School of Cybersecurity · Advanced

Cloud Security Engineering Course

Secure cloud identities, networks, data, workloads and delivery pipelines — then investigate and respond to cloud attacks.

Talk to an adviser on WhatsApp
Cloud Security Engineering course illustration at Brightnest AI Academy
Cloud Security Architecture and Shared ResponsibilityCloud IAM and Privileged AccessNetwork and Perimeter SecurityData, Secrets and Key Security
Cloud architecture toolsAWSAzureGCP IAM conceptsCloud network/security services
Duration10–12 weeks78 hours
Batch startsConfirm with admissionsEnquiries open
Learning formatLive mentor-led learningConfirm with admissions
Curriculum8 modulesLabs and assessed capstone
Portfolio2 projectsPlus module evidence
LevelAdvancedCourse level
PathwayCybersecurity EngineerRelated career pathway

How you will learn

Live instructor-led sessions that connect concepts to real workplace decisions.
Guided labs and workshops in every module.
Assignments, checkpoints and practical feedback.
Portfolio documentation, demonstrations and capstone review.
Access to recordings and LMS resources according to the published batch policy.
Career preparation based on completed work and target roles.
Course curriculum

What you will learn, module by module

Secure cloud workloads, identities, networks, data and DevSecOps pipelines. Progress from Cloud Security Architecture and Shared Responsibility to Governance, Compliance and Cloud Security Capstone through guided labs, assessed projects, and portfolio evidence.

01Module 1 · 6 hoursCloud Security Architecture and Shared ResponsibilityThreat-model a cloud application and identify responsibility/control ownership.
Topics you will cover
  • Cloud service models
  • Shared responsibility
  • Threat modeling
  • Landing zones
  • Multi-account/subscription/project strategy
  • Zero trust principles
Tools and platforms
Cloud architecture tools
Portfolio evidence
Cloud threat model
Assessment
Architecture case
02Module 2 · 10 hoursCloud IAM and Privileged AccessRedesign an overprivileged cloud IAM model and implement least-privilege roles in a lab.
Topics you will cover
  • Cloud identities
  • Roles/policies
  • Least privilege
  • Workload identities
  • Federation
  • MFA
  • Privileged access
  • Service accounts
  • Keyless patterns
Tools and platforms
AWS/Azure/GCP IAM concepts
Portfolio evidence
Cloud IAM control matrix
Assessment
IAM lab
03Module 3 · 8 hoursNetwork and Perimeter SecurityDesign secure network segmentation for a three-tier cloud workload.
Topics you will cover
  • VPC/VNet design
  • Segmentation
  • Private endpoints
  • Security groups/NSGs/firewalls
  • WAF
  • DDoS concepts
  • Egress controls
  • Service-to-service security
Tools and platforms
Cloud network/security services
Portfolio evidence
Secure cloud network diagram
Assessment
Network design review
04Module 4 · 8 hoursData, Secrets and Key SecurityImplement a secrets and encryption strategy for application/data services.
Topics you will cover
  • Classification
  • Encryption
  • KMS/key vaults
  • Secrets management
  • Rotation
  • Storage policies
  • Database controls
  • Tokenisation concepts
  • Backup protection
Tools and platforms
KMS/Key Vault/Secret Manager concepts
Portfolio evidence
Cloud data protection design
Assessment
Data security lab
05Module 5 · 10 hoursWorkload, Container and Serverless SecurityAssess a containerised workload and design preventive/detective controls.
Topics you will cover
  • VM hardening
  • Images
  • Containers
  • Kubernetes security concepts
  • Serverless permissions
  • Runtime controls
  • Supply chain
  • Vulnerability management
Tools and platforms
Container scanner concepts, Kubernetes security controls
Portfolio evidence
Cloud workload hardening plan
Assessment
Workload review
06Module 6 · 10 hoursDevSecOps, CSPM and Cloud PostureAdd IaC/container scanning and posture checks to a deployment pipeline.
Topics you will cover
  • IaC scanning
  • Policy-as-code
  • CI/CD security
  • CSPM/CNAPP concepts
  • Misconfiguration detection
  • Compliance mapping
  • Remediation workflows
Tools and platforms
Terraform, CI/CD, CSPM/CNAPP concepts
Portfolio evidence
Secure cloud deployment pipeline
Assessment
DevSecOps lab
07Module 7 · 10 hoursCloud Detection, Incident Response and ForensicsInvestigate a simulated cloud account compromise and execute a response playbook.
Topics you will cover
  • Cloud audit logs
  • Identity events
  • Workload telemetry
  • Detection use cases
  • Compromised credentials
  • Isolation
  • Snapshots
  • Evidence
  • Recovery
Tools and platforms
Cloud audit/monitoring logs, SIEM concepts
Portfolio evidence
Cloud incident response report
Assessment
Cloud IR practical
08Module 8 · 16 hoursGovernance, Compliance and Cloud Security CapstoneSecure an end-to-end cloud application and present architecture, controls, detections and incident plan.
Topics you will cover
  • Control frameworks
  • Policies
  • Continuous compliance
  • Risk
  • Third parties
  • Data residency
  • Architecture review
  • Cost/security balance
  • Executive communication
Tools and platforms
AWS/Azure/GCP security services, IaC, SIEM concepts
Portfolio evidence
Cloud security architecture portfolio
Assessment
Capstone defence
Applied portfolio

