Harden AI before attackers do.
Threat-model, test, and harden AI applications against prompt injection, data leakage, unsafe tools, and supply-chain risk.

- In planning
- No launch date is promised
- Remote-first
- Proposed delivery format
- Practical proof
- Capstone-led curriculum design
- Interest only
- Not an internship application
Why this belongs on the roadmap.
Security roles remain among the fastest-growing categories, while NIST identifies secure and resilient behavior as a core characteristic of trustworthy AI. This track is planned as hands-on engineering, not policy-only awareness.
Research sources support the direction, not a launch date or outcome. This page does not promise a job, salary, client, income, or final curriculum.
The work this curriculum would cover.
Each planned module is designed to produce evidence, moving from foundations to work a real operator can inspect.
- 01Map assets, trust boundaries, attackers, and likely misuse
- 02Test prompt injection, indirect injection, and data exfiltration
- 03Secure tool permissions, secrets, identity, and tenant boundaries
- 04Review model, data, dependency, and deployment supply chains
- 05Build security evaluations and release gates in CI
- 06Respond to an AI security incident and document remediation
The proof this track would demand.
A security assessment and hardened release of a real AI application, with a threat model, repeatable attack suite, fixed findings, CI security gates, an incident exercise, and a clear remediation report.

The working stack.
Tools can change before launch. The proposed workflow and quality bar are the durable part.
- OWASP guidance
- PyRIT
- Garak
- Semgrep
- OWASP ZAP
- GitHub Actions
- A cloud sandbox
Register interest in this track.
Join the track-specific waitlist. This is separate from the internship intake waitlist and does not submit an application.