AI Threat Modeling
Map attack surfaces across prompts, RAG, memory, tools, identity, MCP servers, model providers, orchestration, and external APIs using OWASP, MITRE ATLAS, and NIST AI RMF.
Become an AI Security Engineer in 5 Weeks
Live (Zoom) • Advanced • 💎 15000
Part of AI Career Accelerator
The most in-demand AI job right now. Companies deploying autonomous AI agents need someone to secure them.

Prerequisites
Completed AI Testing Course
Requirements
YAML, Git, Terminal and APIs
Duration
5 Weeks (Weekend sessions)
Format
Live, Hands-On Training
Upcoming
Start Date: September 12, 2026
End Date: October 11, 2026
Duration: 5 Weeks
Format: Interactive live Zoom sessions
Pricing
$2,497
$2,997
Early bird price until July 31
or Buy Now, Pay Later with (only for United States)
by paying, you agree to the Terms & Conditions
Course Schedule (PDT)
September 12
Saturday
10:00 AM - 2:00 PM
September 13
Sunday
10:00 AM - 2:00 PM
September 19
Saturday
10:00 AM - 2:00 PM
September 20
Sunday
10:00 AM - 2:00 PM
September 26
Saturday
10:00 AM - 2:00 PM
September 27
Sunday
10:00 AM - 2:00 PM
October 3
Saturday
10:00 AM - 2:00 PM
October 4
Sunday
10:00 AM - 2:00 PM
October 10
Saturday
10:00 AM - 2:00 PM
October 11
Sunday
10:00 AM - 2:00 PM
“I know how to test LLMs… but real AI security feels different.”
→ This cohort bridges that gap.
Break Into AI Testing gave you the foundation. You learned how to test LLM outputs, run Promptfoo evals, detect hallucinations, red team prompts, and report AI defects.
The AI Security Engineer cohort takes you to the next level.
You will scope an authorized AI security engagement, connect an assessment harness to a real target, run adaptive multi-turn attacks, verify and reproduce real vulnerabilities, and package confirmed findings into evidence-backed reports and permanent CI regression controls.
This is where you learn to secure the full AI system – not just probe the model response.

This cohort is different because you will run a complete, authorized AI security engagement from start to finish. You will not just test prompts. You will work with:
Master the modern stack of AI Quality Engineering.
Map attack surfaces across prompts, RAG, memory, tools, identity, MCP servers, model providers, orchestration, and external APIs using OWASP, MITRE ATLAS, and NIST AI RMF.
Translate a client's business, architecture, and risk priorities into an authorized test plan with scope, boundaries, budget, kill switches, and escalation contacts.
Engineer target-specific Promptfoo cases, plugins, strategies, assertions, graders, skip logic, dual-grader evaluation, and run manifests for AI security assessments.
Test prompt injection, indirect injection, goal hijacking, retrieval poisoning, unsafe tool use, privilege escalation, excessive agency, and identity failures across agents and MCP workflows.
Run controlled multi-turn and sequential red-team episodes that learn from previous responses while staying inside the Rules of Engagement.
Reproduce candidate issues, use multiple graders, challenge findings independently, and package confirmed vulnerabilities with trace evidence, confidence, and AIVSS context.
Convert confirmed vulnerabilities into deterministic Promptfoo regression cases and promote them through human review into CI deploy, change, scheduled, or manual trigger policies.
Generate client-ready assurance reports that separate prepared/static coverage from autonomous agentic discovery, and present findings to both engineering and business stakeholders.
Test retrieval poisoning, document-based prompt injection, data exfiltration, bad citations, groundedness failures, and vector database access controls.

CEO and Founder
Igor is an accomplished CEO and Founder of Engenious.io, with 15+ years of experience in software testing and development and over a decade in management. He has worked at Barnes & Noble, Expedia, Tinder, and consulted at Apple and Grammarly. In the mentorship program, Igor offers expertise in building a testing process from scratch, leadership success, understanding C-level executives' expectations, selecting the right technology stack, providing and collecting feedback, and team growth. Mentees benefit from Igor's insights on creating efficient testing processes, fostering productive teams, aligning with executive priorities, making informed technology choices, establishing feedback channels, and securing resources for team development. With Igor as their mentor, participants gain valuable knowledge, skills, and perspectives to excel as Dev/QA Directors or Managers.

