How John Became A Cloud Security Expert in 3 Steps
Follow his steps to start your own journey into the cloud !
Let me tell you about John.
John is a guy I tried to help get into Cloud Security
He had been working in data center and on-prem security for years and was bored out of his mind
Along with a new challenge .. John also realized that he needed to improve his skills and make them more in line with the market
The Cloud was something that interested him and Cloud Security seemed to be a nice niche to break into.
The Cloud Security Market has a serious skills gap with the recent ISC2 Cloud Security Report 2023 stating it as one of the major reasons holding back cloud adoptions
It has been my own experience that it is easy to find Cloud professionals and Cyber security professionals but VERY difficult to find Cloud Security Professionals
John reached out to me for help and these are the steps we took to upskill him in Cloud Security
NOTE: I have used AWS as an example as it is the largest cloud provider but these concepts can be applied to any provider honestly !
Step 1: Get a Cloud Sandbox Ready
Learning Cloud Security comes from actually DOING it and not reading a 500 page certification guide
There is no substitute for hands-on experience and the good news is that it is REALLY easy to get that in the cloud.
Cloud providers are more than happy to provide free sandboxes to experiment with their services.
John got access to an AWS free tier account and started playing around with these services

Step 2: Start Building
With a sandbox in place, John needed a way to systematically skill up in the cloud
Not a course which teaches you .. what is IAM , what is cloud blah blah
Those teach you concepts and not HANDS-ON skills
John needed to build things within the cloud to get confident with this skills
Good news is that AWS and other providers often provide great and free workshops that let people get confident with their services.
A few of them are listed below :
AWS Workshops:
https://workshops.aws/
Azure Workshops:
https://microsoftcloudworkshop.com/
Google Cloud: https://cloud.google.com/training
Believe me when I say nothing will give your teams more confidence than actually making something with different cloud services.
John thought this would be the first step but I advised him to keep it for the last
I am a big fan of knowing the right place to put certifications
If fact I advised him to not even start with a security certification but with a solutions architect one
How do you secure an environment if you do not even know how it works ?
Do not fall for the certification hype
Learning never stops in the cloud!
With these steps, John was able to get a firm foundation in place when it comes to Cloud Security.
It is important to know that learning is a continuous journey.
Even after spending several years dedicated to cloud security, I can safely say that I am still learning
Use John’s journey as a template if you are planning to start in cloud security today and I guarantee you will see results
Good luck in your journey !





