AWS

Security Engineering on AWS AWS-08

  • 1 upcoming date 1 open for booking
  • $2,025 per seat

Upcoming dates

Dates Where Status Seat Book
Sep 28–30 2026 Live Online 6:00 AM to 2:00 PM PT Confirmed to run Partner led $2,025

See every class on the schedule

About this class

This course demonstrates how to efficiently use AWS security services to stay secure in the AWS Cloud. The course focuses on the security practices that AWS recommends for enhancing the security of your data and systems in the cloud. The course highlights the security features of AWS key services including compute, storage, networking, and database services. You will also learn how to leverage AWS services and tools for automation, continuous monitoring and logging, and responding to security incidents.

This course is intended for

Security engineers Security architects Information security professionals

What you'll be able to do

  • Introduction to Security in the AWS Cloud
  • Managing Identity and Access Control
  • Securing Web Application Environments
  • Application Security at Scale
  • Data Protection and Encryption Best Practices
  • Network Security and Traffic Protection
  • Centralized Monitoring and Logging
  • Log Processing and Analysis
  • Securing Hybrid Cloud Architectures
  • Building Global Resilience and DDoS Protection
  • Serverless Security Practices
  • Threat Detection and Investigation
  • Secrets and Key Management
  • Automating Security by Design
  • Governance and Account Management at Scale

Course outline

  1. Module 1Introduction to Security in the AWS Cloud

    • Understand the AWS Shared Responsibility Model
    • Explore core cloud security principles
    • Review incident response strategies in AWS
    • Align DevOps processes with security engineering
  2. Module 2Managing Identity and Access Control

    • Define and apply IAM policies, roles, and permissions boundaries
    • Use IAM Access Analyzer for insight into access risks
    • Implement multi - factor authentication (MFA)
    • Monitor access activity with AWS CloudTrail
  3. Module 3Securing Web Application Environments

    • Analyze threats to 3- tier application architectures
    • Address common risks around user and data access
    • Leverage AWS Trusted Advisor for continuous improvement
  4. Module 4Application Security at Scale

    • Harden Amazon Machine Images (AMIs)
    • Perform automated security assessments with Amazon Inspector
    • Apply secure configuration management with AWS Systems Manager
  5. Module 5Data Protection and Encryption Best Practices

    • Encrypt data in S3, RDS, DynamoDB, and Glacier
    • Apply key management strategies using AWS KMS
    • Use S3 Access Analyzer and Access Points for precise control
  6. Module 6Network Security and Traffic Protection

    • Implement best practices for securing Amazon VPCs
    • Use VPC Traffic Mirroring for deep packet inspection
    • Respond to compromised instances
    • Secure endpoints with AWS Certificate Manager and ELB
  7. Module 7Centralized Monitoring and Logging

    • Configure CloudWatch, AWS Config, and Amazon Macie
    • Enable VPC Flow Logs, ELB Logs, and S3 Server Access Logs
  8. Module 8Log Processing and Analysis

    • Aggregate log data with Amazon Kinesis
    • Analyze security events using Amazon Athena
  9. Module 9Securing Hybrid Cloud Architectures

    • Connect environments with VPNs and Direct Connect
    • Secure cross - region traffic with AWS Transit Gateway
  10. Module 10Building Global Resilience and DDoS Protection

    • Use Route 53 and CloudFront for edge - level protection
    • Defend against attacks with AWS WAF, Shield, and Firewall Manager
  11. Module 11Serverless Security Practices

    • Control access in serverless environments with Amazon Cognito
    • Secure APIs with API Gateway
    • Implement least - privilege execution in AWS Lambda
  12. Module 12Threat Detection and Investigation

    • Identify suspicious activity with Amazon GuardDuty
    • Consolidate findings in AWS Security Hub
    • Perform forensic analysis with Amazon Detective
  13. Module 13Secrets and Key Management

    • Manage encryption keys using AWS KMS and CloudHSM
    • Store and rotate secrets with AWS Secrets Manager
  14. Module 14Automating Security by Design

    • Create secure, repeatable deployments with AWS CloudFormation
    • Standardize infrastructure with AWS Service Catalog
  15. Module 15Governance and Account Management at Scale

    • Manage multi - account environments with AWS Organizations
    • Enforce controls using AWS Control Tower and AWS SSO
    • Integrate centralized identity with AWS Directory Services

Download the full outline (PDF)

Before you attend

We recommend that attendees of this course have: Working knowledge of IT security practices and infrastructure concepts pract ices that AWS recommends for enhancing the security of your systems in the cloud. Completed AWS Security Essentials and Architecting on AWS courses .

Run this for a team

Private cohorts run on your dates, at your site or online, with the labs pointed at your environment. Above about four people it usually costs less than buying seats.

Or call 916-920-1700, weekdays 8 to 5 Pacific.

More cloud computing classes

See all