SC-500: Cloud & AI Security Engineer
Protect cloud and AI workloads with enterprise-grade security
Secure hybrid cloud and generative AI environments by mastering identity, networking, data protection and threat response. Learn practical techniques to harden AI workloads against emerging threats while aligning to Australian security frameworks and preparing for SC-500 certification.

At a Glance
Who it's for
- Cloud security engineers and architects
- AI security specialists and ML engineers
- DevOps teams managing hybrid cloud environments
- Security operations professionals using Sentinel/Defender
- Organisations implementing generative AI securely
- Candidates preparing for Microsoft SC-500 certification
Course Details
Course Overview
This intensive 36-hour course dives deep into securing cloud and AI infrastructures. You'll configure robust identity and access controls with Microsoft Entra ID, implement network segmentation and private links, and protect data at rest and in transit using Key Vault and encryption. The curriculum covers AI-specific threat mitigation such as prompt injection and model poisoning, and shows how to build security operations workflows with Microsoft Sentinel and Defender for Cloud. Throughout the course you'll apply Australian Privacy Principles, Essential Eight, ISO 27001 and other local compliance frameworks. Ideal for senior engineers and security professionals tasked with defending AI and hybrid cloud services.
What You'll Learn
Course Curriculum
Module 1: Secure Identity & Access
8 hours- Designing Entra ID tenants and managing users/groups
- Implementing multi-factor authentication and conditional access
- Configuring privilege identity management and least-privilege RBAC
- Service principals, managed identities and access tokens for AI workloads
- Audit logging and access reviews for compliance
Module 2: Secure Networking & Infrastructure
8 hours- Virtual network design for AI services
- Private Link, Service Endpoints and firewall policies
- Network security groups and Azure Firewall configuration
- Segmentation for data sovereignty and Essential Eight alignment
- Monitoring network traffic with NSG flow logs and Traffic Analytics
Module 3: Securing AI Data & Applications
8 hours- Encryption at rest with Storage Service Encryption and Customer-Managed Keys
- TLS/HTTPS, VPN and ExpressRoute for data in transit
- Key Vault integration and secret management patterns
- Protecting containerised AI (AKS, ACI) and functions
- Secure configuration of ML compute instances and notebooks
Module 4: AI-Specific Threat Protection
6 hours- Understanding the OWASP Top 10 for LLMs
- Defending against prompt injection and jailbreaks
- Detecting and preventing data poisoning and model inversion
- Implementing input validation and sanitisation pipelines
- Using content safety services and prompt shields
Module 5: Security Operations & Response
6 hours- Configuring Microsoft Sentinel for cloud/AI telemetry
- Creating analytics rules and playbooks for AI incidents
- Integrating Defender for Cloud alerts and recommendations
- Automating response with Logic Apps and Azure Functions
- Reporting and compliance dashboards for APPs and ISO audits
Who Should Attend
- Cloud security engineers and architects
- AI/ML security specialists
- DevSecOps and platform engineers
- Security operations centre (SOC) analysts
- IT leaders responsible for cloud and AI governance
- SC-500 exam candidates and auditors
Prerequisites
Before enrolling, please ensure you meet these requirements:
- • Strong Azure fundamentals (AZ-900 or equivalent)
- • Experience with Entra ID, networking and security concepts
- • Familiarity with scripting (PowerShell/Bash) and infrastructure as code
- • Basic understanding of machine learning lifecycle concepts
- • Access to an Azure subscription with appropriate permissions
Delivery, Format and Logistics
Delivery Mode
Live online with hands-on labs
Maximum 12 participants to allow deep technical lab work
What You'll Need
- Computer with modern web browser and administrative access
- Active Microsoft Azure subscription (pay-as-you-go or sponsorship)
- Visual Studio Code or preferred IDE installed
- Reliable internet connection (minimum 20 Mbps)
- Experience with PowerShell or Bash scripting
- Familiarity with Azure portal and CLI
- Background in cloud networking and security concepts
What You'll Receive
- 36 hours of instructor-led training across 4–5 weeks
- Intensive labs in a controlled Azure environment
- Comprehensive course workbook and security templates
- Exam-style scenarios and practice questions for SC-500
- Access to security checklists and compliance guides
- Certificate of completion
- 12 months access to course materials
Frequently Asked Questions
Not Ready to Enrol?
Join our mailing list to receive updates about courses, resources, and cybersecurity insights tailored for Australian organisations.
Early-bird rate — apply your promo code at checkout.
Secure payment via Stripe · Promo codes accepted
Next Intake
September 2026 — register your interest at educ4te.com
Format
Live online with hands-on labs
Group & Enterprise Options
Discounted rates available for teams of 3+ delegates. Contact us for in-house delivery options.
What's Included
- 36 hours of instructor-led training across 4–5 weeks
- Intensive labs in a controlled Azure environment
- Comprehensive course workbook and security templates
- Exam-style scenarios and practice questions for SC-500
- Access to security checklists and compliance guides
- Certificate of completion
- 12 months access to course materials
Have questions about this course?