Cybersecurity Professional TrainingAdvanced security program

From cloud practitioner to enterprise security engineer

Cloud and AI Security Specialist Program

Engineer defensible cloud and AI systems through identity-first architecture, Kubernetes controls, secure delivery, AI threat modelling, detection and incident response.

View curriculum
Recommended background

Who should take this course

  • Two or more years in cloud, security, infrastructure, operations or software engineering
  • Comfort with Linux, networking, Git and one public cloud
  • Basic Docker or Kubernetes experience is recommended
  • Authorized access to the course cyber range; no production credentials or data
Capability outcomes

What you should be able to do

  • Model cloud and AI attack paths against business impact
  • Design identity, secrets and privileged-access controls
  • Harden containers, Kubernetes and infrastructure-as-code delivery
  • Test AI applications for injection, data leakage and unsafe tool use
  • Create actionable detections and investigation evidence
  • Lead a cloud or AI incident exercise through containment and recovery
Detailed curriculum

Six guided modules from fundamentals to applied work.

Every module combines instructor explanation, guided implementation and a practical milestone. Tools may be adapted to the sponsoring organization’s approved stack.

6Learning modules
3Guided projects
P1

Threat-led security architecture

Connect assets, trust boundaries and likely attack paths to measurable control objectives.

Topics covered

  • Cloud shared responsibility
  • Asset and data-flow discovery
  • Threat modelling and abuse cases
  • Control mapping using NIST CSF and Zero Trust principles

Practical milestone

Threat-model a multi-account cloud application with an AI service boundary.

Tools and platforms

Architecture tooling · NIST CSF concepts · Cloud security services

P2

Identity, access and secrets

Reduce the blast radius created by standing privilege, weak workload identity and unmanaged credentials.

Topics covered

  • Human and workload identities
  • Federation, MFA and conditional access
  • PAM, JIT access and break-glass controls
  • Secrets, keys, certificates and rotation

Practical milestone

Build and test a least-privilege access model with a controlled escalation path.

Tools and platforms

AWS IAM or Microsoft Entra · Secrets manager · Policy simulator

P3

Cloud-native workload protection

Apply preventive and detective controls from source code through Kubernetes runtime.

Topics covered

  • Supply-chain and dependency risk
  • Container images and registries
  • Kubernetes admission and network policies
  • IaC scanning and policy-as-code

Practical milestone

Harden a containerized service and block non-compliant deployment changes.

Tools and platforms

Docker · Kubernetes · OPA concepts · IaC scanner

P4

Secure AI application engineering

Treat models, prompts, retrieval, tools and data connectors as a connected security boundary.

Topics covered

  • AI system data-flow and trust boundaries
  • Prompt injection and indirect injection
  • Retrieval poisoning and sensitive-data exposure
  • Tool authorization, output handling and human approval

Practical milestone

Attack and harden a retrieval-and-tool workflow in an isolated range.

Tools and platforms

AI gateway concepts · RAG stack · Evaluation harness · DLP controls

P5

Detection engineering and investigation

Turn cloud and AI telemetry into high-signal detections with evidence an analyst can use.

Topics covered

  • Cloud audit and identity telemetry
  • Kubernetes and workload signals
  • AI gateway and application logs
  • Detection-as-code, triage and evidence preservation

Practical milestone

Create detections for credential misuse and anomalous AI tool execution.

Tools and platforms

SIEM · Cloud audit logs · Detection rules · Case management

P6

Incident response and assurance

Practise decision-making under pressure and prove that controls operate as intended.

Topics covered

  • Cloud and AI incident playbooks
  • Containment, credential rotation and recovery
  • Forensics boundaries and communication
  • Control testing, metrics and improvement backlog

Practical milestone

Run a team incident exercise and defend the after-action report to a review panel.

Tools and platforms

Cyber range · Incident timeline · Control-evidence pack

Applied learning

Turn each module into practical project work.

PROJECT 01

Zero Trust cloud identity and privileged-access redesign

PROJECT 02

Hardened Kubernetes delivery path with policy-as-code

PROJECT 03

AI application red-team and incident-response capstone

Course completion

Projects, feedback and final review

Threat model 15% · Identity and workload labs 25% · AI security test 25% · Incident exercise 20% · Control-evidence defense 15%

Completion depends on working project evidence and a clear explanation of the learner’s decisions. Detailed rubrics, lab access and vendor prerequisites are confirmed before enrolment.

Corporate or individual training

Confirm fit, prerequisites and the next cohort.