Careers in cloud computing
Cloud professionals design, build and run applications and infrastructure on platforms such as AWS and Microsoft Azure instead of in a company's own data center. The work covers identity and access, virtual networks, compute, storage, databases, monitoring, automation with infrastructure as code, and keeping the monthly bill under control. Almost every organization now runs at least part of its IT in the cloud, so these skills are in demand in every industry.
It suits people who like building systems from parts, enjoy automation and are comfortable with constant change, because cloud providers release new services and features every week. You do not need to be a programmer, but you do need to be at ease with the command line, reading documentation, and thinking about security and cost at the same time as functionality.
Many people start in help desk, system administration or networking and add cloud skills, and some go straight into junior cloud support roles with a fundamentals certification and a strong home lab. Fundamentals exams prove you understand the concepts and pricing; associate-level and vendor-neutral certifications plus hands-on projects such as a secured account, a VPC design and infrastructure as code are what get you hired as an engineer.
Certification path
- Cloud Practitioner CLF-C02
The gentlest start: cloud concepts, the shared responsibility model, core AWS services, security basics and pricing. It gives you the vocabulary every later cloud certification and interview assumes. - Azure Fundamentals AZ-900
Adds the Microsoft side of the market: Azure architecture, resource groups, RBAC, Azure Policy and cost management. Many employers run both clouds, and knowing two providers shows you understand concepts rather than one console. - Cloud+ CV0-004
A vendor-neutral, operations-focused exam covering architecture, deployment, security, automation and troubleshooting across clouds. It suits people coming from sysadmin or networking roles and is recognized for many government and contractor jobs. - Solutions Architect Associate SAA-C03
The most requested associate cloud credential: designing secure, resilient, high-performing and cost-optimized architectures on AWS. Take it once you have built VPCs, IAM policies and monitoring yourself, because the scenarios reward real experience.
Jobs
Troubleshoots customer or internal cloud issues such as access denied errors, networking problems and failed deployments, and documents fixes in runbooks.
Manages accounts and subscriptions, users and roles, virtual machines, storage and backups, applies tagging and budgets, and handles routine change requests.
Builds and operates cloud infrastructure with infrastructure as code, designs networks and identity, sets up monitoring and alerting, and automates deployments.
Keeps cloud workloads available and fast, defines alerts and reliability targets, runs incident response for outages and reduces toil with automation.
Designs least-privilege access, guardrails and policies, reviews configurations for misconfigurations, and monitors cloud audit logs for threats.
Designs whole solutions to meet business requirements for security, resilience, performance and cost, and guides teams and customers through trade-offs and migrations.
Skills employers ask for
- Identity and access management: root and admin protection, least-privilege policies, roles and RBAC
- Virtual networking: CIDR planning, public and private subnets, route tables, security groups and NSGs
- Compute and storage services: virtual machines, object storage, block storage, snapshots and lifecycle rules
- Monitoring and logging with CloudWatch or Azure Monitor, including alarms and log queries
- Infrastructure as code with Terraform or CloudFormation, plus Git and code review
- Cost management: pricing models, budgets, tagging and right-sizing
- The shared responsibility model and cloud governance with policies, tags and locks
- Linux command line and scripting with Bash, Python or PowerShell
Your next 30 days
- Create a free AWS account and secure it first: root MFA, a zero-spend budget and an Identity Center admin user
- Complete the S3, EC2 and VPC labs and delete everything the same day, checking the bill the next morning
- Create an Azure free account and practise resource groups, RBAC and Azure Policy in the governance lab
- Rebuild one of your labs with Terraform or CloudFormation and put the code (without state files) in a Git repository
- Estimate the cost of a small web application in both pricing calculators and write a one-page memo
- Book AWS Cloud Practitioner or AZ-900 and set a weekly study block, then plan for Cloud+ or Solutions Architect Associate
Portfolio labs
- Secure a new AWS account before you build anything: root MFA, zero-spend budget and an Identity Center admin
- Write, test and tighten least-privilege IAM policies for an application role
- Host a static website on Amazon S3 and control access with Block Public Access and bucket policies
- Launch, secure, snapshot and terminate an EC2 web server on the Free Tier
- Design a two-AZ VPC with public and private subnets, reach a private instance without a NAT gateway
- Monitor with Amazon CloudWatch: logs, metric filters, alarms, email alerts and a billing alarm
- Azure governance basics: free account guardrails, resource groups, tags, RBAC, Azure Policy and locks
- Azure Storage and VMs: blob tiers, lifecycle rules, SAS, a Linux VM, snapshots and cost cleanup
- Infrastructure as code on AWS: deploy, change, detect drift and destroy with Terraform and CloudFormation
- Shared responsibility and cost estimation with the AWS and Azure pricing calculators (no account needed)
- Secure a new AWS account: root MFA, least privilege, logging
- Audit your AWS account's security posture with Prowler and fix the findings
- AWS VPC networking: subnets, route tables, security groups vs NACLs, peering and flow logs
- Azure administration basics: resource groups, VNet, NSG, VM, storage, RBAC and cost control
- Infrastructure as code with Terraform: providers, modules, state and workspaces
Interview practice
Cybersecurity Architecture
How would you design secure access to a cloud environment?
