Pillar A: CybersecurityA5

Cloud Security

AWS/Azure/GCP security controls, IAM policies, CSPM, container security, shared responsibility model.

Part of Pillar A: Cybersecurity · Cybersecurity groups the disciplines that share methods, tools, and threat models with Cloud Security.

What is Cloud Security?

Cloud security is the discipline of protecting data, applications, and infrastructure hosted in cloud environments — whether public (AWS, Azure, GCP), private, or hybrid. As organizations migrate critical workloads to the cloud, the attack surface shifts from on-premises networks to cloud control planes, identity systems, storage buckets, and API endpoints. Misconfigurations — not sophisticated exploits — remain the leading cause of cloud breaches.

The shared responsibility model is the foundational concept: cloud providers secure the infrastructure (physical data centers, hypervisors, network fabric), while customers are responsible for securing their configurations, data, identity, and applications. This boundary varies by service model — IaaS customers manage more than PaaS or SaaS customers — and misunderstanding the boundary is a primary source of security failures.

Cloud Security Posture Management (CSPM) tools continuously scan cloud environments for misconfigurations and compliance violations. Cloud Workload Protection Platforms (CWPP) secure containers, serverless functions, and virtual machines. Cloud Infrastructure Entitlement Management (CIEM) addresses the identity explosion in cloud environments where overprivileged service accounts and roles create massive lateral movement opportunities. Kubernetes security, infrastructure as code scanning, and cloud-native application protection platforms (CNAPP) represent the cutting edge of the field.

Why it matters

The cloud is now the default deployment target for most organizations. A single misconfigured S3 bucket or overprivileged IAM role can expose millions of records. Cloud security skills are no longer optional for any security professional.

Cloud security extends every traditional security domain — network, identity, application, and data security — into cloud-native architectures. It requires understanding both the provider's controls and the customer's responsibilities.

Key topics

Shared responsibility model (IaaS, PaaS, SaaS)
Cloud IAM (AWS IAM, Azure AD/Entra ID, GCP IAM)
Cloud Security Posture Management (CSPM)
Cloud Workload Protection Platforms (CWPP)
Container security (Docker, Kubernetes, image scanning)
Infrastructure as Code (IaC) security scanning
Cloud-native application protection (CNAPP)
Serverless security (Lambda, Functions, Cloud Run)
Cloud logging and monitoring (CloudTrail, Azure Monitor)
Storage security (S3 policies, encryption, access logging)
Multi-cloud security strategy

People shaping this field

Researchers and practitioners worth following in this space.

Cloud security architect, AWS security open-source contributor

Cloud security researcher, creator of flaws.cloud

Cloud security practitioner and writer on pragmatic security

Curated resources

Authoritative sources we ground Cloud Security questions in — frameworks, research, guides, and tools.

Roles where this matters

Career paths where this domain shows up as core or recommended.

🔍Penetration TesterRecommended

Ethically hack systems to find vulnerabilities before attackers do. Offensive security requires deep technical knowledge.

🏗Security EngineerCore

Design, build, and maintain security infrastructure. The architects of an organization's defensive posture.

Cloud Security EngineerCore

Secure cloud infrastructure across AWS, Azure, and GCP. Specialize in the shared responsibility model and cloud-native controls.

💻AppSec / DevSecOps EngineerRecommended

Embed security into the software development lifecycle. Shift left to catch vulnerabilities before they reach production.

👑CISO / Security LeaderRecommended

Lead security strategy, communicate risk to the board, and build security programs. Executive-level cybersecurity leadership.

🗝IAM / Identity EngineerRecommended

Design and operate the identity fabric that every other control inherits. Federated identity, MFA/passkeys, PAM, identity governance, and the policy glue between them.

Cloud Detection / SecOps EngineerCore

A hybrid role growing out of the realisation that SOCs need engineers who understand cloud-native telemetry, IAM-first threat models, and how to instrument AWS/Azure/GCP for detection.

