AWS Security Engineering
Secure AWS estates at professional depth: IAM policy craft including permission boundaries, org-wide guardrails with SCPs, GuardDuty detection with hands-on finding response, network protections, KMS key policy, and centralized logging — closing with response to seeded findings under time pressure.
What this course covers.
6 modules, 42 named skill atoms. Expand any module to see them.
1IAM Mastery7 skill atoms
2Org Guardrails7 skill atoms
3Detection Stack7 skill atoms
4Network & Data Protection7 skill atoms
5Logging Architecture7 skill atoms
6Finding Response Drill7 skill atoms
SEC-202 in the role journeys.
This course appears in 2 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.
Roles this course serves
This course is authored to band B4.
Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.
What do B1–B6 mean?The CASI Capability Ladder — click to expand
Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.
A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.
Other Security courses at this level.
Azure Security Engineering
GCP Security Engineering
Cloud Security Posture Management (CSPM) & Hardening
Secrets Management & Cross-Cloud Federation
SaaS Security Posture Management (SSPM)
Identity Threat Detection & Response (ITDR)
Run SEC-202 for your team.
This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.