Testimonials

Services

Video meeting . 30 mins
5
FREE
Priority DM . 3 days reply
FREE

About me

A Security Engineer and a Network enthusiast who always loves to work at massive scale with crazy amount of chaos. I generally spend time exploring Cloud Security, DevSecOps & Detection Engineering. I love Linux Kernel, especially Networking Subsystem, would always spend time exploring it whenever I find time. Would always use basic and fundamental ways of solving complex problems and a strong believer of "fundamentals first". Medium: https://medium.com/@hkoushik

Frequently asked questions

What is cloud security in cyber security?

Cloud security is the branch of cyber security focused on protecting data, applications, identities, and infrastructure running on cloud platforms like AWS, Azure, and GCP. It covers identity and access management, misconfiguration prevention, network controls, encryption, and continuous monitoring. Because of the shared responsibility model, the provider secures the underlying infrastructure while you are responsible for securing everything you build and configure on top of it.

What is a cloud security engineer, and how do you become one?

A cloud security engineer designs and maintains the security of cloud environments — hardening IAM, securing networks and workloads, automating guardrails through code, and responding to incidents. If you are exploring how to become a cloud security engineer, the usual path is mastering one major cloud platform first (compute, networking, IAM), then adding security depth through hands-on labs, a recognized certification, and real projects such as securing a complete cloud deployment end to end.

What is the cloud security engineer salary in India?

The cloud security engineer salary in India varies widely with experience, city, and company type. Entry-level roles typically start around ₹6–12 LPA, mid-level engineers with strong cloud and security skills often earn ₹15–30 LPA, and senior specialists at product companies can earn significantly more. Demonstrable cloud projects, DevSecOps skills, and one solid certification tend to push offers toward the higher end.

Do you need a cloud security certification, or are cloud security courses enough?

A cloud security certification helps you get shortlisted, while structured cloud security courses are how you actually build the skill. If you already know one cloud platform well, a vendor-specific security certification or a vendor-neutral credential adds credibility; if you are new, start with hands-on courses and labs, then certify once the concepts stick. Hiring teams generally value practical projects plus one strong certification over a long list of course completion badges.

How to run a cloud security scan on your own cloud environment?

If you are working out how to run a cloud security scan, start by inventorying every account and asset, then scan for misconfigurations — overly permissive IAM policies, public storage buckets, open security groups, and unencrypted data. Do a read-only pass first, triage findings by severity, fix the critical exposures, and schedule recurring scans in your CI/CD pipeline so new misconfigurations are caught continuously instead of during one-off audits.

What is cloud security posture management?

Cloud security posture management (CSPM) is the practice — and tooling category — of continuously checking cloud environments against security best practices and compliance benchmarks. CSPM tooling automatically detects issues like public storage, over-privileged identities, disabled logging, and insecure network rules, then helps prioritize and remediate them. It has become essential because most cloud breaches begin with a simple misconfiguration rather than a sophisticated attack.

What is DevSecOps?

DevSecOps is the practice of embedding security into every stage of the software delivery pipeline — design, code, build, test, deploy, and operate — instead of testing for security only at the end. In practice it means automated security scanning in CI/CD, infrastructure-as-code checks, secrets management, and giving developers security feedback as fast as they get build feedback. The goal is to make secure defaults the norm without slowing releases down.

What are DevSecOps tools?

DevSecOps tooling generally falls into a few categories: SAST, DAST, and software composition analysis scanners for code and dependencies, secrets detection tools, IaC and container image scanners, cloud security posture tools, and policy-as-code frameworks. Teams typically wire a handful of these into pipelines running on GitHub, GitLab, Azure DevOps, or AWS-native services, starting with dependency and secrets scanning since those catch the highest-impact issues earliest.

What is detection engineering in cyber security?

Detection engineering in cyber security is the discipline of designing, building, and tuning the detections that catch malicious activity — writing rules and analytics for SIEM and EDR tools, mapping coverage to attacker techniques, and continuously improving alert quality so real threats surface while noise stays low. It sits between threat intelligence and incident response, turning knowledge of attacker behavior into working, tested detection logic.

How to become a detection engineer in India?

Most detection engineers grow out of SOC analyst, system administration, or security operations roles, so getting close to logs and alerts is the best starting point. There is no standard degree for it — the practical answer to how to learn detection engineering is to study attacker behavior mapped to frameworks like MITRE ATT&CK, understand key log sources such as endpoint, identity, and cloud audit logs, and build real detection rules in a home lab using a free SIEM and open detection rule sets. Pair that with Python or SQL-style query skills, and you will have a portfolio hiring managers trust.

What is detection engineering with Sigma?

Detection engineering with Sigma means writing detection rules in Sigma, an open, vendor-neutral rule format that describes suspicious log events in a simple structured syntax. Because a single Sigma rule can be converted into queries for many different SIEM products, it lets you build a portable detection library instead of rewriting logic for every tool — which is why it is a common starting point for anyone learning to write quality detections.

What do detection engineering jobs involve day to day?

Detection engineering jobs involve writing and tuning detection rules, validating alert logic through investigation, closing coverage gaps for new attacker techniques, and working with SOC analysts to reduce false positives, along with improving logging across IT and cloud teams. Compensation is a common draw — the detection engineering salary generally sits above generic SOC analyst roles because the work combines security knowledge with genuine engineering and data skills.

Can you learn detection engineering on TryHackMe?

Yes — TryHackMe is a solid on-ramp because it offers guided paths for SIEM basics, log analysis, and attacker techniques in browser-based labs, so you don't need to build infrastructure before you start learning. Treat it as the foundation layer: once comfortable, move on to building your own detections in a personal SIEM lab and writing Sigma-style rules, since real detection engineering skill comes from creating and tuning rules against actual log data.

Which detection engineering books should I read?

Start with books that build the detection mindset — titles like The Practice of Network Security Monitoring, Crafting the InfoSec Playbook, and Data-Driven Security are commonly recommended for monitoring, alert design, and security data analysis. Since dedicated detection engineering books are still limited, round them out with Sigma rule documentation and real intrusion write-ups, then practice by writing detections against log samples in your own lab.

How to detect social engineering attacks before they succeed?

Watch for the classic signals: urgency, unusual requests for credentials or payments, sender addresses that look almost right, and pressure to bypass normal process. On the technical side, detection relies on layered controls — email authentication checks like SPF, DKIM, and DMARC, look-alike domain monitoring, and alerts for anomalous login or access behavior that often follows a successful phish. The human layer matters just as much, so verify unexpected requests through a second channel and make reporting suspicious messages effortless.