Zum Inhalt springen

FieldsCybersecurityAI Security Engineer

AI Security Engineer

Secure AI systems against adversarial attacks, injection, and misuse.

Career

Structure
8 modules, each ending in a milestone
Proof
Verified against real tasks from module 2
Ends in
A defended capstone and a high-assurance credential

Get early access

The journey

  1. Practised under observation

    1. AI systems as an attack surfaceWhat is actually being defended: model and application mechanics understood well enough to attack them, and the reason AI security is a distinct discipline rather than an application of the old one.Practised under observation
      MilestoneMaps the AI attack surface

      The architecture is explained mechanically rather than by diagram, the exact place untrusted content reaches the model is pointed at, and the ordinary way in is named alongside the clever one.

  2. From here, milestones are verified rather than practised.

    Verified against a real task

    1. Prompt injection and the input attack surfaceThe field's defining vulnerability, understood mechanically, defended in layers, and measured honestly against the residual risk that cannot be removed.Verified against a real task
      MilestoneInjection defended, measured, and honestly reported

      Injection defences are reported as a rate you measured over a sample you can state, and nothing you write claims the problem is solved.

    2. Securing agents, tools and autonomous actionWhere AI security stops being about words: agents hold credentials and take real actions, so the defence is architectural before it is behavioural.Verified against a real task
      MilestoneBlast radius first, behavior second

      Assume the model is fully compromised and the agent still cannot reach what matters, the limits that hold are deterministic rather than persuasive, and the capability that was tempting to grant is the one you took back.

    3. Model and data attacksAttacks on the model itself, understood mechanically, defended where a defence exists and detected where one does not.Verified against a real task
      MilestoneModel attacks understood, defended, detected

      A model gives up less than it did and you can say how much less, and a query never returns content the person asking is not allowed to see.

    4. AI supply chain and infrastructure securityEverything the system depends on, with models, datasets, frameworks and providers treated as a supply chain and the surrounding infrastructure held to conventional standard.Verified against a real task
      MilestoneSupply chain verified, infrastructure held

      Every dependency has a provenance you checked, including the one that runs code the moment it is loaded, and what leaves the organisation for a provider is stated along with what you refused to send.

    5. Red-teaming AI systemsAttacking the system properly: structured adversarial assessment, conducted ethically, measured honestly, and converted into defences.Verified against a real task
      MilestoneRed-teams properly, reports honestly

      Authorisation and scope are on paper before anything runs, a finding says how often it works and over how many attempts rather than showing it once, and the impressive result that cannot hurt anyone is marked down.

    6. Securing the AI system lifecycleSecurity engineered into how AI systems are built and run, with requirements at design, gates before release, and monitoring for attacks in production.Verified against a real task
      MilestoneLifecycle secured, attacks visible

      A release is stopped when the adversarial evaluation says so, and a provider's new model version is treated as a security event rather than as an upgrade.

    7. The AI Security Engineer in the organizationThe newest seat in security, working with builders who are moving fast: credibility without alarmism, and the discipline to say what is and is not known.Verified against a real task
      MilestoneCalibrated, credible, and shipping with builders

      The problem nobody has solved is described as unsolved rather than covered by an invented control, and a decision-maker who wanted certainty leaves able to make a real choice.

    1. Capstone

      An AI system that holds under attack

      A complete AI security engagement on a realistic AI application or agentic system, proposed by you and approved by an instructor, worked under observation on authorised targets throughout, from the attack-surface map through layered injection defence, blast-radius engineering, model and supply-chain work and a structured red-team engagement to the lifecycle and organisational layers of the seat.

      Defence

      You walk an instructor through your own system: where untrusted content reaches the model and what still holds when it does, your attack success rate and the sample behind it, what the agent can still do if the model is fully compromised, and which problem here is genuinely unsolved. The credential is not awarded if you cannot account for your own work.

    2. Credential

      High-assurance credential

      Evidence that you can secure an AI system so it holds under adversarial pressure, and state honestly what it still does not stop. It does not claim seniority, and it does not oblige any employer to accept it.

      See how proof works

What is not live yet

The desktop app, consent-based observation, scoring, and credentials are in development. Nothing here implies they are live yet.

Get early access