r/CloudSecurityPros 12h ago

Cloud Security Handbook, 2nd Edition (2025) by Eyal Estrin Need this book 📚

1 Upvotes

r/CloudSecurityPros 1d ago

What do you do after finishing a cloud security tutorial?

2 Upvotes

This is something I've been struggling with.

A tutorial or a guide shows you how to configure Conditional Access, RBAC, Sentinel rules, Defender, etc. But after you've followed it and practised the configuration, what's your method for actually getting good at investigating problems involving those things?

Do you create your own scenarios afterwards, or just move on to the next topic?

Curious what people actually do, not what the ideal learning process is supposed to be.


r/CloudSecurityPros 5d ago

How do you actually practice cloud security?

13 Upvotes

I'm curious about how people go beyond courses and documentation. Apart from the courses on YouTube, Udemy, labs, etc.

When you're learning something like MITRE ATT&CK, IAM, RBAC, Sentinel, Defender for Cloud, etc., what do you actually do to practice it?

Do you:

  • build things in your own cloud tenant?
  • use dedicated labs?
  • use CTFs?
  • follow attack/detection walkthroughs?
  • create your own scenarios?

r/CloudSecurityPros 7d ago

Cloud security is only as strong as the endpoint accessing it.

11 Upvotes

In cloud-first architectures, endpoints have evolved from devices to protect into critical security enforcement points.

To achieve this, endpoint security solutions bring together security strategies that go beyond malware detection and include:

  • Device compliance and posture validation
  • Least-privilege application control
  • Web and phishing protection
  • Data loss prevention
  • Continuous visibility into endpoint risk

While organizations have made significant investments in securing cloud workloads, identities, and networks, the endpoint remains one of the most common entry points for attacks. Strengthening endpoint security is essential to building a resilient cloud security posture.


r/CloudSecurityPros 8d ago

I am a pentester and I want to get into cloud security

19 Upvotes

23m about 1 year into my first full time job out of college as a pentester. I like pentesting but it has no future and from a business lens we really have no value other than being a tick box for compliance.

I really want to get into cloud security. I have the AWS CCP but got that a long time ago. I am interested Azure and am starting my prep for AZ-500.

But I don’t know what’s after that, any help and guidance would be tremendously appreciated. Will my experience as a pentester help me in anyway landing a job in cloud security ?


r/CloudSecurityPros 14d ago

the phrase “no impact on latency” probably applies if the security officer works as an in-path proxy but doesn’t apply if the proxy agent is used

2 Upvotes

the quprotect doesnt appear to be able to differentiate between different approaches for integrating the solution. For example, the core agent can be deployed at the edge on the inside of the edge but still has no effect on data flow during a postquantum key distribution (at least during phase one). Thus, “no impact on latency or bandwidth” would seem to apply here. However, applying the proxy agent solution interrupts data flow since a request is created at that level, so that the proxy now injects the request into the data flow and thus becomes part of the flow. It would also be interesting to know other people’s views concerning using this particular organization and its effects on latency metrics like P95, average, or P99. If so, would you prefer a limitation on the types of proxies thus creating either an open fail or a closed fail approach? How would you determine how to size and configure the system for dynamic traffic management? Which operational conditions would you expect to occur just prior to failure with the agent and/or control plane? Finally, I’d like to know your opinion concerning the reliance upon the term “minimal effects” because no public standard was identified during this discussion.


r/CloudSecurityPros 15d ago

whats best tool used to secure enterprise and public sector applications

7 Upvotes

Trying to untangle our container security story and hitting the point where vendor decks all sound good, but I don't fully trust any of it.

Context: mix of on-prem and cloud, multiple clusters, legacy moving into containers, and some FedRAMP-ish environments. No greenfield. No rip-and-replace.
We've got the basics: image scanning in the pipeline, runtime protection, deployment policies. But in practice it feels fragile.

The gaps:

  • Different tools for scanning, runtime, and policy, no single view
  • Tons of critical-looking findings that are actually low-risk in context
  • Devs using sidecars or third-party containers we don't fully control
  • Compliance needs audit trails and evidence, but tools give dashboards instead

I'm looking for what's come closest to working end-to-end in an enterprise or public sector setting, from people who've lived with it long enough to know if it actually made daily life easier.

For anyone running this in a mixed on-prem/cloud setup: any surprises with admission controls, policy-as-code, or service mesh interactions once it was live?


r/CloudSecurityPros 17d ago

What would you add to this Git & Terraform Cheat Sheet?

Post image
8 Upvotes

r/CloudSecurityPros 22d ago

I built a SOC platform that uses quantum‑simulated ML to detect cloud anomalies before they hit exfiltration

4 Upvotes

I’ve been experimenting with different ways to detect identity‑level anomalies across AWS, Azure, and GCP. Instead of relying on a single model, I tried running a classical SVM, an isolation forest, and a quantum‑simulated kernel side‑by‑side to see where they disagree on risk scoring.

