Online professional certificate

Professional Certificate in Cloud Security Operations

Turn cloud signals into practical security decisions. Assess posture, Zero Trust access, workload identities and alerts; plan safe changes and hand clear evidence to the right owner.

Format
Online, self-paced
Study time
Up to 1 month
Curriculum
22 applied lessons
Language
English

Practical capability

Operate cloud security with clear evidence and ownership.

Build six connected capabilities used in cloud security operations, from scope and baseline checks to identity, detection, secure change and reviewable evidence.

01Scope and owners

Map services, assets, trust boundaries and the people who approve and carry out changes.

02Posture and priority

Check an approved baseline, validate drift and route findings by evidence and impact.

03Identity and Zero Trust

Review human and workload access, token paths, policy conditions and exceptions.

04Detection and response

Plan telemetry, test detections, triage alerts and prepare an incident handoff.

05Secure delivery

Review infrastructure as code, pipelines, remediation and bounded automation tests.

06Control evidence

Brief security metrics, map controls to evidence and assess AI workload signals.

Who this course is for

A practical route into cloud security operations.

Designed for beginning and transitioning professionals who need a repeatable way to check cloud evidence, explain choices and coordinate with authorized owners.

CSAspiring cloud security engineer
CACloud security analyst
SOSecurity operations analyst
DPDevSecOps or platform practitioner

The operating cycle

Move from a signal to a reviewable decision.

Practise the trigger-to-close progression in the Cloud Security Operations role playbook, with evidence and approval visible at each handoff.

Step 1Open and scope the request
Step 2Validate source evidence
Step 3Prioritize with the owner
Step 4Plan an authorized response
Step 5Verify the changed state
Step 6Close or transfer the record

Curriculum

Four modules. Twenty-two applied lessons.

Module 1

Scope cloud services and prioritize findings

A cloud security operator often receives an incomplete request: a team wants a service checked, a finding fixed, or a deployment approved. Before anyone changes a setting, the operator must know which service and data are involved, what evidence exists, and who has the authority to decide. This module begins with the human handoffs and service map that make later security work reliable.

01 Define the Cloud Security Operator's Remit and Handoffs

Map a cloud security operator's responsibilities, decision boundaries and handoffs in a supervised service request.

Five practical steps

  1. State the requested decision
  2. Identify affected service and data
  3. Separate analysis from approval
  4. Map owners and interfaces
  5. Record unresolved authority; route next action

Primary deliverable: Role-boundary and stakeholder map.

02 Inventory Cloud Assets and Trust Boundaries

Inventory cloud assets, identities, data flows and trust boundaries before a security review.

Five practical steps

  1. Define scope
  2. List accounts and services
  3. Trace identities and data
  4. Mark trust boundaries
  5. Record unknowns; seek owner validation

Primary deliverable: Scoped cloud asset and trust-boundary inventory.

03 Assign Cloud Control Owners and Change Authority

Assign shared-responsibility control owners and approved change paths for a cloud guardrail.

Five practical steps

  1. State control outcome
  2. Separate provider and customer parts
  3. Assign build and validation owners
  4. Identify approval path
  5. Define evidence; check uncovered responsibility

Primary deliverable: Control ownership and change-authority matrix.

04 Assess Cloud Posture and Validate Drift

Assess cloud posture against an approved baseline, validate drift and identify the right owner.

Five practical steps

  1. Confirm asset and baseline
  2. Validate the observed configuration
  3. Compare with approved exception
  4. Record impact and uncertainty
  5. Identify owner; recommend verification

Primary deliverable: Posture baseline and drift assessment.

05 Prioritize Findings and Route Remediation

Prioritize validated posture and vulnerability findings and route them for remediation.

Five practical steps

  1. Validate each finding
  2. Estimate likely consequence
  3. Identify exploitability and exposure
  4. Record uncertainty
  5. Rank with rationale; route to owners; set follow-up evidence

Primary deliverable: Finding triage and service-owner routing register.

Module 2

Make identity and Zero Trust access decisions

A cloud service can have a sound configuration and still expose the wrong person or workload to the wrong resource. Access decisions depend on identity, policy, context, and a known owner. This module moves from a human account to workload tokens, then to a complete Zero Trust access path.

06 Review Human Access and Least Privilege

Review a human identity's access lifecycle and recommend a least-privilege decision.

Five practical steps

  1. Verify identity and business task
  2. Map existing access
  3. Compare least-privilege need
  4. Spot conflicts and stale grants
  5. Record decision rationale; route approval and revocation

Primary deliverable: Human-identity access decision record.

07 Trace Workload Tokens and Signing-Key Ownership

Trace workload token issuance, audience, lifetime and signing-key ownership.

