- Cloud Platforms (IaaS, PaaS, SaaS)
- Deep understanding ofAWS,Azure, and/orGoogle Cloud Platform (GCP)
- Familiarity with cloud-native services (e.g., IAM, VPC, KMS, Security Groups)
- Security Architecture & Design
- Designing secure cloud architectures
- ApplyingZero Trustprinciples
- Understanding ofshared responsibility models
- Identity and Access Management (IAM)
- Role-based access control (RBAC)
- Single Sign-On (SSO), MFA, and federated identity
- Privileged access management
- Network Security
- Firewalls, VPNs, segmentation, and secure connectivity
- Cloud-native network security tools (e.g., AWS Security Groups, Azure NSGs)
- Data Protection
- Encryption at rest and in transit
- Key management systems (KMS, HSM)
- Data classification and loss prevention (DLP)
- Compliance & Governance
- Familiarity with standards likeNIST,CIS,ISO 27001,SOC 2,HIPAA,GDPR
- Policy-as-code (e.g., using tools like OPA, Sentinel)
- DevSecOps & Automation
- Integrating security into CI/CD pipelines
- Infrastructure as Code (IaC) security (e.g., Terraform, CloudFormation)
- Security scanning tools (e.g., Snyk, Checkov)
- Threat Modeling & Risk Assessment
- Identifying and mitigating cloud-specific threats
- Using frameworks like STRIDE or MITRE ATT&CK for Cloud
· |