Group Purchasing
Group Purchasing

SEC480: AWS Secure Builder

SEC480Cloud Security
  • 16 Hours (Self-Paced)
Course authored by:
Serge Borso
Serge Borso
SEC480: AWS Secure Builder
Course authored by:
Serge Borso
Serge Borso
  • GIAC AWS Secure Builder Micro-Credential
  • 12 CPEs

    Apply your credits to renew your certifications

  • Self-paced

    Train at your own pace from wherever you are

  • Essential Skill Level

    Course material is for individuals with an understanding of IT or cyber security concepts

  • 9 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Ensure resilience against threats: Fortify applications, secure data, harden infrastructure, comply with GRC programs.

Course Overview

SEC480: AWS Secure Builder equips non-security personnel such as cloud engineers, developers, and architects with the security fundamentals necessary to build secure AWS workloads from the beginning. This course serves as foundational AWS security training, designed to fill the critical knowledge gap for technical professionals responsible for building and deploying workloads to AWS environments. Organizations operating in AWS face a level of complexity that can introduce vulnerabilities, frequently resulting from inadvertent misconfigurations.

Students engage in nine self-paced modules covering identity management, encryption, access control protocols, AI security, and secure coding principles—each paired with practical, real-world labs. The course delivers immediate value by empowering teams to implement protective measures without overburdening security personnel. Upon completion, learners leave with enhanced skills to construct resilient AWS environments.

Securing AWS Infrastructure: Strategic Defense Implementation

SEC480: AWS Secure Builder addresses eight critical risk areas, providing students with the skills and knowledge to enable enterprises to securely move workloads to AWS. By completing this AWS security course, participants will be well-equipped to implement and enhance security controls, leading to immediate improvements in security and business enablement. With this training, organizations can be confident in their teams' ability to adopt, build, and deploy in the cloud without overburdening security teams.

This AWS Security training is designed to scale across enterprise engineering and development teams, making a swift and significant impact on the security of AWS workloads.

Author Statement

"I think everyone can agree on the importance of safeguarding assets in today's world of sustained threats and immeasurable technical complexity, especially in the realm of AWS. How we do that, and why specific actions are performed, however, is not common knowledge, which is why SEC480 exists—to fill that knowledge gap.

In this course, we'll delve into the intricacies of identity management, encryption, access controls, and secure coding. My goal is to teach you how to fortify applications, secure data, harden infrastructure, comply with GRC programs and work to ensure resilience against threats, all while accounting for the fact that we are not completely in control of our success. As we navigate the AWS ecosystem, we'll embrace the shared responsibility model and lean into the fact that security is not an afterthought, but instead an integral part of every deployment.

With that said, let us explore the AWS cloud, understand cloud-native security solutions, and arm ourselves with the knowledge needed to implement best-in-class security controls."

- Serge Borso

What You'll Learn

  • Implement robust IAM configurations aligned with zero trust principles
  • Construct hardened CI/CD pipelines integrating automated security checks
  • Deploy encrypted communication channels securing inter-service data flows
  • Configure comprehensive logging mechanisms across AWS infrastructure
  • Design resilient incident response frameworks detecting intrusion attempts
  • Understand how to use and secure AI within AWS environments

Business Takeaways

  • Reduce security breaches through proactive secure architecture design
  • Accelerate compliance validation with built-in security controls
  • Decrease resource investment needed for retroactive security fixes
  • Enhance organizational security posture through workforce upskilling
  • Minimize operational disruptions resulting from security incidents
  • Strengthen client trust through demonstrable security capabilities
  • Improve security team efficiency by distributing security knowledge

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC480: AWS Secure Builder.

Section 1Secure Development and Deployment Practices in AWS

In Section 1 of Secure AWS Development, we will concentrate on the shared responsibility model, hardening workloads, securing the CICD pipeline, and understanding the critical role of IAM in AWS.

Module 1: Responsibility To, For, and Of Security

Overview

Students will understand the shared responsibility model, the difference between cloud and on-premesis security, AWS security architecture, compliance requirements, and how to apply effective security controls.

Topics

  • Cloud Security and Shared Responsibility Model
  • Security and Compliance
  • AppSec in the Cloud

Lab

  • Who's Responsible?

Module 2: Identification and Authorization

Overview

Students will implement best practices for IAM, explore workforce identity management, address common authentication failures, and apply secure access controls.

Topics

  • IAM in the Cloud
  • Workforce Identity
  • Identification and Authorization Failures

Lab

  • Cognito or Incognito?

Module 3: Continuous Integration Continuous Delivery (CICD)

Overview

Students will master CICD pipelines, automate code deployment with AWS Code Pipeline, integrate security tools, and prevent misconfigurations through hands-on labs and real-world demos.

Topics

  • CICD Explained
  • Build Process
  • CICD Security

Lab

  • Deploying and Securing Code

Module 4: Workload and Service Hardening

Overview

Students will harden AWS workloads and services like API Gateway, S3, EC2, and RDS, address misconfigurations, and ensure compliance through practical labs and real-world examples.

Topics

  • Common Services
  • AWS Workloads
  • Complexity Breeds Insecurity

Lab

  • Encryption at Rest

Section 2Securing AWS: Monitoring, Incident Response, and Trust

In Section 2 of Secure AWS Development, we seek to understand what happens when there are misconfigurations in our environment and how to deal with adversaries. In addition, we will delve into what proper logging and monitoring entail, how to use and secure AI, and strategies to leverage an incident response plan and minimize supply chain risks.

