Study tracks
Cloud Security Engineer Track
Cloud security engineer is one of the largest security job categories, and most employers run more than one cloud plus dozens of SaaS apps. This track covers what transfers across AWS, Azure and GCP (identity first, guardrails, logging, incident response) and the platform-specific details interviewers probe. For a single-vendor exam, use the AWS Security Specialty or CCSP tracks.
2 min read
6 sections
verified 2026-10
Opens each topic in order with a Next button at the bottom of the screen.
Last verified2026-10
Getting certified
Last verified2026-10
AWS Certified Security – Specialty
Details are in the AWS track.
CCSP
Vendor-neutral; details are in the CCSP track.
Microsoft Azure and Google Cloud
Both offer cloud security engineer certifications. Exam codes and content change often, so check Microsoft Learn and Google Cloud's certification pages for the current version before you book.
Part 1 — Identity, the real perimeter
- AWS IAM: how a request is evaluated
- AWS privilege escalation paths and PassRole
- Entra roles vs Azure RBAC — two permission systems
- Conditional Access and PIM
- GCP IAM and dangerous patterns
- Workload identities — managed identities, instance roles, workload identity federation
Part 2 — Guardrails and posture
- AWS landing zone, SCPs and RCPs
- GCP organisation policies and VPC Service Controls
- Network edge and compute
- Data protection and keys
- SaaS posture — the tenant settings no cloud scanner sees
- Vulnerability prioritisation
Part 3 — Kubernetes and pipelines
- Kubernetes security — RBAC, pod security, network policy, service mesh
- OWASP CI/CD Top 10 — pipelines hold the keys to production
- GitHub security — OIDC to the cloud instead of stored keys