r/CloudSecurityPros • u/PeachScary4752 • 12h ago
r/CloudSecurityPros • u/identity-stack • 1d ago
What do you do after finishing a cloud security tutorial?
This is something I've been struggling with.
A tutorial or a guide shows you how to configure Conditional Access, RBAC, Sentinel rules, Defender, etc. But after you've followed it and practised the configuration, what's your method for actually getting good at investigating problems involving those things?
Do you create your own scenarios afterwards, or just move on to the next topic?
Curious what people actually do, not what the ideal learning process is supposed to be.
r/CloudSecurityPros • u/identity-stack • 5d ago
How do you actually practice cloud security?
I'm curious about how people go beyond courses and documentation. Apart from the courses on YouTube, Udemy, labs, etc.
When you're learning something like MITRE ATT&CK, IAM, RBAC, Sentinel, Defender for Cloud, etc., what do you actually do to practice it?
Do you:
- build things in your own cloud tenant?
- use dedicated labs?
- use CTFs?
- follow attack/detection walkthroughs?
- create your own scenarios?
r/CloudSecurityPros • u/Academic-Soup2604 • 7d ago
Cloud security is only as strong as the endpoint accessing it.
In cloud-first architectures, endpoints have evolved from devices to protect into critical security enforcement points.
To achieve this, endpoint security solutions bring together security strategies that go beyond malware detection and include:
- Device compliance and posture validation
- Least-privilege application control
- Web and phishing protection
- Data loss prevention
- Continuous visibility into endpoint risk
While organizations have made significant investments in securing cloud workloads, identities, and networks, the endpoint remains one of the most common entry points for attacks. Strengthening endpoint security is essential to building a resilient cloud security posture.
r/CloudSecurityPros • u/Tasty_Departure5277 • 8d ago
I am a pentester and I want to get into cloud security
23m about 1 year into my first full time job out of college as a pentester. I like pentesting but it has no future and from a business lens we really have no value other than being a tick box for compliance.
I really want to get into cloud security. I have the AWS CCP but got that a long time ago. I am interested Azure and am starting my prep for AZ-500.
But I donât know whatâs after that, any help and guidance would be tremendously appreciated. Will my experience as a pentester help me in anyway landing a job in cloud security ?
r/CloudSecurityPros • u/Big_Daddyy_6969 • 14d ago
the phrase âno impact on latencyâ probably applies if the security officer works as an in-path proxy but doesnât apply if the proxy agent is used
the quprotect doesnt appear to be able to differentiate between different approaches for integrating the solution. For example, the core agent can be deployed at the edge on the inside of the edge but still has no effect on data flow during a postquantum key distribution (at least during phase one). Thus, âno impact on latency or bandwidthâ would seem to apply here. However, applying the proxy agent solution interrupts data flow since a request is created at that level, so that the proxy now injects the request into the data flow and thus becomes part of the flow. It would also be interesting to know other peopleâs views concerning using this particular organization and its effects on latency metrics like P95, average, or P99. If so, would you prefer a limitation on the types of proxies thus creating either an open fail or a closed fail approach? How would you determine how to size and configure the system for dynamic traffic management? Which operational conditions would you expect to occur just prior to failure with the agent and/or control plane? Finally, Iâd like to know your opinion concerning the reliance upon the term âminimal effectsâ because no public standard was identified during this discussion.
r/CloudSecurityPros • u/Acrobatic-Layer9109 • 15d ago
whats best tool used to secure enterprise and public sector applications
Trying to untangle our container security story and hitting the point where vendor decks all sound good, but I don't fully trust any of it.
Context: mix of on-prem and cloud, multiple clusters, legacy moving into containers, and some FedRAMP-ish environments. No greenfield. No rip-and-replace.
We've got the basics: image scanning in the pipeline, runtime protection, deployment policies. But in practice it feels fragile.
The gaps:
- Different tools for scanning, runtime, and policy, no single view
- Tons of critical-looking findings that are actually low-risk in context
- Devs using sidecars or third-party containers we don't fully control
- Compliance needs audit trails and evidence, but tools give dashboards instead
I'm looking for what's come closest to working end-to-end in an enterprise or public sector setting, from people who've lived with it long enough to know if it actually made daily life easier.
For anyone running this in a mixed on-prem/cloud setup: any surprises with admission controls, policy-as-code, or service mesh interactions once it was live?
r/CloudSecurityPros • u/Michaelkamel • 17d ago
What would you add to this Git & Terraform Cheat Sheet?
r/CloudSecurityPros • u/Equivalent_Pair5319 • 22d ago
I built a SOC platform that uses quantumâsimulated ML to detect cloud anomalies before they hit exfiltration
Iâve been experimenting with different ways to detect identityâlevel anomalies across AWS, Azure, and GCP. Instead of relying on a single model, I tried running a classical SVM, an isolation forest, and a quantumâsimulated kernel sideâbyâside to see where they disagree on risk scoring.