Projects you will build

2 portfolio projects plus module evidence

Portfolio project 1

Secure Cloud Application Blueprint

Harden IAM, network, data, workloads and CI/CD for a cloud application.

Threat model · IaC/security controls · Logging · Incident plan
Portfolio project 2

Cloud Compromise Investigation

Investigate a simulated compromise of an identity or workload and carry out the response.

Evidence timeline · Containment steps · Root cause · Improvements
Course value

Why this course

Cloud security requires coordinated controls across identity, networks, workloads, data, pipelines, posture management, and incident investigation.

The curriculum progresses from Cloud Security Architecture and Shared Responsibility to Governance, Compliance and Cloud Security Capstone, with guided labs, assessments, and two portfolio projects: Secure Cloud Application Blueprint and Cloud Compromise Investigation.

Course fit

Who this course is for

Cloud, security and DevOps professionals specialising in cloud-security engineering.

AdvancedCybersecurity Engineer
PrerequisitesLearners should understand cloud and cybersecurity fundamentals. Prior exposure to AWS, Azure, or Google Cloud is helpful.
Practical capabilities

What you will be able to do

  • Threat-model a cloud application and identify responsibility/control ownership.
  • Redesign an overprivileged cloud IAM model and implement least-privilege roles in a lab.
  • Design secure network segmentation for a three-tier cloud workload.
  • Implement a secrets and encryption strategy for application/data services.
  • Assess a containerised workload and design preventive/detective controls.
  • Investigate a simulated cloud account compromise and execute a response playbook.
  • Secure an end-to-end cloud application and present architecture, controls, detections and incident plan.
Tools and platforms

Technology you will use in this course

Cloud architecture toolsAWSAzureGCP IAM conceptsCloud network/security servicesKMSKey VaultSecret Manager conceptsContainer scanner conceptsKubernetes security controlsTerraformCI/CDCSPMCNAPP concepts
Career relevance

Cybersecurity Engineer

This course supports the development of skills relevant to roles such as Cloud Security Engineer, DevSecOps Engineer, and Cloud Security Analyst. The strongest learner outcome is a portfolio that shows the problem, implementation, testing or evaluation, documentation and a clear explanation of decisions—not a certificate alone.

Course evidence and instruction

Course guidance

Discuss your learning pathway

Review prerequisites, learning format and project expectations with admissions before enrolment.

Get course guidance
Project evidence

Explore the course projects

Review the project briefs and deliverables to understand the work expected during the course.

Review project expectations

Technology references

Technology names identify learning tools and do not imply an employer partnership or endorsement.

MicrosoftAmazon Web ServicesDeloitteTech MahindraTata Consultancy ServicesWipro
Course FAQs

Clear answers before you enrol

Is the Cloud Security Engineering course suitable for beginners?

This is an advanced-level course. Learners should understand cloud and cybersecurity fundamentals. Prior exposure to AWS, Azure, or Google Cloud is helpful.

What will I build during the course?

You will complete guided labs in every module and build two portfolio projects: Secure Cloud Application Blueprint and Cloud Compromise Investigation. Deliverables include working files or code, documentation, testing or evaluation evidence, and a final presentation.

Which tools and platforms are covered?

Key tools include Cloud architecture tools, AWS, Azure, GCP IAM concepts, Cloud network, security services, KMS, and Key Vault. Additional platforms are introduced in relevant modules through practical tasks, and the toolset may evolve as industry practice changes.

How long does the course take?

The course includes approximately 78 guided learning hours across 8 modules, normally delivered over 10–12 weeks depending on batch intensity and learner practice time.

Which career paths can this course support?

The curriculum supports the development of skills relevant to roles such as Cloud Security Engineer, DevSecOps Engineer, and Cloud Security Analyst. Career outcomes depend on prior experience, project quality, interview readiness and market conditions; employment is not guaranteed.

Will I receive mentor and career support?

The course includes live instruction, lab support, assignment feedback, project reviews and career preparation covering portfolio development, CV writing, LinkedIn profile improvement, and interview guidance.

Ready to start?

Ready to start your Cloud Security Engineering journey?

Review the full curriculum, experience a live class and confirm the right starting point before enrolling.

A-56, Sector-64, Noida, Uttar Pradesh – 201301