Five practical steps

  1. Trace issuer and subject
  2. Identify audience and trust boundary
  3. Map token lifetime
  4. Locate key owner and rotation path
  5. Check logging; record gap and owner

Primary deliverable: Workload-token and signing-key owner map.

08 Evaluate a Zero Trust Access Path

Evaluate a Zero Trust access path using explicit identity, policy, telemetry and failure conditions.

Five practical steps

  1. Identify subject and resource
  2. State trust assumptions
  3. Define minimum access
  4. Choose verification conditions
  5. Plan logging and failure mode; route policy approval

Primary deliverable: Zero Trust access-path decision map.

09 Review Network Exposure and Segmentation

Review cloud network exposure and propose a controlled segmentation change.

Five practical steps

  1. Trace source to destination
  2. Identify exposure
  3. Compare authorized purpose
  4. Consider segmentation alternatives
  5. Assess operational effect; route change; plan retest

Primary deliverable: Network exposure and segmentation review.

10 Record Access Reviews and Exceptions

Document an access review, an exception and the authorized decision for each grant.

Five practical steps

  1. Define review population
  2. Verify grants
  3. Request owner attestation
  4. Record exception basis and expiry
  5. Route decision; retain evidence

Primary deliverable: Access review and exception decision log.

Module 3

Detect, investigate, and hand off cloud incidents

A security alert is useful only when the team can explain what it saw, what it did not see, and how it will check the claim. This module begins with telemetry coverage because missing or short-lived logs can undermine every later conclusion. A detection is treated as a testable hypothesis rather than an automatic verdict.

11 Plan Cloud Telemetry and Evidence Coverage

Plan cloud telemetry sources and identify evidence and retention gaps for an investigation.

Five practical steps

  1. State investigation question
  2. Map event sources
  3. Check identity and time fields
  4. Identify gaps
  5. Set collection/retention owner; plan validation

Primary deliverable: Cloud telemetry coverage and gap plan.

12 Design and Test a Cloud Detection

Turn a cloud threat hypothesis into a detection with positive and negative tests.

Five practical steps

  1. Define observable behavior
  2. Select signal fields
  3. State detection rule
  4. Design positive and negative tests
  5. Inspect false positives; record tuning and owner

Primary deliverable: Detection hypothesis and test-case sheet.

13 Triage a Cloud Alert with Evidence

Triage a cloud alert, distinguish facts from hypotheses and route the next action.

Five practical steps

  1. Confirm alert identity
  2. Inspect source events
  3. Correlate timeline
  4. Separate facts from hypotheses
  5. Assess priority; route or close with reason

Primary deliverable: Alert triage evidence record.

14 Reconstruct an Identity-to-Cloud Incident

Reconstruct an identity-to-cloud incident timeline from multiple event sources.

Five practical steps

  1. Fix scope and time zone
  2. Preserve source references
  3. Order events
  4. Correlate identities and sessions
  5. Mark uncertainty; identify investigative gaps; brief incident owner

Primary deliverable: Identity compromise investigation timeline.

15 Recommend Containment and an Authorized Handoff

Recommend a bounded containment option and preserve evidence for an authorized incident handoff.

Five practical steps

  1. State confirmed facts
  2. Describe potential impact
  3. Compare containment options
  4. Identify disruption and evidence risks
  5. Name approver and responder; record recommendation and handoff

Primary deliverable: Incident handoff and containment recommendation.

Module 4

Secure changes, prove closure, and review evidence

Cloud security operations continue after an alert or posture finding. Changes must be reviewed before deployment, remediation must be retested, and a team needs evidence that explains what was done. This module follows a change from infrastructure code through pipeline trust boundaries and closure checks.

16 Review Infrastructure as Code and Policy Tests

Review an IaC change and policy test before an authorized cloud deployment.

Five practical steps

  1. State intended control
  2. Read changed resource
  3. Compare to baseline
  4. Design a test
  5. Assess false confidence; route review and rollback

Primary deliverable: IaC security review and policy-test report.

17 Threat-Model a Pipeline and Container Path

Threat-model CI/CD and container identities, artifacts and trust crossings.

Five practical steps

  1. Map pipeline stages
  2. Locate secrets and identities
  3. Identify trust crossings
  4. Assess artifact integrity
  5. Choose least-privilege controls; assign owners and tests

Primary deliverable: Pipeline and container threat model.

18 Retest Remediation and Recommend Closure

Retest a cloud remediation and record whether a finding can be closed.

Five practical steps

  1. Restate original failure
  2. Inspect change evidence
  3. Repeat the relevant test
  4. Compare before/after
  5. Record residual risk; obtain owner closure

Primary deliverable: Remediation validation and closure record.

