✈️ We’re flying at least two interns to Sarajevo this October (all expenses paid + a friend)! Learn more (opens in a new tab) | Already an intern? Read announcement (opens in a new tab)

In planningAI Security Engineering

Harden AI before attackers do.

Threat-model, test, and harden AI applications against prompt injection, data leakage, unsafe tools, and supply-chain risk.

No confirmation email is sent. We store your email only for updates about AI Security Engineering. Read our privacy policy.

Editorial concept for the planned AI Security Engineering curriculum
Concept artwork for a curriculum still being researched and scoped.
In planning
No launch date is promised
Remote-first
Proposed delivery format
Practical proof
Capstone-led curriculum design
Interest only
Not an internship application

Why this belongs on the roadmap.

Security roles remain among the fastest-growing categories, while NIST identifies secure and resilient behavior as a core characteristic of trustworthy AI. This track is planned as hands-on engineering, not policy-only awareness.

Research sources support the direction, not a launch date or outcome. This page does not promise a job, salary, client, income, or final curriculum.

The work this curriculum would cover.

Each planned module is designed to produce evidence, moving from foundations to work a real operator can inspect.

  1. 01Map assets, trust boundaries, attackers, and likely misuse
  2. 02Test prompt injection, indirect injection, and data exfiltration
  3. 03Secure tool permissions, secrets, identity, and tenant boundaries
  4. 04Review model, data, dependency, and deployment supply chains
  5. 05Build security evaluations and release gates in CI
  6. 06Respond to an AI security incident and document remediation

The proof this track would demand.

A security assessment and hardened release of a real AI application, with a threat model, repeatable attack suite, fixed findings, CI security gates, an incident exercise, and a clear remediation report.

The planned capstone centers inspectable work, not a tool-completion badge.

The working stack.

Tools can change before launch. The proposed workflow and quality bar are the durable part.

  • OWASP guidance
  • PyRIT
  • Garak
  • Semgrep
  • OWASP ZAP
  • GitHub Actions
  • A cloud sandbox
In planning

Register interest in this track.

Join the track-specific waitlist. This is separate from the internship intake waitlist and does not submit an application.

No confirmation email is sent. We store your email only for updates about AI Security Engineering. Read our privacy policy.

Back to future tracks