cloud-security
Cloud Security
Cloud breaches are rarely clever. They are a public bucket, an over-permissive role, a database on an open security group, and no audit log to reconstruct what happened. This skill covers cloud posture specifically: the configuration of identity, network exposure, encryption, detection coverage, and multi-account guardrails across AWS, Azure, and GCP.
Scope boundary. This skill is deliberately narrow so it does not overlap
its neighbours in engineering/. It does not cover application-code
vulnerabilities, dependency CVEs, or compliance-framework mapping — that is
senior-secops. It does not cover log analysis and intrusion signals —
that is threat-detection. It does not cover offensive engagement planning
or rules of engagement — that is red-team. It does not cover prompt
injection, model extraction, or ML-pipeline threats — that is ai-security.
What lives here is the posture of the cloud control plane itself: who can do
what, what is reachable, what is encrypted, and what is logged.