19 Design and Test Safe Security Automation

Design and test a small cloud security automation in a read-only synthetic setting, including failure and rollback cases.

Five practical steps

  1. Define narrow task
  2. Identify read and write permissions
  3. Specify normal and exceptional inputs
  4. Design dry-run tests
  5. Review failure handling; name approver and rollback path; record validation

Primary deliverable: Security automation design, test and rollback plan.

20 Brief Control Evidence and Security Metrics

Create traceable security evidence and metrics for a locally defined operating review.

Five practical steps

  1. Define audience and decision
  2. Verify data lineage
  3. Select meaningful measures
  4. Explain limits
  5. Name action owners; check migration impact

Primary deliverable: Control evidence and metric briefing.

21 Map a Cloud Control to Complete Local Evidence

Map a locally applicable cloud control to period-bounded evidence and governance ownership.

Five practical steps

  1. Confirm applicable requirement and owner
  2. State control intent
  3. Map implementation and evidence source
  4. Test completeness and period
  5. Record gap or exception; hand off for governance judgment

Primary deliverable: Cloud control-to-evidence mapping sheet.

22 Assess AI Workload Telemetry and Human Triage

Assess AI workload telemetry and verify an AI-assisted alert with a human triage owner.

Five practical steps

  1. Define workload and data
  2. Map identity and telemetry
  3. Verify AI-assisted alert against events
  4. Assign triage owner
  5. Route consequential action; record closure evidence

Primary deliverable: AI workload security coverage and triage plan.

Applied capstone

Make one defensible cloud security decision.

Use the relevant course methods to prepare a concise recommendation and accountable handoff from a time-bounded cloud security case.

The situation

A service team has introduced a cloud application with a privileged workload identity. A new posture finding and identity-linked alert appear before a planned deployment, while the service owner wants a decision by the next change window.

Your task

Prepare a supervised cloud security recommendation that weighs the available evidence, identifies uncertainty, proposes a safe next action, and routes approval and execution to named local owners.

Cloud Security Decision and Handoff BriefOne evidence-based brief with verified observations, open checks, bounded options, a recommended next action and named approval and execution routes.

The people behind MTF

Meet MTF faculty and the learner community.

Explore the professional backgrounds of MTF faculty and learn more about the international community studying with the Institute.

Enrollment

Enroll in Professional Certificate in Cloud Security Operations

One-time course price: €10, including applicable taxes. Payment is processed securely by Stripe. No card details are stored on the MTF Institute website.

You will receive an email with access to the course. If you have any difficulties, please write to welcome@gtf.pt.

Secure payment on this page

Enter your enrollment email to continue in Stripe's encrypted form.

Cards, Apple Pay, Google Pay and other eligible methods

Questions and details

Frequently asked questions

Open the sections that matter to you, including delivery format, AI-supported practice and the evidence used to design the curriculum.

Who is this cloud security operations course for?

The course serves beginning cloud security engineers, cloud security analysts, security operations analysts and DevSecOps or platform practitioners. It teaches a repeatable way to inspect evidence, prepare recommendations and coordinate with service, identity, platform and incident owners.

How does the course work?

Study online at your pace over up to one month. Four modules contain 22 applied lessons, each with a practical work product, blank template, completed fictional example and optional AI practice. A separate capstone asks for one Cloud Security Decision and Handoff Brief.

How is AI used in the practical work?

Each lesson has a drafting prompt and a separate challenge prompt tied to its work product. You can use fictional or authorized inputs, check the response against the source facts and complete the same exercise without AI. A human owner reviews consequential decisions and changes.

What evidence supports the curriculum?

MTF Institute reviewed 109 current U.S. cloud-security vacancies and separately reviewed ten current primary sources on cloud identity, AI workloads and related operations changes. The research report, trend article and archived record DOI 10.5281/zenodo.23186319 document the evidence.

What practical work will I complete?

You will create 22 distinct workplace artifacts, including a cloud asset and trust-boundary inventory, Zero Trust access-path decision map, detection test sheet, incident handoff, IaC review and control-to-evidence map. The capstone brings the relevant methods into one decision and handoff brief.

How does Zero Trust fit the course?

You will trace a request from subject and workload identity through policy, resource, telemetry and failure conditions. The practice connects access decisions with token ownership, least privilege, segmentation, exceptions and the people who authorize changes.

What certificate and access will I receive?

After enrollment you receive access to the MTF learning platform. The closing section provides the course-completion certificate for Professional Certificate in Cloud Security Operations and a separate Student ID activity. The certificate records professional education.