Skip to main content

Cloud Security Certifications

Certification Roadmap for Junior Engineers

As a junior cloud engineer interested in security, it can be overwhelming to decide which certifications to pursue. Here's a suggested pathway to build your cloud security expertise:

Step 1: Foundational Cloud Certifications

Start with a basic cloud certification to understand the platforms before specializing in security:

Cloud ProviderBeginner CertificationTime to PrepareDescription
AWSAWS Certified Cloud Practitioner1-2 monthsBroad introduction to AWS services and concepts
AzureMicrosoft Certified: Azure Fundamentals (AZ-900)1-2 monthsBasic understanding of Azure services and cloud concepts
GCPGoogle Cloud Digital Leader1-2 monthsFundamental knowledge of Google Cloud capabilities

Step 2: Associate-Level Certifications

Once you have the basics, move to these intermediate certifications that include security components:

Cloud ProviderAssociate CertificationFocus Areas
AWSAWS Certified Solutions Architect - AssociateArchitecture, Security, Network
AzureMicrosoft Certified: Azure Administrator Associate (AZ-104)Implementation, Security, Monitoring
GCPGoogle Cloud Associate Cloud EngineerOperations, Security, Management

Step 3: Security Specialization

After gaining general cloud experience, focus on security-specific certifications:

ProviderSecurity CertificationDifficulty LevelKey Topics
AWSAWS Certified Security - SpecialtyIntermediate-AdvancedData protection, IAM, Incident Response
MicrosoftMicrosoft Certified: Security Operations Analyst Associate (SC-200)IntermediateThreat Monitoring, Incident Response
MicrosoftAZ-500: Microsoft Certified: Azure Security Engineer AssociateIntermediateIdentity Management, Platform Protection
GoogleGoogle Professional Cloud Security EngineerIntermediate-AdvancedInfrastructure Security, IAM, Compliance
Vendor-NeutralCompTIA Security+Beginner-IntermediateGeneral Security Fundamentals

Well Known Vendor Certs

Every major cloud service provider (AWS, Azure, GCP) has some sort of security certification. At the time of writing this none of them are actually practical certifications. They are multiple choice and scenario-based exams. However, don't let this discourage you from actually getting your hands dirty. Any practical, labs-based, project-based, etc is going to sink your learning home. Many employers do recognize the competency and attestation that comes with these vendor certifications even if there are better options out there to learn the material for you.

VendorCertification
ISC2Certified Cloud Security Professional
MicrosoftSC-200: Microsoft Certified: Security Operations Analyst Associate- AZ-500: Microsoft Certified: Azure Security Engineer Associate
AWSAWS Certified Security - Specialty
GoogleGoogle Professional Cloud Security Engineer

Free Certification Resources for Junior Engineers

Before investing in expensive courses, try these free resources:

  1. AWS:

  2. Azure:

  3. GCP:

  4. General Security:

    • TryHackMe - Many free rooms for learning security concepts
    • Cybrary - Free security courses and labs

Practical Certifications (training included)

Depending on who you ask, these are lesser-known certifications focused on providing training along with hands-on testing of your skills, rather than just multiple-choice questions.

AWSAzureGCP
AWS Red Team ApprenticeCertified Azure Red Team ProfessionalGCP Red Team Apprentice
Offensive AWS Security ProfessionalCertified Azure Web Application Security Professional
Offensive Azure Security Professional