🏛Security ArchitectCore

Senior design role — defines how pillar A components fit together across identity, crypto, network, cloud, and data — and, increasingly, how pillar C bolts into it.

🐛Vulnerability Management LeadRecommended

Owns the end-to-end find → prioritize → fix → verify loop at scale, now increasingly AI-driven.

🖥ML Platform Security EngineerCore

Secures the platform that trains, stores, and serves ML models — multi-tenant GPU isolation, pipeline integrity, feature-store hygiene, secrets management in ML workflows.

🌐Threat Exposure Management / Attack Surface AnalystCore

External-first role: inventories what an attacker can see, tracks what's new, and drives closure through the org. The outside-in counterpart to vuln management.

📦Product Security EngineerRecommended

Embedded in a product team — owns threat modelling, secure design, libraries, dependency risk, and increasingly the AI-specific hardening of LLM features the product ships.

Certifications that signal this domain

Credentials whose blueprint meaningfully covers this domain. Core means centrally covered; also touched means present in the blueprint but not the primary focus.

Core coverage

AWS CPProfessional·AWSOfficial page →

Amazon Web Services Certified Cloud Practitioner

Amazon Web Services Certified Cloud Practitioner

AWS CSSProfessional·AWSOfficial page →

Amazon Web Services Certified Security - Specialty

The AWS Security Specialty is AWS's most demanding security certification and requires solid practical experience with AWS workloads. It covers a broad spectrum: from IAM and data encryption to incident response, logging, and compliance. The practical relevance is high; pure textbook candidates typically fail. The certification has high market value potential, as it is regarded as proof of quality for security architects in cloud environments. Important: Version SCS-C02 was superseded in December 2025; SCS-C03 is now current.

AWS SAAAssociate·AWSOfficial page →

Amazon Web Services Certified Solutions Architect - Associate

Amazon Web Services Certified Solutions Architect - Associate

AWS SAPProfessional·AWSOfficial page →

Amazon Web Services Certified Solutions Architect - Professional

Amazon Web Services Certified Solutions Architect - Professional

AWS Security SpecialtyProfessional·Amazon Web ServicesOfficial page →

AWS Certified Security — Specialty (SCS-C02)

Deep AWS security: IAM, data protection, detection, incident response within AWS primitives.

AZ-104Associate·MicrosoftOfficial page →

Microsoft Azure Administrator Associate

Microsoft Azure Administrator Associate

AZ-305Expert·MicrosoftOfficial page →

Microsoft Azure Solutions Architect Expert

Microsoft Azure Solutions Architect Expert

AZ-500Associate·MicrosoftOfficial page →

Microsoft Certified: Azure Security Engineer Associate

Azure-native security engineering: Entra ID, network controls, Defender, Sentinel.

AZ-900Associate·MicrosoftOfficial page →

Microsoft Azure Fundamentals

Microsoft Azure Fundamentals

C)CSOProfessional·Mile2Official page →

Mile2 Certified Cloud Security Officer

Mile2 Certified Cloud Security Officer

CASP+Expert·CompTIAOfficial page →

CompTIA Advanced Security Practitioner+

CompTIA's SecurityX (formerly CASP+, current exam code CAS-005) is one of the few vendor-neutral advanced certifications for technical security experts without management focus. It deliberately positions itself as a technical alternative to CISSP and is recognized by DoD and US government agencies as an 8570-compliant credential, which is a real advantage in government environments. In the private sector, market perception is mixed: CISSP clearly dominates job postings, but SecurityX provides a credible signal for technically deep skills. The pass/fail format without score disclosure is unusual and criticized by some as lacking transparency. Performance-based questions increase the practical rigor.

CCPenX-AWSExpert·AWSOfficial page →

The SecurityOps Group Certified Cloud Pentesting eXpert-AWS

The SecurityOps Group Certified Cloud Pentesting eXpert-AWS

CCSPProfessional·ISC2Official page →

Certified Cloud Security Professional

Cloud security architecture: shared responsibility, identity, data protection, crypto, and cloud-native detection.

