AI Security Engineer Track
AI security is the fastest-growing area in security job ads: in 2026 about 30% of cybersecurity postings asked for AI skills, double the year before. The role sits between application security and cloud security: securing products built on language models and agents, and the tools engineers use every day. This track takes you from prompt injection to agent design to interview-ready threat models.
Last verified2026-10
Getting certified
Last verified2026-10
Interviewers care far more about whether you can threat-model an agent than about a credential.
Launched in 2025 for security managers. You can sit the exam first, but the certification is only awarded to holders of an active CISM or CISSP. It covers AI governance, risk and controls.
Governance- and privacy-focused, popular in legal and compliance-heavy organisations.
A threat model of a real agent, a write-up of an MCP server review, or a small red-team harness for a chatbot is stronger evidence than any of these.
Part 1 — How language-model applications fail
- Prompt injection — direct and indirect, and why it can't be fully fixed
- Sensitive information disclosure
- Improper output handling — model output into SQL, shells and HTML
- Excessive agency — what an injection cashes out into
- Vector and embedding weaknesses — RAG access control
- Supply chain and model poisoning — pickled models, poisoned datasets
Part 2 — Agents and MCP
- What an agent is — the loop and where untrusted text enters
- The Model Context Protocol — hosts, clients, servers, tool descriptions
- OWASP Agentic Top 10 and the lethal trifecta
- Tool poisoning and rug pulls
- Toxic agent flows — the GitHub MCP case
- Designing a safer agent — identity, pinning, sandboxing, approval, logging
Part 3 — The security engineering underneath
- Threat modelling — the method every AI design review uses
- Worked example: a coding agent
- OAuth integrations — agents act through tokens like any integration
- Software supply chain — MCP servers and model files are dependencies
- Secrets in pipelines — where agent credentials leak from
- Detection engineering — turning tool-call logs into alerts
Part 4 — Attackers using AI
- Agents used by attackers — GTG-1002 and what speed changes
- Vulnerability management — shrinking time from disclosure to exploitation
- Phishing triage — AI-written lures and deepfake pretexts
- AI interview questions — rehearse all seven out loud