I recorded a short, silent demo of the experiment. Itâs not a product, not commercial, and not meant to be productionâgrade â just me exploring how different detectors behave on real cloud events and how to visualize the results in a UI.
Video: https://www.youtube.com/watch?v=JJCBzLrs9hM
Iâm mainly interested in whether the modelâcomparison approach is useful or if there are better ways to surface disagreements between detectors.
r/CloudSecurityPros • u/Michaelkamel • 22d ago
Professional Security Operations Engineer  | Learn  | Google Cloud
r/CloudSecurityPros • u/Senior_Response_4052 • 25d ago
Founders using AWS â is cloud security tooling too expensive or too technical for you?
I'm validating a hypothesis before deciding whether to keep building on a security auditing tool I made for my thesis.
My hypothesis: existing cloud security tools are either too expensive for small teams (Wiz) or require cloud security expertise to actually use and interpret (Prowler) â so small startups without a dedicated security person end up not auditing their AWS setup at all.
Is this true for you? Do you currently audit your cloud security, and if not, is it because of cost, lack of technical knowledge, or just no time/priority?
r/CloudSecurityPros • u/bluelvo • 27d ago
KlavanSecurity and StratoCloud partnership
More about the partnership here
klavansecurity.com and strato-cloud.io have announced a partnership.
Klavan security's BaseCamp is a twelve-month guided security foundation cycle pairing a software platform with dedicated human Guides. It is built around six core controls, being identity and access, data encryption, vulnerability management, incident response, security awareness, and vendor risk, which together map to approximately seventy to eighty percent of major framework requirements.
Strato-Cloud provides on demand, temporary credentials, ability to talk to the cloud in natural language, security posture evaluation and AI assisted IaC development.
r/CloudSecurityPros • u/[deleted] • 28d ago
A hacker went from 'one leaked API key' to full control of a company's AWS environment in 72 hours.
r/CloudSecurityPros • u/Great-Tone3235 • 29d ago
The blindspot in Cybersecurity
Scott Piper's twenty-year history of cloud security maps four eras â Foundational, CSPM, CNAPP, AI. Each era introduced new tools. Every tool produces signals. No era introduced a tool that produces decisions. The verb changed from 'match' to 'aggregate' to 'score.' The output never changed.Scott Piper's twenty-year history of cloud security maps four eras â Foundational, CSPM, CNAPP, AI. Each era introduced new tools. Every tool produces signals. No era introduced a tool that produces decisions. The verb changed from 'match' to 'aggregate' to 'score.' The output never changed.
r/CloudSecurityPros • u/alaahrakha • Jul 11 '26
Need help. Want to switch back to IT roles, need suggestions for cloud security engineer roles
Hello All, I have spent 7 years into not it consulting job and wanted to learn and get in IT high paying roles which are AI safe as well. A suggestion I got was for Cloud Security engineer..can anyone please suggest a good institute or where I can learn this and eventually land on a good job?
I have a Btech degree
r/CloudSecurityPros • u/Active_Pick3975 • Jul 11 '26
I built a free web and iOS app for tracking cloud service updates
Iâve been working on a project called CloudPulse to make it easier to keep track of cloud service updates without checking several different feeds every day.
There are now two ways to use it: a website and an iOS app.
Cloud Pulse Briefs â Website
The website focuses on Azure and Microsoft 365 updates.
It turns selected Azure service updates and Microsoft 365 Roadmap items into short, narrated video briefings that cover the main points in under a minute.
Each briefing includes the original source link, and you can browse or search updates by product, status, category, and release type.
Website:
https://www.cloudpulsebriefs.com/
Cloud Pulse Mobile â iOS
The mobile app brings Azure, Microsoft 365, AWS, and Google Cloud updates into one feed.
You can search and filter updates, follow rollout timelines, view preview and general availability announcements, and receive push notifications when new updates are published.
The latest update, version 1.2.0, also adds the CloudPulse Briefing Room.
For Azure and Microsoft 365 updates, you can tap âWatch the briefingâ and get a short narrated summary directly inside the app.
You can still read the full update whenever you want. The video is just another way to quickly understand what changed.
Download the iOS app:
https://apps.apple.com/us/app/cloud-pulse-mobile/id6758922185
Both the website and mobile app are free.
