← All certifications

GIAC Cloud Security Automation (GCSA)

The Global Information Assurance Certification (GIAC), Cloud Security Automation (GCSA) is for professionals working with cloud services and modern DevSecOps practices used to securely build and deploy applications and systems. The GCSA is designed for such professionals as developers, software architects, operations engineers, system administrators, security analysts and engineers, risk managers and anyone working in a DevOps or public cloud environment. Candidates must pass a written exam.

We have a course for this

Built from this exam's published objectives. The first module is free.

What this qualifies you for

Listed specifically for 11 work roles — up to Advanced proficiency. Because options cascade downward, a cert listed at Advanced also satisfies Intermediate and Basic for that role.

541Vulnerability Assessment AnalystPerforms assessments of systems and networks within the NE or enclave and identifies where those systems/networks deviate from acceptable configurations, enclave policy, or local policy. Measures effectiveness of defense-in-depth architecture against known vulnerabilities.Intermediate611Authorizing Official/Designated Representative (AO/DR)Senior official or executive with the authority to formally assume responsibility for operating an information system at an acceptable level of risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation (CNSSI 4009).Advanced612Security Control AssessorConducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37).Intermediate622Secure Software AssessorAnalyzes the security of new or existing computer applications, software, or specialized utility programs and provides actionable results.Intermediate631Information Systems Security DeveloperDesigns, develops, tests, and evaluates information system security throughout the systems development lifecycle.Intermediate632Systems DeveloperDesigns, develops, tests, and evaluates information systems throughout the systems development lifecycle.Advanced641Systems Requirements PlannerConsults with customers to evaluate functional requirements and translate functional requirements into technical solutions.Advanced651Enterprise ArchitectDevelops and maintains business, systems, and information processes to support enterprise mission needs; develops information technology (IT) rules and requirements that describe baseline and target architectures.Advanced652Security ArchitectDesigns enterprise and systems security throughout the development lifecycle; translates technology and environmental conditions (e.g., law and regulation) into security designs and processes.Intermediate722Information Systems Security Manager (ISSM)Responsible for the cybersecurity of a program, organization, system, or enclave.Intermediate723Communications Security (COMSEC) ManagerManages the Communications Security (COMSEC) resources of an organization (CNSSI No. 4009).Advanced
Also listed for 14 Cyberspace Enablers roles — but so is every other certification

The Enablers matrix isn’t role-differentiated: the same certification options are listed for all 14 roles at every proficiency level. We verified that across all 14. So this is true, and it carries no information about this credential specifically — which is why it isn’t in the count above.