotation
drill
Post
-
incident
review
Tabletop
&
game
-
day
exercises
09
Governance
,
Risk
&
Compliance
Mapping
controls
to
regulatory
and
industry
frameworks
and
producing
audit
-
ready
evidence
at
scale
.
NIST
Cybersecurity
Framework
NIST
SP
800-53 & 800-171
ISO
/
IEC
27001
SOC
2
Type
II
PCI
DSS
4.0
HIPAA
GDPR
FedRAMP
CIS
Benchmarks
CSA
Cloud
Controls
Matrix
SOX
ITGC
controls
Policy
-
as
-
code
Control
mapping
&
evidence
automation
Third
-
party
&
supply
-
chain
risk
Audit
readiness
&
walkthroughs
3 / 4
10
Automation
,
Infrastructure
as
Code
&
Scripting
Encoding
guardrails
and
remediation
as
versioned
,
testable
code
rather
than
manual
process
.
Terraform
AWS
CloudFormation
Pulumi
Ansible
Python
Go
Bash
PowerShell
Boto
3 &
AWS
SDK
Azure
SDK
&
PowerShell
modules
Rego
(
Open
Policy
Agent
)
Chef
InSpec
Serverless
security
automation
SOAR
&
ChatOps
integration
REST
API
integration
11
Certifications
&
Framework
Fluency
Recognized
credentials
that
validate
the
depth
of
the
skills
listed
above
.
CCSP
CISSP
AWS
Certified
Security
–
Specialty
Microsoft
Certified
:
Azure
Security
Engineer
(
AZ
-500)
Google
Professional
Cloud
Security
Engineer
CompTIA
Security
+
CCSK
CISM
HashiCorp
Certified
:
Vault
Associate
GIAC
GCLD
/
GPCS
4 / 4