Assess internet-facing technologies and external attack surfaces, including web applications, APIs, exposed services, authentication mechanisms, WAFs, DDoS protections, DNS, certificates, ingress architectures, and external connectivity. Strong working knowledge of cloud security architecture, including IAM, networking, data protection, workload security, logging/monitoring, encryption, and shared-responsibility models (AWS, Azure, and/or GCP).