Module 5: Security Monitoring

Overview

Students will implement comprehensive security monitoring with logging at all levels, utilize monitoring tools, enhance alerting with artificial intelligence (AI), and set up early warning systems.

Topics

  • Logging
  • Monitoring
  • Alerting

Lab

  • Early Warning System

Module 6: Exposure and Attack Vectors

Overview

Students will identify and mitigate exposure and attack vectors through open-source intelligence (OSINT), understand the anatomy of attacks, and minimize attack surfaces using threat modeling and compliance tools.

Topics

  • OSINT
  • Anatomy of an Attack
  • Minimizing Attack Surface

Lab

  • Reducing Attack Surface

Module 7: Incident Response

Overview

Students will master the six-step incident response process, implement best practices with roles, playbooks, and technology, and prepare with tools and exercises.

Topics

  • Six-Step Incident Response Process
  • Incident Response Best Practices
  • Proper Preparation

Lab

  • Incident Response

Module 8: Trust, Control, and the Supply Chain

Overview

Students will evaluate vendor reliance and onboarding processes, implement Zero Trust principles, and defend against supply chain attacks to ensure secure vendor interactions and compliance.

Topics

  • Reliance on Vendors
  • Vendor Onboarding and Risk Evaluation
  • Zero Trust
  • Supply Chain Attacks

Lab

  • Trusted Vendor

Module 9: AI in AWS

Overview

Students will learn what AI tools exist in AWS and how they can be abused by adversaries, as well as how to architect their own environment for secure utilization of AI. 

Topics

  • Pre-trained AI and Generative AI
  • AI Use Cases and Benefits
  • AI for Enhanced Security Operations
  • Attacking and Abusing AI Systems in AWS
  • Defenses and Guardrails

Lab

  • Amazon Bedrock

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration And Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Students should have an OpenSSH client installed on their laptop.

If you have additional questions about the laptop specifications, please contact customer service.

SEC480 training is recommended for a diverse range of individuals, including:

  • AWS Builders and Build Teams:
    • Cloud Application Developers
    • Cloud Engineering Leaders
    • Cloud Engineers
    • Cloud Architects
    • Cloud Admins
    • Technical professionals who will be building in, operating in, configuring and / or managing AWS Cloud environments

The AWS Secure Builder Micro-Credential validates competency in securing and managing AWS environments, covering key areas such as the shared responsibility model, identity and access management, CI/CD pipeline security, and workload hardening. Candidates demonstrate knowledge of monitoring solutions, mitigating attack vectors, and applying incident response best practices. The exam also emphasizes zero trust principles and supply chain security to ensure a resilient AWS infrastructure.

More Certification Details

  • Printed books
  • MP3 audio files of the complete course lectures
  • Electronic courseware

While no specific prerequisites exist, basic familiarity with AWS services and security concepts will enhance the learning experience. The course is designed for technical professionals including cloud engineers, developers, architects, and security specialists working with AWS environments.

The learning path begins with SEC480 as foundational AWS security training, progressing to SEC502 for multi-cloud security fundamentals, then advancing to SEC510 for comprehensive cloud control implementation. Specialized paths include SEC540 for DevSecOps integration, SEC541 for threat detection capabilities, or SEC588 for cloud penetration testing, creating a complete professional development roadmap addressing diverse cloud security specializations.

AWS Secure Builder teaches engineers, developers, and architects how to securely build and manage workloads in Amazon Web Services (AWS). It focuses on preventing common cloud misconfigurations by covering identity and access management, data protection, secure CI/CD pipelines, and threat detection. Designed for non-security roles, the course helps technical teams build security into their AWS environments from the start. Delivered via SANS OnDemand, it can be completed in as little as 12 hours and includes practical labs and a micro-credential to validate newly acquired skills.

SEC480 students gain the skills to build and maintain secure AWS environments, reducing the risk of costly misconfigurations. Organizations benefit from stronger cloud security, fewer incidents, and greater confidence in development workflows. With an improved understanding of AWS best practices, non-security personnel will improve operational efficiency while maintaining compliance and protecting critical business assets. This AWS cyber security course gives you the practical experience needed to contribute directly to secure cloud architecture and DevSecOps initiatives.

Relevant Job Roles

Cybersecurity Architecture (OPM 652)

NICE: Design and Development

Responsible for ensuring that security requirements are adequately addressed in all aspects of enterprise architecture, including reference models, segment and solution architectures, and the resulting systems that protect and support organizational mission and business processes.

Explore learning path

Technology Research and Development (OPM 661)

NICE: Design and Development

Responsible for conducting software and systems engineering and software systems research to develop new capabilities with fully integrated cybersecurity. Conducts comprehensive technology research to evaluate potential vulnerabilities in cyberspace systems.

Explore learning path

Enterprise Architecture (OPM 651)

NICE: Design and Development

Responsible for developing and maintaining business, systems, and information processes to support enterprise mission needs. Develops technology rules and requirements that describe baseline and target architectures.

Explore learning path

Course Includes:

Group Purchase?Contact Sales
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $1,300 USD*Prices exclude applicable local taxes
    Registration Options
Showing 1 of 1

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources