AI Security Engineer
Secure applications built on large language models: find prompt injection, data leakage and unsafe tool use before attackers do.
One of the fastest-growing security specialisms as companies ship LLM features and agents.
Day to day
- •Red-team LLM features before release
- •Design guardrails and tool permissions
- •Review agent architectures for data exposure
- •Write findings engineers can act on
Start from: Some programming and basic security knowledge
Loading your lab progress…
- 1
Security and web foundations
4–6 weeksUnderstand how web applications are attacked and defended.
HTTP, APIs and authentication
Every LLM feature is reached through an API; most real breaches start with auth mistakes.
OWASP Top 10 for web
The shared vocabulary for application risk that security reviews are written in.
Python scripting
Automating test cases and calling model APIs is daily work.
Certifications
- CompTIA Security+ · CompTIA
Portfolio project
Find and write up three vulnerabilities in a deliberately vulnerable web app, with reproduction steps and fixes.
- 2
How LLM applications work
3–4 weeksBuild with model APIs so you understand what you will later attack.
Prompting and system prompts
Injection is an attack on instructions; you need to know how instructions are layered.
Tool use and agents
Tools turn a text bug into a real action like sending email or reading files.
Retrieval-augmented generation
Retrieved documents are an indirect injection path most teams overlook.
Certifications
- Claude Certified Associate – Foundations · AnthropicPractise
Portfolio project
Build a small RAG assistant with one tool, then document every place untrusted text enters the model.
- 3
Attacking LLM applications
4–6 weeksRun adversarial tests and turn results into evidence.
OWASP Top 10 for LLM applications
The reference list clients and auditors ask you to test against.
Direct and indirect prompt injection
The most common and most damaging LLM vulnerability class.
Data exfiltration and system prompt leakage
Leaked context is often the finding with the biggest business impact.
Certifications
No certification needed here. Your project is the proof.
Portfolio project
Red-team your own RAG assistant: a report with severity, evidence, and a regression test for each finding.
- 4
Defence and architecture
4 weeksDesign systems that fail safely, and prove it.
Least-privilege tool design
Limiting what a tool can do caps the damage of any injection that succeeds.
Human-in-the-loop controls
Consequential actions need approval gates that attackers cannot talk their way past.
Evaluation and regression testing
A fix without a test comes back in the next release.
Certifications
- Claude Certified Architect – Foundations · AnthropicPractise
Portfolio project
Harden the assistant: permissions, approval gates and an eval suite that fails the build when an old attack works again.
Finish line
Prove you're ready to apply
20 workplace scenarios. Reach 80% with no area below 60% for a job-ready signal.
Take the readiness exam
Certification requirements, prices and exam formats change. Always confirm on the issuer's site, linked from the certifications page.