Security Engineering on AWS with JAM Training & Certification Course
Security Engineering on AWS with JAM equips cloud security engineers and architects with AWS-recommended practices to secure data and systems in the cloud, addressing the critical industry need for robust cloud security as 98% of enterprises now adopt multi-cloud strategies.
Course Overview
The course covers core AWS security services including AWS Identity and Access Management (IAM), AWS Key Management Service (KMS), AWS Secrets Manager, Amazon Macie, AWS WAF, and AWS Shield. Students engage in hands-on labs within the AWS Console, configuring encryption, implementing multi-factor authentication, and setting up logging with Amazon CloudWatch and AWS CloudTrail. A key component is the AWS Jam—a gamified, team-based event where participants solve real-world security challenges in a live AWS environment. During this immersive session, learners build and secure multi-account architectures, automate threat detection workflows, and respond to simulated incidents, reinforcing concepts through practical application.
This training directly supports preparation for the AWS Certified Security – Specialty certification, a globally recognized credential that demonstrates mastery in securing AWS workloads. Certified professionals report an average base salary of $168,700 in the U.S., with senior roles exceeding $215,000 annually. optiv Solutions enhances learning with official AWS courseware and a Guaranteed-to-Run schedule, ensuring access to expert-led instruction in a real-world lab environment. By completing Security Engineering on AWS with JAM, participants gain the skills to design secure cloud infrastructures and advance into high-impact roles as cloud security architects or security operations leads.
Skills You’ll Develop
Who Should Attend
WHO SHOULD ATTEND (TARGET AUDIENCE)
• Security Architects
• Cloud Security Engineers
• Cloud Architects
• Cloud Operators
• Information Security Professionals
• Cybersecurity Engineers
• Security Operations Professionals
• DevSecOps Engineers
• Cloud Infrastructure Engineers
• Cloud Administrators
• IT Security Managers
• Security Consultants
• AWS Solutions Architects with security responsibilities
• Professionals preparing for advanced AWS security responsibilities
Pre-requisites
RECOMMENDED KNOWLEDGE BEFORE TAKING THIS COURSE
- ✓ Completed AWS Security Essentials or equivalent AWS security fundamentals training.
- ✓ Completed Architecting on AWS or have equivalent AWS architecture knowledge.
- ✓ Working knowledge of IT security practices and infrastructure concepts.
- ✓ Familiarity with the AWS Cloud.
- ✓ Understanding of fundamental cloud computing concepts.
- ✓ Basic familiarity with AWS networking, compute and storage services is beneficial.
- ✓ Experience working with AWS environments is recommended for getting maximum value from the hands-on exercises.
Certification Exam Details
Everything you need to know about the certification exam
Exam Details
Upcoming Batch Schedule
Enroll in upcoming batches and start your learning journey
Curriculum & Course Syllabus
Module 1: Security Overview and Review
- Security in the AWS Cloud
- AWS Shared Responsibility Model
- AWS security principles
- Security controls and best practices
- IAM fundamentals
- Data protection
- Threat detection and response
- AWS Console, CLI and SDK access
- Multi-factor authentication
- Protecting the AWS root user
- Securing AWS access keys
- Introduction to incident response
Module 2: Securing Entry Points on AWS
- AWS authentication mechanisms
- IAM policies
- IAM roles
- Identity-based and resource-based policies
- Permission boundaries
- IAM Access Analyzer
- MFA implementation
- AWS CloudTrail
- API activity monitoring
- Access history
- Cross-account authentication
- Hands-on identity and resource-based policy exercises
Day 3: Account Management and Provisioning on AWS
- AWS Organizations
- Multi-account AWS environments
- AWS Control Tower
- Centralized account management
- AWS IAM Identity Center
- AWS Directory Service
- Identity providers
- Federated access
- Domain user access
- Centralized security controls
- Multi-account security considerations
- Hands-on account and identity management
Module 4: Secrets Management on AWS
- Secrets management concepts
- AWS Secrets Manager
- AWS Key Management Service
- AWS CloudHSM
- AWS Certificate Manager
- Encryption keys
- Key rotation
- Certificate management
- Protecting credentials
- Secure application access
- Hands-on AWS KMS exercises
Module 5: Data Security
- Data protection strategies
- Data classification
- Encryption at rest
- Encryption in transit
- Amazon S3 security
- Amazon RDS security
- Amazon DynamoDB security
- Amazon S3 Access Analyzer
- Amazon S3 Access Points
- Amazon S3 Glacier security
- Key management
- Access controls
- Protecting sensitive information
Module 6: Infrastructure Edge Protection
