Cloud Security
Cloud Security Engineer Bootcamp
Secure identity, network, data and workloads across AWS, Azure and GCP.
- 14 modules
- 22 labs
- ~40 hours
- Intermediate

- Hands-on Labs
- Projects
- Certificate
Course overview
A multi-cloud engineering course focused on the controls that actually stop incidents: identity boundaries, network segmentation, encryption and key management, logging pipelines, and posture management.
Every module ends with you building the control in a real cloud account under free-tier constraints, documenting the design, and tearing it down cleanly.
What you will be able to do
- Design least-privilege identity models in AWS, Azure and GCP
- Segment cloud networks and control egress
- Implement encryption and managed key rotation
- Centralise cloud logs into a detection pipeline
- Codify controls with Terraform and review posture findings
Curriculum
- 1
Cloud Security Architecture
Shared responsibility, landing zones and blast radius.
- Shared responsibility in practice
- Account and subscription strategy
- Landing zone patterns
- 2
Cloud Identity & Access
The control plane attackers go after first.
- AWS IAM policies and boundaries
- Azure RBAC and managed identities
- GCP IAM bindings
- Cross-account and workload identity
- 3
Network Security in the Cloud
Segmentation, private connectivity and egress control.
- VPC/VNet design
- Security groups and NSGs
- Private endpoints
- Egress filtering
- 4
Data Protection & Key Management
Encryption that survives an audit.
- KMS and Key Vault
- Customer-managed keys
- Secrets management
- Storage exposure prevention
- 5
Logging, Monitoring & Detection
Know what happened, in every cloud.
- CloudTrail, Activity Log, Cloud Audit Logs
- Centralised log pipelines
- Cloud detections
- Alert routing
- 6
Posture, IaC & Automation
Make the secure path the default path.
- CSPM findings triage
- Terraform for security controls
- Policy as code
- Cost-safe cleanup
Labs you will build
PrimeSec does not hand you a pre-built machine. You get professional lab guides and build the environment yourself — that is where the skill comes from.
- Build a least-privilege IAM role model in AWS
- Configure Azure RBAC with managed identities
- Segment a VPC and block unintended egress
- Encrypt storage with a customer-managed key
- Centralise CloudTrail into a detection pipeline
- Detect and remediate a public storage bucket
- Deploy a guarded baseline with Terraform
- Full teardown and billing verification
Portfolio projects
- Multi-cloud security architecture document with diagrams
- Terraform module set implementing your baseline controls
- A posture remediation report for a deliberately misconfigured environment
Frequently asked questions
Do you provide the lab environment?
No — and that is intentional. PrimeSec gives you professional lab guides that teach you to build and configure the environment yourself using your own machine, Hyper-V, VMware, VirtualBox, Docker, or a cloud free tier. Building and troubleshooting the environment is part of the skill.
Is this course self-paced?
Cloud Security Engineer Bootcamp is self-paced. Lessons, knowledge checks, labs and projects unlock in order so you always know what to do next.
Do I get a certificate?
You receive a PrimeSec course completion certificate once every module, lab and project requirement is met. It demonstrates completion and practical work — not an accredited industry certification.
Will cloud labs cost me money?
Labs are designed around free tiers and local virtualisation wherever possible, and every cloud lab includes cleanup steps so you do not leave billable resources running.
Related courses
AI Security
AI Security Fundamentals: Protecting AI Systems
Intermediate · 10 modules · 16 labs
IAM & Identity
Entra ID & Identity Security Mastery
Intermediate · 9 modules · 14 labs
DevSecOps
DevSecOps Engineering: Secure CI/CD Pipelines
Intermediate · 12 modules · 18 labs