Quality Engineering Manager
Seasoned IT professional with 14+ years of experience in Software Engineering, Quality Assurance, and Automation. Skilled in leading teams, designing test strategies, and building automation frameworks across diverse industries. Adept at leveraging modern tools, AI-driven testing approaches, and cloud technologies to deliver high-quality, scalable solutions. Holds a Bachelor’s in Management Information Systems and a Master’s in Information Technology with proven success supporting enterprise-level clients and Fortune 500 companies.

Senior iOS Engineer to Co-Founder & CTO·WeOptimize.ai
Vladimir is an experienced engineer with 8+ years in iOS/macOS development, specializing in AI-powered solutions. As the Co-Founder & CTO of WeOptimize.ai, he leverages AI to optimize workflows and enhance productivity. He has a track record of delivering innovative products for both startups and large enterprises.

Software Engineer
10 years of experience in the tech industry; Senior Android Engineer in Platform team. Expert in CI/CD pipelines, test automation, and mobile infrastructure; passionate about developer productivity and workflow optimization.

Award Winning Leader in Quality Assurance
Visionary QA Leader with substantial experience in the IT industry. Worked across Salesforce, Sony, and now as part of Video Engineering and Quality Assurance, he leads the strategy for high-concurrency streaming environments, where a single second of latency is unacceptable.
You will not start from a blank screen and you will never test real production systems. During the cohort, you will work with authorized sandbox and staging targets that may include:
01
Week
Day 1: AI Security Threat Modeling Theme
Theme: Move from AI quality defects to security impact and abuse paths.
Theory: OWASP LLM Top 10 2025, OWASP Agentic Top 10 2026, MITRE ATLAS, and NIST AI RMF. Trust boundary modeling across model, prompt, RAG, memory, tools, identity, orchestration, MCP, and external systems.
Hands-on: Threat-model an agentic application and identify highest-value attack paths.
End-of-Day Deliverable: Target attack-surface map and prioritized threat hypotheses.
Day 2: Client Discovery, Rules of Engagement & Evidence Design
Theme: Ask the right questions before you run a single test.
Theory: In-scope and out-of-scope systems, staging boundaries, test windows, budgets, kill switches, escalation contacts, and prohibited actions. Creating canaries and success criteria.
Hands-on: Convert a completed questionnaire into a provider config, assessment plan, attacker profile, and signed-lab Rules of Engagement.
End-of-Day Deliverable: Approved intake package and evidence plan.
02
Week
Day 3: Connecting to LLM Applications and Agents
Theme: Establish a reliable, traceable connection to the target before any attack.
Theory: Connection patterns for HTTP APIs, CLI targets, MCP-connected systems, and custom Promptfoo providers. Authentication, environment variables, request/response extraction, rate limits, and tracing.
Hands-on: Connect the assessment harness to a sandbox agent and pass a smoke test.
End-of-Day Deliverable: Working provider adapter with connection and trace evidence.
Day 4: Advanced Promptfoo Security Engineering
Theme: Build an assessment suite that targets this system specifically.
Theory: Target-specific cases, plugins, strategies, assertions, rubrics, deterministic checks, dual-grader evaluation, false-positive controls, budgets, concurrency, and run manifests.
Hands-on: Prepare a full configured Promptfoo assessment for the target.
End-of-Day Deliverable: Reviewed assessment plan and executable Promptfoo suite.
03
Week
Day 5: Agentic Attack Surfaces
Theme: Test the system where agents make decisions, use tools, and take actions.
Theory: Direct and indirect prompt injection, goal hijacking, context manipulation, retrieval poisoning, data exfiltration, excessive agency, unsafe tool use, privilege escalation. MCP server, plugin, vector-store, memory-poisoning, and multi-agent trust risks.
Hands-on: Attack an agent with RAG, memory, and tools through multiple trust boundaries.
End-of-Day Deliverable: Attack matrix mapped to business impact and expected controls.
Day 6: Sequential and Automated Red Teaming
Theme: Run adaptive attacks that learn from previous responses.
Theory: Explore-versus-exploit planning, strategy registers, session journals, and open candidate tracking. Promptfoo multi-turn strategies, PyRIT, and garak for complementary coverage.
Hands-on: Run a bounded adaptive episode and open candidate findings.
End-of-Day Deliverable: Traceable attacker episode, memory update, and candidate register.
04
Week
Day 7: Verification, Refutation & Scoring
Theme: A strange output is not a finding. Prove it.
Theory: Reproduce candidate behavior at least three times. Use deterministic checks and model graders without self-grading. Run an independent adversarial validation pass. Apply OWASP AIVSS-Agentic context per confirmed finding.
Hands-on: Confirm or reject a candidate finding package with full evidence and disposition.
End-of-Day Deliverable: Confirmed or rejected finding package with evidence.
Day 8: Regression Generation & CI Policy
Theme: Make confirmed findings permanent and testable.
Theory: Convert a confirmed vulnerability into a reusable Promptfoo regression case. Human approval workflow.
Execution triggers: deployment, material change, scheduled, and on-demand. Release thresholds, ownership, rollback, and escalation.
Hands-on: Promote one approved finding into a staging CI gate and prove the fixed behavior.
End-of-Day Deliverable: Generated case, approval record, CI policy, and passing retest.
05
Week
Day 9: Reporting, Remediation & Client Communication
Theme: Communicate risk clearly to engineers and executives.
Theory: Separate prepared/static coverage from autonomous agentic discovery. Report assurance status, scope, target build, time window, methodology, open findings, peak AIVSS, suite results, and regression state. Client readout structure.
Hands-on: Write an executive finding and technical remediation handoff.
End-of-Day Deliverable: Shareable assurance report and technical remediation handoff.
Day 10: Capstone Audit and Professional Defense
Theme: Run a complete engagement and defend every decision.
Execution: Teams run the full assessment on an authorized staging target. Each student defends scope decisions, test selection, evidence quality, scoring, remediation, and CI behavior. Peer refuters challenge the strongest finding.
Career: Portfolio narrative, resume bullets, LinkedIn proof-of-work post, role-specific interview questions.
End-of-Day Deliverable: Complete audit package and live client-style walkthrough.
By the end of the cohort, you will have a complete AI security assessment portfolio you can show, explain, and defend in interviews.
Lifetime Community Access
Recorded Sessions