Centralize identity with SSO and MFA, use role-based access with least privilege and just-in-time elevation for admins, separate environments into accounts or subscriptions, enforce guardrail policies, log all administrative actions centrally and review access regularly. Interviewers want layered, identity-first design.
Explain zero trust in practical terms.
Zero trust means no implicit trust based on network location; every request is authenticated, authorized and evaluated using identity, device health and context. In practice it means strong identity, conditional access, segmentation, encryption and continuous monitoring. Avoid treating it as a single product.
What is threat modeling and when do you do it?
It is a structured way to identify what can go wrong with a system and how to mitigate it, for example using STRIDE on a data flow diagram. Do it during design and when significant changes happen, with developers and owners involved. Mention that outputs should become tracked requirements.
How do you secure data at rest and in transit?
Use TLS for data in transit, encryption at rest with managed keys, strict key access controls and rotation, and classification to decide where stronger controls apply. Mention that encryption does not replace access control and that key management is where designs often fail.
A business team wants to launch a new service quickly without a security review. How do you respond?
Understand their deadline, offer a lightweight review focused on the highest risks, provide pre-approved patterns they can adopt, and agree follow-up actions for later. This shows you enable the business rather than blocking it.
How do you segment a network to limit lateral movement?
Group systems by function and sensitivity, place controls between segments with default deny, restrict administrative access through jump hosts or privileged access workstations, and use micro-segmentation where supported. Monitor traffic between segments. Interviewers look for defense in depth.
Tell me about a design decision where you had to make a trade-off.
Describe the options, the criteria such as risk, cost, performance and complexity, what you chose and why, and how it worked out. Interviewers want structured reasoning and honesty about downsides.
How do you make sure architecture standards are actually followed?
Publish clear reference designs, automate checks with policy as code and posture management, include security in design reviews and pipelines, and track exceptions with owners and expiry dates. Enforcement through automation is more reliable than documents alone.
Systems Administration
A server is running slowly. How do you investigate?
Check CPU, memory, disk I/O and network utilization with tools such as top, vmstat, iostat or Performance Monitor, identify the process responsible, review logs and recent changes, and compare with baseline. Explain how you would fix or escalate. Interviewers want a structured approach using evidence.
How do you approach patching production servers?
Test patches in a non-production environment first, schedule a maintenance window, take backups or snapshots, patch in stages, verify services afterward and have a rollback plan. Track compliance and handle emergency patches for actively exploited issues. This shows balance between security and uptime.
What is your backup strategy, and how do you know it works?
Describe the 3-2-1 approach of three copies, two media types and one offsite or immutable copy, with retention set by business needs. Stress that you test restores regularly, because an untested backup is not a backup. Mention recovery time and recovery point objectives.
Explain Linux file permissions and how you would give a group write access to a directory.
Permissions are read, write and execute for owner, group and others. You would set the group owner with chgrp, grant group write with chmod g+w, and consider setgid on the directory so new files inherit the group. Mention ACLs for more complex needs and least privilege.
What is Group Policy and give an example of how you have used it?
Group Policy centrally manages settings for users and computers in Active Directory, applied through objects linked to sites, domains and organizational units. Give an example such as enforcing password policy, mapping drives or deploying security baselines, and mention testing and gpresult for troubleshooting.
A service failed to start after a reboot. What do you do?
Check its status and logs with systemctl status and journalctl or the Windows event log, look for dependency, permission, configuration or port conflicts, check recent changes, fix and verify, then make sure it is enabled to start on boot. Document the cause.
Tell me about a task you automated.
Describe the manual process, why it was worth automating, the script or tool you wrote, how you tested it and the time or errors saved. Interviewers want to see initiative and safe automation practices.
How do you handle a user asking for administrator rights?
Understand what they need to do, find a way to meet it with least privilege, such as installing the software for them or granting a specific permission, and follow the approval process. Explain the risk politely. This shows service mindset combined with security.
How do you document your work?
Keep runbooks, configuration records, network and server diagrams, and clear ticket notes that another admin could follow. Update documentation as part of each change. Interviewers value this because it shows you think about the team, not just yourself.
Infrastructure Support
How would you design firewall rules for a new web application?
Start with default deny, allow only required traffic such as HTTPS from the internet to a load balancer or web tier, restrict the web tier to the application tier on specific ports, and the database only from the application tier. Log denies, document each rule's purpose and owner, and review regularly. Interviewers want least privilege and documentation.
What is the difference between an IDS and an IPS?
An IDS monitors and alerts on suspicious traffic; an IPS sits inline and can block it. IPS reduces response time but can break legitimate traffic if tuned poorly, so rollouts often start in detection mode. Showing awareness of that trade-off is the key.
A new log source is not showing up in the SIEM. How do you troubleshoot?
Check that the source is generating logs, the forwarder or agent is running, network paths and firewall ports are open, the collector is receiving, parsing is correct, and time stamps are right. Work step by step along the pipeline. Interviewers listen for structured troubleshooting.
