🎓 Part of the free, open-source AI Career Curriculum ecosystem — Infrastructure · ML Engineering · AI Engineering · Governance. Live cohorts & team programs: ai-infra-curriculum.github.io.
💜 Sponsor this curriculum — sponsorships keep the whole open-source AI Career Curriculum free and moving.
Role level: 35 (hands-on engineering specialist — AI Governance family)
Planned commitment: ~305 hours — 180 h across 12 modules + 125 h across 3 projects
Status: planned — see CURRICULUM.md and .aicg/curriculum-plan.json
The AI/ML Security & Governance Engineer is a hands-on engineering specialist at the intersection of AI security engineering and AI governance engineering. This role authors threat models for ML/LLM systems, hardens the ML platform (zero-trust, workload identity, secrets, admission-time gates), engineers adversarial-ML and LLM-attack defences at platform scale, wires ML supply-chain security (SLSA for models, cosign / sigstore, ML-BOM, ModelScan), translates AI governance obligations (NIST AI RMF, ISO/IEC 42001, EU AI Act) into enforceable engineering controls and policy-as-code, and produces the AI-specific detection content and incident-response playbooks the enterprise SOC consumes.
CURRICULUM.md— the full 12-module, 3-project plan with per-module summaries.JOB_REQUIREMENTS.md— the requirement catalog and cited authoritative references.PREREQUISITES.md— assumed lower-level tracks and working knowledge.VERSIONS.md— release history.
- Lower: AI Governance Analyst (level 15) · ML Engineer (level 20) · AI Infra Engineer (level 25) · AI Risk Engineer (level 25) · AI Infra Senior Engineer (level 30)
- This track: AI/ML Security & Governance Engineer (level 35)
- Peer at same level: AI Evaluation Engineer (level 35)
- Higher: Agentic Safety & Red-Team Engineer (level 40) · Senior AI Governance Architect (level 50) · Head of AI Governance (level 60) · Chief AI Officer (level 70)
- Solutions repo:
security-solutions— reference implementations for each module and project.
This track owns the engineering craft of AI/ML security and governance end-to-end. It defers up to agentic-safety-engineer (level 40) for frontier-agent red-team methodology, to senior-ai-governance-architect (level 50) for control-library architecture, and to head-of-ai-governance (level 60) for program leadership. It defers sideways to its peer ai-evaluation-engineer (level 35) for release-assurance methodology, and to ai-risk-engineer (level 25) for harm modelling and risk quantification. It is out of scope for legal opinion (owned by counsel) and SOC-side incident handling (owned by enterprise Security Operations — this track authors the AI-specific detection content and playbooks the SOC consumes).
See CURRICULUM.md Ownership rule and .aicg/job-requirements.json ownership_rule for the full deferral contract.
This packet was bootstrapped on 2026-08-04. Requirement themes, ownership rule, and the module + project plan are ready; live job-posting evidence is deferred to the next autonomous research cycle (WebSearch / WebFetch not authorised in the bootstrap session — see JOB_REQUIREMENTS.md "Status — bootstrap session"). Legacy content under lessons/mod-001-* .. lessons/mod-012-* is preserved for reuse under the migration map in .aicg/curriculum-plan.json ownership_links[].
MIT — see LICENSE.
Maintained by VeriSwarm.ai