macOS:
Processor: Apple Silicon M1, M2, M3 or M4
Memory: 16 GB RAM (or higher)
Storage: 30 GB free SSD space
Note: Mac OS systems without an M chip are not supported
Windows:
Processor: Intel Core i5 / i7 or AMD Ryzen 5 / 7
Memory: 16 GB RAM (or higher)
GPU: Dedicated GPU with ≥ 6 GB VRAM (e.g., NVIDIA RTX 2060 / 3060)
Storage: 30 GB free SSD space
Yes. The final part of the course focuses on communicating like an AI Quality Engineer. Students prepare a portfolio presentation, practice explaining findings to non-technical stakeholders, review how to talk about the project in interviews, and refine LinkedIn and portfolio positioning.
The goal is for students to leave with practical experience and concrete artifacts they can confidently discuss in career conversations.
A candidate finding must reproduce under defined conditions, pass more than one evaluation method, survive an independent challenge, and include full trace evidence before it can be reported as confirmed. Reporting an unverified candidate as a confirmed vulnerability is an automatic failure condition.
Yes. The final project is the Final AI Quality Audit Portfolio. Students present the system they tested, explain what they built or extended, summarize what they evaluated, share the most important risks they found, show what observability revealed, recommend controls, make a release readiness decision, and share key lessons learned.
The course follows a clear 5-week structure:
Week 1 — Scope the system (threat modeling, rules of engagement)
Week 2 — Connect and engineer the assessment harness
Week 3 — Attack agentic systems adaptively
Week 4 — Verify findings and make them permanent
Week 5 — Report, remediate, and defend the capstone
This structure helps students move through the same workflow used in professional AI quality engineering: understand the system, test the behavior, document the risk, and communicate the findings.
The first course teaches the foundations of AI and LLM testing — prompt testing, assertions, Promptfoo, red teaming concepts, bug reporting, and career positioning.
This advanced cohort focuses on professional AI security engagements. Students learn to scope an authorized assessment, connect an evaluation harness to a real target, threat-model agentic attack surfaces, run adaptive multi-turn red teaming, verify and reproduce real vulnerabilities, communicate risk to stakeholders, and convert confirmed findings into CI regression protection.
Click the link below this FAQ to apply for the next cohort.
Submit your application and confirm your eligibility — only 30 seats per Advanced cohort are available. Early applicants receive priority for personalized feedback and project pairing.
The training is a 5-week long training. It includes 10 lectures (40 hours). Classes are held on weekends, Saturdays and Sundays from 10.00 am to 2.00 pm PST
Yes, currently available for U.S. applicants and can be available in other regions for USD payments.
During checkout, you can select a payment plan through Stripe’s Klarna interface, allowing you to spread tuition into manageable installments.
Yes, for the AI Security Engineer bootcamp you have to either:
- Finish the "Break Into AI Testing" Bootcamp
OR
-Have AI Testing experience of a minimum 6 months
You must be comfortable with the command line, YAML/JSON, Git, and APIs.
Students follow a professional engagement process: scope the system, attack it adaptively, prove the findings, and convert confirmed vulnerabilities into CI regression protection.
💻 Windows
✅ Windows 10 (64-bit) or newer
✅ Intel i5 (8th Gen +) / AMD Ryzen 5 +
✅ 16 GB RAM (or higher)