How do you manage changes to security devices safely?
Use a change request with justification, peer review, a test plan, a maintenance window, configuration backups before and after, and a rollback plan. Verify the change worked and update documentation. This shows you protect availability as well as security.
Explain how a site-to-site IPsec VPN is established.
Phase 1 (IKE) authenticates the peers and builds a secure channel using agreed encryption, hashing, Diffie-Hellman group and pre-shared key or certificates. Phase 2 negotiates the IPsec security associations that protect the actual traffic, defined by the interesting traffic selectors. Mention that mismatched parameters or selectors are the most common failure.
How would you find and clean up unused or risky firewall rules?
Use hit counters and logs over a meaningful period to find unused rules, look for overly broad rules such as any-any, confirm with rule owners, disable before deleting, and document the change. Doing this regularly as a scheduled review is what interviewers want to hear.
Tell me about a time a change you made caused a problem.
Be honest: describe the change, the impact, how you detected and rolled back, how you communicated, and what process you improved afterward. Interviewers value ownership and learning over a perfect record.
How do certificates and PKI support infrastructure security?
Certificates bind identities to public keys, enabling TLS encryption, device and user authentication, VPNs and code signing. PKI manages issuing, renewal and revocation. Mention that expired certificates cause outages, so inventory and automated renewal are important.
Systems Security Analysis
How would you harden a newly built Windows or Linux server?
Start from a recognized baseline such as CIS benchmarks, remove unused services and software, apply patches, enforce strong authentication and least privilege, configure host firewall and logging, and verify with a compliance scan. Document deviations. Interviewers want a baseline-driven, verifiable approach.
What logs would you make sure are collected from a server, and why?
Authentication events, privilege use, process creation, service and configuration changes, security tool events and application logs, with accurate time sync and central forwarding. These support detection, investigation and compliance. Mention protecting logs from tampering.
What is configuration drift and how do you detect it?
Drift is when systems gradually move away from their approved configuration through manual changes. Detect it with regular compliance scans, configuration management tools and file integrity monitoring, and fix it by reapplying the baseline. Explain why automation reduces drift.
Explain least privilege and how you would apply it to service accounts.
Give each account only the access needed to do its job. For service accounts, use dedicated accounts per service, deny interactive logon, use managed service accounts or vaulted credentials with rotation, and review permissions regularly. Show practical controls, not just the definition.
An audit finds that multifactor authentication is not enforced for some administrators. What do you do?
Confirm the scope, identify why such as legacy systems or exemptions, prioritize enforcing MFA for privileged access, apply compensating controls where it is not yet possible, and track remediation with a deadline. Report progress to management. This shows risk ownership.
How do you balance security settings with usability?
Understand how people work, test settings with a pilot group, communicate changes in advance, provide alternatives where friction is high and measure the impact. Good answers show that unusable security leads to workarounds.
Tell me about a time you found a security issue in a system you did not own.
Describe how you verified it, reported it to the owner with evidence and a suggested fix, followed up and how it was resolved. Interviewers look for tact and responsible escalation.
How would you use file integrity monitoring?
Monitor critical system files, configurations and binaries for unexpected changes, alert on changes outside approved change windows, and tune it to avoid noise from normal updates. Tie alerts to change records so real anomalies stand out.
Enterprise Architecture
How do you align technology decisions with business strategy?
Start from business goals and capabilities, assess the current state, define a target architecture and a roadmap of steps, and evaluate options against cost, risk and value. Involve stakeholders and review regularly. Interviewers want to see business thinking, not just technology preferences.
How would you decide between building, buying or using a managed service?
Consider whether it differentiates the business, total cost including maintenance, time to value, skills available, integration, security and vendor lock-in. Build only what gives competitive advantage. Structured criteria are what interviewers want.
What makes a good API design for an enterprise?
Consistent naming and versioning, clear contracts and documentation, strong authentication and authorization, pagination and error standards, backward compatibility and monitoring. Explain how standards help many teams integrate safely.
How do you handle technical debt at an architectural level?
Make it visible in a register with impact, prioritize debt that blocks goals or creates risk, fund it as part of the roadmap and prevent new debt through standards and reviews. Show you treat it as a business decision.
A team wants to adopt a new technology that does not fit current standards. What do you do?
Understand the problem it solves, evaluate it against criteria such as security, supportability and cost, consider a time-boxed pilot, and either update the standards or recommend an alternative with reasons. This shows openness with governance.
How do you design for resilience?
Identify critical services and their availability needs, remove single points of failure, use redundancy across zones, design for graceful degradation, test failover and backups, and monitor. Link design choices to recovery objectives.
Tell me about a time you influenced a decision without direct authority.
Describe the stakeholders, how you built your case with evidence, addressed concerns and reached agreement, and the result. Influence is central to architecture roles, so interviewers listen closely.
How do you document an architecture so others can use it?
Use diagrams at multiple levels of detail, record key decisions with context and alternatives, keep it versioned and close to the work, and update it when things change. Useful documentation is short and current.