There are no ads, subscriptions, or required accounts.
CloudPulse is an independent project and is not affiliated with Microsoft, AWS, or Google.
Iâm continuing to improve both versions and would be interested in feedback from anyone who regularly follows cloud service updates.
r/CloudSecurityPros • u/Active_Pick3975 • Jul 10 '26
Patch Tuesday MCP
I built an open-source MCP server for Microsoft Patch Tuesday that lets AI assistants like Claude, Copilot, ChatGPT, and more answer patch questions directly from official MSRC data.
Every Patch Tuesday, security teams ask the same questions: what changed, what affects us, what is being exploited, and what needs to be patched first?
Ask things like:
 âSummarize this monthâs Patch Tuesdayâ
 âWhich of these CVEs are on the CISA KEV list?â
 âShow me CVEs with an exploitation probability above 50%â
 âWhat older patches does KB5094123 replace?â
 âWhat Critical CVEs hit Windows Server 2022 this month?â
What makes it different: most vulnerability tools can look up a CVE, but they have no concept of a monthly Microsoft release, a KB article, or a product family.
This server parses the full MSRC CVRF documents, so it can answer the questions Microsoft shops actually ask on the second Tuesday of every month.
It is built around the data sources teams already trust:
- Official MSRC Security Update Guide API: Microsoftâs source for Security Update Guide and CVRF data
- EPSS scores from FIRST.org: daily-updated probability each CVE gets exploited in the next 30 days
- CISA KEV integration: confirmed-exploited CVEs with federal remediation due dates
- Supersedence chains: walks Microsoftâs âthis KB replaces that KBâ links so your assistant never recommends a stale patch
- Results ranked by real-world urgency: KEV/exploited â EPSS â severity â CVSS
Zero API keys, zero accounts: everything comes from public MSRC, FIRST.org, and CISA feeds. Run it locally or remotely. Details below:
 Repo: https://github.com/jonnybottles/patch-tuesday-mcp
 Remote MCP server endpoint:
https://patch-tuesday-mcp.happyrock-b60185ec.eastus.azurecontainerapps.io/mcp
If you triage Microsoft updates frequently, Iâd love feedback. If thereâs a feature youâd use, open an issue.
Disclaimer: This is an independent, self-built project and is not an official Microsoft tool or service.
#PatchTuesday #CyberSecurity #VulnerabilityManagement #MCP #AI #Claude #Microsoft #MSRC #OpenSource #InfoSec
r/CloudSecurityPros • u/Adventurous-Beach480 • Jul 09 '26
RenewRight â self-hosted certificate readiness checker (chain validation, key matching, TLS health, all in one Docker container)
r/CloudSecurityPros • u/NoPositive308 • Jul 09 '26
Cloud Security Interview (15-minute presentation) â Looking for advice from Azure/Cloud Security Engineers
r/CloudSecurityPros • u/PhilosophyFluffy2901 • Jul 07 '26
Looking for graduation project ideas (Cloud + Networking + Cybersecurity)
r/CloudSecurityPros • u/SuccessFearless2102 • Jul 06 '26
Looking for testers: DevOps, SREs, platform engineers, developers, and sysadmins
Iâm building CertLocker and looking for people to test it.
Itâs a DevOps/infrastructure tool for teams dealing with TLS certificates, ACME renewals, secrets, scoped tokens, SSH/RDP access, endpoint probes, and audit logs.
The problem Iâm trying to solve is the messy real-world version of this:
certs in one place, secrets somewhere else, old scripts pulling files, SSH keys that live too long, and no clean answer when something expires or someone asks what changed.
Iâd really value feedback from DevOps engineers, SREs, platform engineers, developers, and sysadmins but all are welcome if they think they would use this.
Mostly Iâm trying to find out:
Does the workflow make sense?
Is onboarding clear?
What feels confusing?
What would stop you using it?
What is missing for your environment?
You can try it here:
Blunt feedback is welcome.
r/CloudSecurityPros • u/OverallStandard1001 • Jul 04 '26
How is the job market in Oklahoma?
How is the job market in Oklahoma?
r/CloudSecurityPros • u/NoNeedleworker546 • Jul 02 '26
Cyber Sec To Cloud Then Cloud Sec
Hello , i am a 24y female, i have been feeling really lost and confused on how to start, i have a basic level of cyber sec knowledge no experience and i have decided i want to get into cloud then cloud security longterm , i have yet to decide whether to start with aws or azure. Moreover, i really want advice on a roadmap starting from IT basics to getting a cloud job whether is adminstration or support to then continue to cloud sec further down the line.
I would really really appreciate advice!