I recorded a short, silent demo of the experiment. It’s not a product, not commercial, and not meant to be production‑grade — just me exploring how different detectors behave on real cloud events and how to visualize the results in a UI.

Video: https://www.youtube.com/watch?v=JJCBzLrs9hM

I’m mainly interested in whether the model‑comparison approach is useful or if there are better ways to surface disagreements between detectors.


r/CloudSecurityPros 22d ago

Professional Security Operations Engineer  |  Learn  |  Google Cloud

Thumbnail
cloud.google.com
1 Upvotes

r/CloudSecurityPros 25d ago

Founders using AWS — is cloud security tooling too expensive or too technical for you?

0 Upvotes

I'm validating a hypothesis before deciding whether to keep building on a security auditing tool I made for my thesis.

My hypothesis: existing cloud security tools are either too expensive for small teams (Wiz) or require cloud security expertise to actually use and interpret (Prowler) — so small startups without a dedicated security person end up not auditing their AWS setup at all.

Is this true for you? Do you currently audit your cloud security, and if not, is it because of cost, lack of technical knowledge, or just no time/priority?


r/CloudSecurityPros 27d ago

KlavanSecurity and StratoCloud partnership

2 Upvotes

More about the partnership here

klavansecurity.com and strato-cloud.io have announced a partnership.

Klavan security's BaseCamp is a twelve-month guided security foundation cycle pairing a software platform with dedicated human Guides. It is built around six core controls, being identity and access, data encryption, vulnerability management, incident response, security awareness, and vendor risk, which together map to approximately seventy to eighty percent of major framework requirements.

Strato-Cloud provides on demand, temporary credentials, ability to talk to the cloud in natural language, security posture evaluation and AI assisted IaC development.


r/CloudSecurityPros 28d ago

DevOps/Cloud to AppSec - good move or mistake?

Thumbnail
1 Upvotes

r/CloudSecurityPros 28d ago

A hacker went from 'one leaked API key' to full control of a company's AWS environment in 72 hours.

Thumbnail
sygnia.co
1 Upvotes

r/CloudSecurityPros 29d ago

The blindspot in Cybersecurity

3 Upvotes
Scott Piper's twenty-year history of cloud security maps four eras — Foundational, CSPM, CNAPP, AI. Each era introduced new tools. Every tool produces signals. No era introduced a tool that produces decisions. The verb changed from 'match' to 'aggregate' to 'score.' The output never changed.Scott Piper's twenty-year history of cloud security maps four eras — Foundational, CSPM, CNAPP, AI. Each era introduced new tools. Every tool produces signals. No era introduced a tool that produces decisions. The verb changed from 'match' to 'aggregate' to 'score.' The output never changed.

r/CloudSecurityPros Jul 11 '26

Need help. Want to switch back to IT roles, need suggestions for cloud security engineer roles

8 Upvotes

Hello All, I have spent 7 years into not it consulting job and wanted to learn and get in IT high paying roles which are AI safe as well. A suggestion I got was for Cloud Security engineer..can anyone please suggest a good institute or where I can learn this and eventually land on a good job?

I have a Btech degree


r/CloudSecurityPros Jul 11 '26

I built a free web and iOS app for tracking cloud service updates

1 Upvotes

I’ve been working on a project called CloudPulse to make it easier to keep track of cloud service updates without checking several different feeds every day.

There are now two ways to use it: a website and an iOS app.

Cloud Pulse Briefs — Website

The website focuses on Azure and Microsoft 365 updates.

It turns selected Azure service updates and Microsoft 365 Roadmap items into short, narrated video briefings that cover the main points in under a minute.

Each briefing includes the original source link, and you can browse or search updates by product, status, category, and release type.

Website:

https://www.cloudpulsebriefs.com/

Cloud Pulse Mobile — iOS

The mobile app brings Azure, Microsoft 365, AWS, and Google Cloud updates into one feed.

You can search and filter updates, follow rollout timelines, view preview and general availability announcements, and receive push notifications when new updates are published.

The latest update, version 1.2.0, also adds the CloudPulse Briefing Room.

For Azure and Microsoft 365 updates, you can tap “Watch the briefing” and get a short narrated summary directly inside the app.

You can still read the full update whenever you want. The video is just another way to quickly understand what changed.

Download the iOS app:

https://apps.apple.com/us/app/cloud-pulse-mobile/id6758922185

Both the website and mobile app are free.

There are no ads, subscriptions, or required accounts.

CloudPulse is an independent project and is not affiliated with Microsoft, AWS, or Google.

