I just want to state, when I get assigned to projects or help builders secure their apps, of course this includes at least some exposure to cloud security because all apps live in the cloud. A lot of my time goes to threat modeling, secure code review, and helping apps find threats in their design.
That said, I feel like my day-to-day is heavily weighted toward application-layer concerns, things like design flaws, api security, a lot of code review, etc.
For those of you who've made a similar transition (or work in cloud security and hire from AppSec backgrounds): How transferable are AppSec skills in practice? I'd assume threat modeling and understanding attacker mindset translate well, but what gaps should I expect?
What should I focus on studying? I'm thinking AWS/Azure/GCP certifications, but I'm not sure which ones actually matter vs. just being resume flair
Any resources, labs, or projects you'd recommend for building hands-on cloud security experience outside of work? Appreciate any advice. Trying to be intentional about this
submitted by
/u/Exact-Advantage-3190 [link] [comments]