CISSP-ISSAPExpert·ISC2Official page →

CISSP Information Systems Security Architecture Professional

Architecture concentration on top of CISSP — trust boundaries, identity / crypto / network composition, defense-in-depth design.

CKAAssociate·Cloud Native Computing FoundationOfficial page →

Cloud Native Computing Foundation Certified Kubernetes Administrator

Cloud Native Computing Foundation Certified Kubernetes Administrator

CKADAssociate·Cloud Native Computing FoundationOfficial page →

Cloud Native Computing Foundation Certified Kubernetes Application Developer

Cloud Native Computing Foundation Certified Kubernetes Application Developer

CKSAssociate·Cloud Native Computing FoundationOfficial page →

Cloud Native Computing Foundation Certified Kubernetes Security Specialist

Cloud Native Computing Foundation Certified Kubernetes Security Specialist

Cloud EssntAssociate·CompTIAOfficial page →

CompTIA Cloud Essentials

CompTIA Cloud Essentials

Cloud+Professional·CompTIAOfficial page →

CompTIA Cloud+

CompTIA Cloud+

CSA CCSKProfessional·Cloud Security AllianceOfficial page →

Cloud Security Alliance Certificate of Cloud Security Knowledge

The CCSK from the Cloud Security Alliance is one of the most widespread vendor-neutral cloud security certifications worldwide. It is based on three core sources: the CSA Security Guidance v4, the ENISA Cloud Computing Risk Assessment, and the CSA Cloud Controls Matrix (CCM). The exam is fully online and open-book — this lowers the entry barrier but also means less practical proof than e.g. CCSP. No professional experience required, no expiration date. Good as an entry point into cloud security and as preparation for the CCSP, but not a strong career building block on its own.

CSA CGCProfessional·Cloud Security AllianceOfficial page →

Cloud Security Alliance Cloud Governance & Compliance

Cloud Security Alliance Cloud Governance & Compliance

EXIN PCAProfessional·EXINOfficial page →

EXIN Professional Cloud Administrator

EXIN Professional Cloud Administrator

EXIN PCDProfessional·EXINOfficial page →

EXIN Professional Cloud Developer

EXIN Professional Cloud Developer

EXIN PCSAProfessional·EXINOfficial page →

EXIN Professional Cloud Solution Architect

EXIN Professional Cloud Solution Architect

EXIN PCSerMProfessional·EXINOfficial page →

EXIN Professional Cloud Service Manager

EXIN Professional Cloud Service Manager

EXIN PCSMProfessional·EXINOfficial page →

EXIN Professional Cloud Security Manager

EXIN Professional Cloud Security Manager

FCP PCSProfessional·FortinetOfficial page →

Fortinet Certified Professional - Public Cloud Security

Fortinet Certified Professional - Public Cloud Security

GCFRProfessional·GIACOfficial page →

GIAC Cloud Forensics Responder

GIAC Cloud Forensics Responder

GCLDAssociate·GIACOfficial page →

GIAC Cloud Security Essentials

GIAC Cloud Security Essentials

GCP Professional Cloud Security EngineerProfessional·Google CloudOfficial page →

Google Cloud Certified — Professional Cloud Security Engineer

GCP-specific security engineering: identity, VPC SC, secrets, logging, compliance.

GCPNProfessional·GIACOfficial page →

GIAC Cloud Penetration Tester

GIAC Cloud Penetration Tester

GCSAProfessional·GIAC / SANSOfficial page →

GIAC Cloud Security Automation

Security-as-code: IaC hardening, CI/CD guardrails, automated cloud response.