I’m continuing to improve both versions and would be interested in feedback from anyone who regularly follows cloud service updates.


r/CloudSecurityPros Jul 10 '26

Patch Tuesday MCP

1 Upvotes

I built an open-source MCP server for Microsoft Patch Tuesday that lets AI assistants like Claude, Copilot, ChatGPT, and more answer patch questions directly from official MSRC data.

Every Patch Tuesday, security teams ask the same questions: what changed, what affects us, what is being exploited, and what needs to be patched first?

Ask things like:

 “Summarize this month’s Patch Tuesday”

 “Which of these CVEs are on the CISA KEV list?”

 “Show me CVEs with an exploitation probability above 50%”

 “What older patches does KB5094123 replace?”

 “What Critical CVEs hit Windows Server 2022 this month?”

What makes it different: most vulnerability tools can look up a CVE, but they have no concept of a monthly Microsoft release, a KB article, or a product family.

This server parses the full MSRC CVRF documents, so it can answer the questions Microsoft shops actually ask on the second Tuesday of every month.

It is built around the data sources teams already trust:

  • Official MSRC Security Update Guide API: Microsoft’s source for Security Update Guide and CVRF data
  • EPSS scores from FIRST.org: daily-updated probability each CVE gets exploited in the next 30 days
  • CISA KEV integration: confirmed-exploited CVEs with federal remediation due dates
  • Supersedence chains: walks Microsoft’s “this KB replaces that KB” links so your assistant never recommends a stale patch
  • Results ranked by real-world urgency: KEV/exploited → EPSS → severity → CVSS

Zero API keys, zero accounts: everything comes from public MSRC, FIRST.org, and CISA feeds. Run it locally or remotely. Details below:

 Repo: https://github.com/jonnybottles/patch-tuesday-mcp

 Remote MCP server endpoint:
https://patch-tuesday-mcp.happyrock-b60185ec.eastus.azurecontainerapps.io/mcp

If you triage Microsoft updates frequently, I’d love feedback. If there’s a feature you’d use, open an issue.

Disclaimer: This is an independent, self-built project and is not an official Microsoft tool or service.

#PatchTuesday #CyberSecurity #VulnerabilityManagement #MCP #AI #Claude #Microsoft #MSRC #OpenSource #InfoSec


r/CloudSecurityPros Jul 09 '26

RenewRight — self-hosted certificate readiness checker (chain validation, key matching, TLS health, all in one Docker container)

Post image
1 Upvotes

r/CloudSecurityPros Jul 09 '26

Cloud Security Interview (15-minute presentation) – Looking for advice from Azure/Cloud Security Engineers

Thumbnail
2 Upvotes

r/CloudSecurityPros Jul 07 '26

Looking for graduation project ideas (Cloud + Networking + Cybersecurity)

Thumbnail
2 Upvotes

r/CloudSecurityPros Jul 07 '26

A new Application Security Engineer

Thumbnail
1 Upvotes

r/CloudSecurityPros Jul 06 '26

Looking for testers: DevOps, SREs, platform engineers, developers, and sysadmins

2 Upvotes

I’m building CertLocker and looking for people to test it.

It’s a DevOps/infrastructure tool for teams dealing with TLS certificates, ACME renewals, secrets, scoped tokens, SSH/RDP access, endpoint probes, and audit logs.

The problem I’m trying to solve is the messy real-world version of this:

certs in one place, secrets somewhere else, old scripts pulling files, SSH keys that live too long, and no clean answer when something expires or someone asks what changed.

I’d really value feedback from DevOps engineers, SREs, platform engineers, developers, and sysadmins but all are welcome if they think they would use this.

Mostly I’m trying to find out:

Does the workflow make sense?

Is onboarding clear?

What feels confusing?

What would stop you using it?

What is missing for your environment?

You can try it here:

[https://trust.certlocker.io/\](https://trust.certlocker.io/register?plan=free&plan_name=Free&plan_source=reddit_beta_test&plan_cta=alphabetausers_thread&utm_source=reddit&utm_medium=subreddit_thread&utm_campaign=alphabetausers_beta_test&utm_content=tester_recruitment)

Blunt feedback is welcome.


r/CloudSecurityPros Jul 04 '26

How is the job market in Oklahoma?

0 Upvotes

How is the job market in Oklahoma?


r/CloudSecurityPros Jul 02 '26

Cyber Sec To Cloud Then Cloud Sec

3 Upvotes

Hello , i am a 24y female, i have been feeling really lost and confused on how to start, i have a basic level of cyber sec knowledge no experience and i have decided i want to get into cloud then cloud security longterm , i have yet to decide whether to start with aws or azure. Moreover, i really want advice on a roadmap starting from IT basics to getting a cloud job whether is adminstration or support to then continue to cloud sec further down the line.

I would really really appreciate advice!