AWS Certified Security – Specialty (Security Engineering on AWS) Training & Certification Course
The AWS Certified Security – Specialty (Security Engineering on AWS) course equips security engineers and cloud architects with advanced skills to design and implement robust security solutions on AWS, addressing the critical shortage of cloud security expertise.
Course Overview
This course provides hands-on experience with core AWS security services, including Amazon GuardDuty, AWS Security Hub, AWS Config, AWS Key Management Service (KMS), Amazon Macie, and AWS Identity and Access Management (IAM). Students gain practical skills by configuring monitoring systems, implementing encryption strategies, and managing access controls within the AWS Console. A key lab component involves building a centralized security monitoring solution using AWS Config and Amazon GuardDuty to detect and respond to threats, while also classifying sensitive data in Amazon S3 using Amazon Macie. These real-world exercises simulate enterprise security operations and reinforce best practices in threat detection, data protection, and compliance.
Earning the AWS Certified Security – Specialty certification significantly enhances career prospects, with certified professionals commanding an average salary of $203,597 according to Skillsoft’s IT Skills and Salary survey. As the top highest-paying technical certification in the U.S., it validates elite skills in securing cloud architectures. Optiv Solutions supports success with Guaranteed-to-Run live training, official AWS courseware, and expert-led instruction. Completing this program positions individuals as trusted security advisors, ready to lead cloud security initiatives and advance into senior roles such as Cloud Security Architect or DevSecOps Engineer.
Skills You’ll Develop
Who Should Attend
WHO SHOULD ATTEND (TARGET AUDIENCE)
* Cybersecurity Professionals
* Security Architects
* AWS Cloud Engineers
* Cloud Architects
* DevSecOps Engineers
* Network Security Engineers
* IT Security Managers
* Security Operations (SOC) Professionals
* Identity & Access Management (IAM) Professionals
* Cloud Administrators
* Systems Administrators working with AWS
* DevOps Professionals responsible for cloud security
* IT Professionals preparing for the **AWS Certified Security – Specialty** certification
* Professionals responsible for securing AWS workloads, applications, and infrastructure
* Experienced AWS professionals looking to advance their careers in cloud security
Pre-requisites
RECOMMENDED KNOWLEDGE BEFORE TAKING THIS COURSE
- ✓ Basic understanding of AWS cloud services and architecture
- ✓ Experience working with AWS infrastructure and workloads
- ✓ Knowledge of networking concepts such as VPCs, subnets, security groups, and network ACLs
- ✓ Understanding of identity and access management concepts
- ✓ Familiarity with cybersecurity and information security principles
- ✓ Basic knowledge of encryption, authentication, authorization, and access controls
- ✓ Experience with AWS security services is recommended but not mandatory
- ✓ Prior hands-on experience administering or securing AWS environments is beneficial
Certification Exam Details
Everything you need to know about the certification exam
Exam Details
Upcoming Batch Schedule
Enroll in upcoming batches and start your learning journey
Curriculum & Course Syllabus
Module 1: AWS Security Fundamentals
- AWS Shared Responsibility Model
- AWS security principles and best practices
- AWS security architecture
- Security of AWS infrastructure and workloads
- Compliance and governance fundamentals
- AWS security design principles
Module 2: Identity and Access Management
- AWS Identity and Access Management (IAM)
- IAM users, groups, roles, and policies
- Resource-based and identity-based policies
- IAM policy evaluation logic
- Least-privilege access
- IAM Access Analyzer
- AWS Organizations and Service Control Policies (SCPs)
- Multi-factor authentication (MFA)
- Federation and identity providers
- AWS IAM Identity Center
Module 3: Data Protection and Encryption
- Data protection in AWS
- Encryption at rest and in transit
- AWS Key Management Service (AWS KMS)
- Customer managed and AWS managed keys
- Key policies and grants
- AWS CloudHSM
- AWS Secrets Manager
- AWS Certificate Manager (ACM)
- S3 encryption and bucket security
- Encryption best practices
Module 4: Network Security
- Amazon VPC security architecture
- Security Groups
- Network ACLs
- VPC endpoints
- PrivateLink
- AWS Network Firewall
- AWS Firewall Manager
- AWS WAF
- AWS Shield and DDoS protection
- Network segmentation
- Secure connectivity and hybrid network security
Module 5: Infrastructure and Application Security
- Securing EC2 instances