Google ACEAssociate·GoogleOfficial page →

Google Associate Cloud Engineer

Google Associate Cloud Engineer

Google PCSAProfessional·GoogleOfficial page →

Google Professional Cloud Architect

Google Professional Cloud Architect

Google PCSEProfessional·GoogleOfficial page →

Google Professional Cloud Security Engineer

Google Professional Cloud Security Engineer

GPCSProfessional·GIACOfficial page →

GIAC Public Cloud Security

GIAC Public Cloud Security

KCNAAssociate·Cloud Native Computing FoundationOfficial page →

Cloud Native Computing Foundation Kubernetes and Cloud Native Associate

Cloud Native Computing Foundation Kubernetes and Cloud Native Associate

MS-100Expert·MicrosoftOfficial page →

Microsoft 365 Certified Enterprise Administrator Expert

Microsoft 365 Certified Enterprise Administrator Expert

SC-100Professional·MicrosoftOfficial page →

Microsoft Cybersecurity Architect

The Microsoft Certified: Cybersecurity Architect Expert (SC-100) is Microsoft's highest security certification and targets experienced professionals who design security architectures for hybrid and cloud-native environments based on the Microsoft platform. It requires at least one associate-level security certification (e.g., AZ-500, SC-200, or SC-300) and builds on that knowledge. The certification addresses zero-trust architectures, compliance requirements, identity governance, and infrastructure protection from a strategic perspective. For organizations heavily invested in Microsoft 365 and Azure, SC-100 is valuable proof of expertise; outside the Microsoft ecosystem, its relevance is more limited. The exam will be updated in April 2026.

SC-900Associate·MicrosoftOfficial page →

Microsoft Certified: Security, Compliance, and Identity Fundamentals

Microsoft Certified: Security, Compliance, and Identity Fundamentals

SFCCCCProfessional·TigerschemeOfficial page →

SalesForce Certified Community Cloud Consultant

SalesForce Certified Community Cloud Consultant

SOG CCSP-AWSProfessional·Mile2Official page →

SecOps Group Certified Cloud Security Practitioner - AWS

SecOps Group Certified Cloud Security Practitioner - AWS

VCDX DCVExpert·VMwareOfficial page →

VMware Certified Design Expert in Datacenter Virtualization

VMware Certified Design Expert in Datacenter Virtualization

Also touched

CIPTProfessional·IAPPOfficial page →

Certified Information Privacy Technologist

Privacy engineering, privacy-by-design in products and platforms.

CISSPExpert·ISC2Official page →

Certified Information Systems Security Professional

Breadth across security engineering, architecture, operations, and governance at senior-IC / manager level. The default senior-generalist signal.

CSA CZTProfessional·Cloud Security AllianceOfficial page →

Certified Zero Trust (CCZT)

Vendor-neutral Zero Trust architecture and governance — NIST SP 800-207, ZTA pillars, and program implementation.

CyberArk GuardianExpert·CyberArkOfficial page →

CyberArk Guardian — PAM

Top-tier CyberArk practitioner — leads complex PAM programs and contributes back to the community.

CyberArk SentryProfessional·CyberArkOfficial page →

CyberArk Sentry — PAM

Designs and deploys CyberArk PAM at enterprise scale — vault architecture, HA/DR, and complex onboarding.

Elastic EngineerProfessional·ElasticOfficial page →

Elastic Certified Engineer

Stands up and operates Elastic Stack clusters — search, observability, and security-analytics workloads on a real cluster.

SailPoint Identity EngineerProfessional·SailPointOfficial page →

SailPoint Certified Identity Security Engineer

Designs and engineers SailPoint identity solutions across IdentityIQ and Identity Security Cloud (ISC).

SC-300Associate·MicrosoftOfficial page →

Microsoft Certified: Identity and Access Administrator Associate

Entra ID deployment, conditional access, privileged access, identity governance.

Security+Entry·CompTIAOfficial page →

CompTIA Security+

Broad entry-level knowledge across threats, ops, IAM, network, and crypto basics.

Browse all certifications → — pick a cert on the interactive map to highlight every domain it covers.

More in Cybersecurity

Test what you know about Cloud Security

45 questions available. Beginner to expert questions, scored against the global leaderboard.