July 25, 2026
How to Beat Vendor Lock-In for Cloud and AI Security:
As an educator, the hardest challenge is creating a starting point that works for everyone. Across my career, I’ve secured environments…
By Zachary Marcy
1 min read
How to Beat Vendor Lock-In for Cloud and AI Security:
As an educator, the hardest challenge is creating a starting point that works for everyone. Across my career, I've secured environments across AWS, Azure, Google Cloud, Akamai, DigitalOcean, and OCI.
Here is the exact 5-step roadmap I recommend to build portable, vendor-agnostic cloud security expertise without getting stuck in a single ecosystem:
5-Step Roadmap to Multicloud Security Master One Foundation First: Pick a major provider (AWS, Azure, or GCP) to build your core engineering knowledge. Focus on how the cloud interacts with enterprise security as a whole.
Understand Services & Exploitation: Deep-dive into how core services operate, but focus heavily on how they get misconfigured and exploited. Always balance security controls with business needs and tech stacks.
Learn Native Defense & Monitoring: Master the logging, IAM, and monitoring tools specific to that environment.
Validate Knowledge & Build Proof:
Certifications: Earn both a foundational and a security certification to benchmark what you know against vendor standards.
Hands-on Projects: Build, secure, and publicly document end-to-end projects to prove your engineering and security capabilities.
Translate to the Next Cloud Provider: Pivot to a second provider (like Azure or Akamai) and map your existing security principles to the new ecosystem.
My Reality Check: AWS to Azure When I first jumped into Azure, I thought it would be smooth sailing because I already had experience with Microsoft Defender and Sentinel. Instead, I was hit with major culture shock. The interfaces, naming conventions (Blob is storage?!?!?), and deployment workflows were completely different from AWS and on-premises setups.
Taking the Azure Fundamentals certification was what finally bridged the gap for me. It forced me to map my existing mental model of cloud security onto Azure's specific framework.
The Bottom Line: Dashboards, names, and buttons will change from cloud to cloud — but core security principles don't. Build a rock-solid foundation in one, and you can defend anywhere.
About Zach Marcy | Cybersecurity, Cloud & AI Architect & Consultant | Creator of HackWithZach
Cybersecurity, Cloud & AI Architect, Consultant, and Mentor. 20+ years in IT. 6 in cybersecurity.
I am Zach Marcy. Online I go by HackWithZach. I am a Cybersecurity Architect, Consultant, and Mentor with 20+ years of IT experience and 6 in cybersecurity. My day-to-day work is designing and securing cloud environments that deploy and secure APIs and AI, and advising the teams that run them. HackWithZach is the project where I turn that work into education.
Cybersecurity Education That Gets You Hired, Promoted and Paid. That is the promise.
FREE GIVEAWAY: The 4 Pillars of AI Security (free PDF) https://hackwithzach.com/#capture
CLOUD & AI SECURITY ENGINEER COURSE: https://hackwithzach.com/foundations-course