Multi Cloud Security Engineering and Controls
A multi cloud security engineering course for people who already run workloads in more than one provider and are tired of controls that only work in one. Ten weeks on AWS, Azure and Google Cloud in equal depth.
You build identity models, key management, and logging pipelines three times over, then reconcile them into a control set that survives all three threat models. The work is hands on and the assessment is whether your controls hold.
- Duration
- 10 weeks
- Format
- Live online, instructor-led
- Prerequisites
- Cloud Security Essentials
- Class size
- Capped at 12 learners

What you will be able to do
- Model identity in AWS IAM, Microsoft Entra ID and GCP IAM without conflating them
- Identify privilege escalation paths unique to each provider's permission model
- Design customer managed key hierarchies and rotation across all three clouds
- Build a logging pipeline that centralises audit events from three providers
- Write policy as code that expresses one intent in three provider dialects
- Assess where a control is genuinely equivalent and where it only looks equivalent
- Produce a per provider threat model and the controls that answer it
- Justify a control decision to an architect who prefers a different provider
Course outline
6 modules
- Where each provider's control plane concentrates risk
- Metadata services, tokens and workload identity in each cloud
- Provider specific attack techniques worth modelling
- Blast radius: accounts, subscriptions and projects compared
- Choosing a common vocabulary across three different sets of jargon
What you need before you start
- Cloud Security Essentials or solid working experience in at least one cloud
- Ability to read and modify Terraform or an equivalent infrastructure language
- Scripting comfort in Python, PowerShell or Bash
- Accounts or trial subscriptions in all three providers for lab work
Who this course is for
- Cloud security engineers responsible for more than one provider
- Platform engineers building shared guardrails for many teams
- Security architects who need implementation depth behind their diagrams
- Consultants assessing multi cloud estates for clients
- Senior analysts moving from operations into engineering work
Where this leads
Prepares you for
CCSP
Awarded by ISC2
This course goes deeper than the ISC2 CCSP requires on engineering detail, while covering its architecture, data and platform domains. ISC2 alone confers the CCSP after its exam and experience review. Course completion is separate from certification.
Questions about this course
More in cloud security
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