✅ 30 GB free storage (SSD)
✅ Node.js v18+, Python 3.8+, VS Code, Git (Docker optional)
✅ Chrome or Edge browser
✅ Stable 10 Mbps+ internet + webcam
🍏 macOS: macOS Monterey (12+) or newer
✅ Apple M1/M2/M3/M4 chip
✅ 16 GB RAM (or higher)
✅ 30 GB free storage
✅ Homebrew, Node.js v18+, Python 3.8+, Docker (optional)
✅ Chrome or Safari browser
✅ Reliable 10 Mbps+ connection + webcam
💡 Tip: Dual-monitor setups improve productivity for labs and evaluations.
The goal is to help students move from AI testing fundamentals to running a complete, authorized AI security assessment.
Students follow a professional engagement process: Scope the system. Attack it adaptively. Prove the findings. Protect against regression.
By the end, students will be able to threat-model LLM, RAG, MCP, tool, memory, and agentic attack surfaces; engineer and execute adversarial test suites; verify and score real vulnerabilities; and communicate findings to both technical and business stakeholders.
This course is for students who already understand the basics of AI testing and want to move into AI security and assurance. It is a strong next step for graduates of the Engenious University "Break Into AI Testing" course, QA engineers, SDETs, automation engineers, and security testers who want hands-on experience securing deployed AI systems.
This course can support students preparing for roles or responsibilities related to:
The course is especially useful for professionals who want to show proof that they can test more than simple prompts. Students learn to evaluate deployed AI systems across architecture, API behavior, RAG, tool calling, red teaming, observability, and risk.
Promptfoo is the primary assessment and regression framework. Students also work with PyRIT, garak, Langfuse-style observability and tracing, Git-based review workflows, and CI/CD pipelines. The exact tools may vary by cohort, but the goal is consistent: students learn to audit a real AI system using a professional security engagement process.
Yes, our main requirement is to complete our "Break Into AI Testing Bootcamp" first.
Students who completed the first Engenious University AI Testing course are prepared because the advanced cohort builds on a foundation in AI testing, LLM behavior, prompt evaluation, hallucination testing, and red teaming basics.
But if you already have experience in using Prompfoo, red-teaming and LLM Evaluation and want to jump straight into Advanced AI Quality Engineers – please book a call with us!
Prior security experience is helpful but not mandatory. You must be comfortable with QA fundamentals and ready to work with threat modeling, authorization boundaries, identity, secrets, cloud controls, and evidence handling. You will also need to be comfortable in the command line, with YAML/JSON, Git, APIs, and modifying small Python or JavaScript scripts.
No. All exercises require explicit authorization and use approved staging or intentionally vulnerable targets. Real customer data is never part of a student lab.
Still have questions?
Not sure if this program is right for you? Need help choosing the best path or want to understand the curriculum better
We are here to help – just drop us a message and we will respond same day.
MESSAGE USScope it
Attack it
Prove it
Protect it.
That is the operating process of an AI security practitioner – and what you will practice in every session of this cohort.
Ready to Become an ?
If you completed Break Into AI Testing and want to move into AI security and assurance, this is your next step. Join the AI Security Engineer cohort and learn how to scope, red team, and protect real AI systems.