- Amazon EBS security
- Amazon S3 security
- Amazon RDS security
- AWS Lambda security
- Container security
- Amazon EKS security fundamentals
- API security
- Application-layer protection
- Secure application architecture
Module 6: Security Monitoring, Logging and Detection
- AWS CloudTrail
- AWS CloudWatch security monitoring
- VPC Flow Logs
- AWS Config
- Amazon GuardDuty
- AWS Security Hub
- Amazon Inspector
- Centralized logging
- Security event monitoring
- Threat detection and investigation
Module 7: Security Automation and Incident Response
- AWS security automation
- Incident response fundamentals
- Security event investigation
- Automated remediation
- AWS Systems Manager for security operations
- AWS Lambda-based security automation
- Event-driven security workflows
- Incident response strategies
- Containment and recovery
Module 8: Security Governance, Risk and Compliance
- AWS Audit Manager
- AWS Artifact
- AWS compliance programs
- Security policies and controls
- Risk management
- Audit preparation
- Regulatory and compliance requirements
- Governance across AWS accounts
- Security best practices and control frameworks
Module 9: Security Architecture and Design
- Designing secure AWS architectures
- Defense-in-depth strategies
- Zero Trust principles in AWS
- Secure multi-account architecture
- High-availability security design
- Secure hybrid cloud architecture
- Identity-centric security
- Data security architecture
- Security architecture best practices
Module 10: AWS Security – Exam Preparation
- AWS Certified Security – Specialty exam structure
- Exam domains and question types
- Scenario-based security questions
- Security architecture case studies
- Practice questions and assessments
- Exam strategies and time management
- Identification of common exam pitfalls
- Final certification readiness assessment
Student Reviews & Testimonials
Real feedback from certified professionals and corporate teams
Frequently Asked Questions
What are the prerequisites for this course?
Participants should have a good understanding of AWS cloud services, AWS architecture, networking, identity and access management, and cybersecurity fundamentals. Hands-on experience securing AWS workloads is highly recommended. AWS currently describes the target candidate for the SCS-C03 certification as having approximately 3–5 years of experience securing cloud solutions.
Is prior AWS certification required?
No. AWS does not require candidates to hold another certification before attempting the AWS Certified Security – Specialty exam. However, practical AWS experience and familiarity with AWS architecture and security services are strongly recommended.
Which AWS security services are covered?
The course covers major AWS security services and features including AWS IAM, AWS KMS, AWS Security Hub, Amazon GuardDuty, AWS WAF, AWS CloudTrail, AWS Config, AWS Firewall Manager, AWS Shield, AWS Secrets Manager, AWS Certificate Manager, AWS Audit Manager, AWS Artifact, AWS Organizations, VPC security groups, network ACLs, and S3 security controls. AWS's current SCS-C03 exam guide includes many of these services within its exam scope.
Does the course include hands-on practical training?
Yes. The training is designed around practical AWS security concepts and real-world scenarios, allowing learners to understand how AWS security services and controls can be applied to secure cloud environments.
Is the AWS Certified Security – Specialty (Security Engineering on AWS) exam fee included in the tuition, and what is the current cost?
The AWS Certified Security – Specialty (Security Engineering on AWS) exam fee is excluded from your training investment. The official AWS exam price is $300 USD, though regional taxes and exchange rates may apply. You can secure your exam voucher through Pearson VUE or verified AWS partners.
How long is lab access for AWS Certified Security – Specialty (Security Engineering on AWS) and what platform is utilized?
Optiv grants 30 days of hands-on lab access for AWS Certified Security – Specialty (Security Engineering on AWS). You will work within a secure, cloud-based AWS sandbox environment. This allows you to master IAM policies, encryption, and incident response workflows safely without impacting your live production systems.
How long is the AWS Certified Security – Specialty (Security Engineering on AWS) certification valid and how do I renew it?
Your AWS Certified Security – Specialty (Security Engineering on AWS) credential remains valid for three years. Recertification requires passing the current SCS-C03 exam for $300 USD. AWS also provides a recertification path via AWS Skill Builder for eligible candidates within 90 days of their expiration date.