- AWS network security
- Amazon VPC security
- Security groups
- Network access controls
- Amazon Route 53 security
- AWS WAF
- AWS Shield
- AWS Firewall Manager
- Amazon CloudFront
- DDoS protection
- Protecting internet-facing applications
- Edge security architecture
Module 7: Monitoring and Collecting Logs on AWS
- AWS security monitoring
- AWS CloudTrail
- Amazon CloudWatch
- VPC Flow Logs
- Application logging
- Security event collection
- Centralized logging
- Log storage
- Monitoring API activity
- Security dashboards
- Identifying suspicious activities
- Security monitoring best practices
Module 8: Processing and Analyzing Logs
- Security log analysis
- CloudWatch Logs
- CloudWatch Logs Insights
- Log processing
- Log aggregation
- Event correlation
- Security analytics
- Identifying anomalous activity
- Monitoring security events
- Automating security analysis
Module 9: Security Considerations for Hybrid Environments
- Hybrid cloud security
- On-premises and AWS connectivity
- Hybrid identity
- Security boundaries
- Network security considerations
- Hybrid workload protection
- Common security risks
- Monitoring hybrid environments
- Security controls across environments
Module 10: Out-of-Region Protection
- Multi-Region security considerations
- Disaster recovery security
- Protecting workloads across Regions
- Data protection
- Access controls
- Security monitoring across Regions
- Regional resilience
Module 11: Security Considerations for Serverless Environments
- Serverless security principles
- Amazon Cognito
- Amazon API Gateway
- AWS Lambda
- Authentication and authorization
- API security
- Lambda permissions
- Least-privilege execution
- Securing serverless applications
Module 12: Threat Detection and Investigation
- AWS threat detection
- Amazon GuardDuty
- AWS Security Hub
- Amazon Detective
- Security findings
- Threat investigation
- Security event analysis
- Incident indicators
- Investigating suspicious activity
- Threat response
- Security incident workflows
Module 13: Secrets and Key Management
- AWS KMS
- AWS CloudHSM
- AWS Secrets Manager
- Key management
- Key rotation
- Certificate management
- Protecting credentials
- Secrets lifecycle management
- Encryption key security
Module 14: Automation and Security by Design
- Security automation
- Security by design
- AWS CloudFormation
- AWS Service Catalog
- Infrastructure as Code
- Repeatable security deployments
- Automated security controls
- Security configuration management
- Standardized deployment
- Automated compliance controls
Module 15: Account Management and Provisioning
- AWS Organizations
- AWS Control Tower
- IAM Identity Center
- AWS Directory Service
- Federated access
- Multi-account security
- Centralized identity
- Account governance
- Security guardrails
- Enterprise AWS security architecture
Student Reviews & Testimonials
Real feedback from certified professionals and corporate teams
Frequently Asked Questions
Is the AWS Certified Security - Specialty exam included in the Security Engineering on AWS with JAM course, and what is the exam fee if separate?
The AWS Certified Security - Specialty exam is not included in the Security Engineering on AWS with JAM course. You must purchase the 300 USD exam fee separately via the official AWS Certification portal. You can schedule your exam at Pearson VUE centers or via online proctoring.
How long is lab access provided for Security Engineering on AWS with JAM, and what environment is used?
Lab access for Security Engineering on AWS with JAM occurs during the 1-day AWS Jam session. You will work within a real AWS environment to solve gamified, team-based security challenges. This immersive, hands-on access is strictly limited to the duration of the live event.
How many questions are on the AWS Certified Security - Specialty exam, what types are included, and what is the passing score and time limit?
The AWS Certified Security - Specialty exam features 65 questions, including multiple choice, multiple response, ordering, and matching formats. You have a 170-minute time limit to achieve a passing score of 750 out of 1,000. Note that 15 questions are unscored and do not impact your final result.
How long is the AWS Certified Security - Specialty certification valid, and what is the renewal process and cost?
The AWS Certified Security - Specialty certification is valid for 3 years. You renew by passing the current exam version. AWS grants a 50% discount voucher via your Certification Account, effectively lowering the renewal cost from the standard 300 USD fee.
What post-training support does Optiv provide after completing Security Engineering on AWS with JAM?
Optiv offers 30 days of post-training email support from certified instructors and access to recorded sessions for review. While mentorship is not included, students may retake the same Security Engineering on AWS with JAM course version at a discounted rate within one year.