Prerequisite course

Security AI Engineering.

How to engineer, govern and account for AI inside authorized client testing. Written for people who already know offensive security — it teaches the engineering discipline around the models, not the security fundamentals underneath.
  • 12 modules
  • A lab artifact per module
  • Completion record only
  • Not a certification

Read this first

Course completion is not certification. Finishing this course produces a completion record with its own identifier and its own expiry, clearly marked as not being SA-APEX. Certification comes from the independent performance exam, and plenty of people who complete the course will not pass it.

Anyone presenting a course completion as a certification is misrepresenting it, and we will say so publicly if asked.

Scope

What this course does not teach.

  • Excluded:Penetration testing.
  • Excluded:Red teaming.
  • Excluded:Programming fundamentals.
  • Excluded:Vulnerability scanning.
  • Excluded:How to copy prompts.

You are expected to arrive able to run the engagement. What most experienced testers have not done is build the governed system around a model — the classification, the gateway, the isolation, the evidence chain and the audit trail that make AI use defensible on a real client.

That is the entire subject of this course.

Learning outcomes

What you will be able to do afterwards.

  • Included:Classify engagement data and choose an allowed AI deployment from sensitivity, contract, geography, retention and provider terms.
  • Included:Build a model gateway that enforces provider allowlists, redaction, tenancy, retention, logging, budgets and an emergency shutdown.
  • Included:Design agents with narrow roles, least-privilege tools, explicit inputs and outputs, and bounded execution.
  • Included:Create retrieval and context pipelines that preserve provenance and cannot contaminate one client with another.
  • Included:Use AI for hypothesis generation, code navigation, test creation, payload mutation, exploit assistance and reporting while keeping a human accountable for the result.
  • Included:Measure precision, recall proxies, validation yield, duplicate rate, evidence sufficiency and critical-coverage gaps.
  • Included:Detect hallucinations, prompt injection, poisoned context, tool misuse and confident-but-unproven findings.
  • Included:Build evidence-linked reports and run completeness reviews that do not simply ask the same model whether it was right.

Curriculum

Twelve modules. Each one ends with something you built.

Course modules and required lab artifacts
#ModuleScopeRequired lab artifact
1AI systems for offensive engineersTokens, context, inference, embeddings, retrieval, agents, tools, deterministic code, model limits, threat model.Architecture comparison and failure analysis.
2Client-data classificationPublic, internal, confidential, restricted, regulated, secrets, exploit artifacts and prohibited data.Engagement data-handling plan.
3Private model patternsLocal inference, dedicated deployments, contractual APIs, zero-retention modes, regional controls, air-gapped options.Deployment decision record with threat model.
4Secure model gatewayAuthentication, authorization, policy, tokenization, DLP, redaction, tenant keys, logging, rate and budget limits, kill switch.Working gateway policy and leakage tests.
5Context and retrieval engineeringChunking, source integrity, isolation, provenance, freshness, injection resistance, selective disclosure.Client-isolated retrieval pipeline.
6Agent and tool designRole decomposition, least agency, tool schemas, safe defaults, sandboxing, scope enforcement, concurrency.Two specialized agents with controlled tools.
7AI-assisted code auditTrust-boundary mapping, data flow, state transitions, authorization, business logic, unsafe composition, variant analysis.Novel defect hypothesis and trace package.
8Exploit engineering with AIHarness generation, mutation, debugging, differential testing, safe proof construction, human code review.Candidate-explained proof of concept and negative controls.
9False-positive engineeringEvidence gates, independent reproduction, counterexamples, consensus limits, deterministic validators, confidence calibration.Evaluation set and precision report.
10Coverage and criticalityAttack-surface inventory, test obligation graph, uncovered paths, stop rules, critical miss review.Coverage ledger and residual-risk statement.
11AI-assisted reportingEvidence-to-finding pipeline, templates, citations, severity, remediation, executive translation, fact locking.Generated report with a validation manifest.
12Operations and incident responseMonitoring, prompt and tool audit, leakage response, revocation, evidence retention, model version change control.AI security incident tabletop.

Labs are assessed for safe architecture, reproducibility, data handling, code quality, evidence quality and candid treatment of limitations. An artifact that hides what did not work scores worse than one that names it.

After the course

The course is step three of eight.

Completion feeds the practice range, which produces readiness evidence, which is what schedules an exam. There is no route from “finished the modules” straight to a credential, and the platform will not create one.

Course pricing is not set. It will be published — like every other price on this site — once delivery cost, eligibility review and support are known. See the open decision log.