Skip to content

Repository files navigation

AI/ML Security & Governance Engineer — Learning Repository

🎓 Part of the free, open-source AI Career Curriculum ecosystem — Infrastructure · ML Engineering · AI Engineering · Governance. Live cohorts & team programs: ai-infra-curriculum.github.io.

💜 Sponsor this curriculum — sponsorships keep the whole open-source AI Career Curriculum free and moving.

Role level: 35 (hands-on engineering specialist — AI Governance family) Planned commitment: ~305 hours — 180 h across 12 modules + 125 h across 3 projects Status: planned — see CURRICULUM.md and .aicg/curriculum-plan.json

What this track teaches

The AI/ML Security & Governance Engineer is a hands-on engineering specialist at the intersection of AI security engineering and AI governance engineering. This role authors threat models for ML/LLM systems, hardens the ML platform (zero-trust, workload identity, secrets, admission-time gates), engineers adversarial-ML and LLM-attack defences at platform scale, wires ML supply-chain security (SLSA for models, cosign / sigstore, ML-BOM, ModelScan), translates AI governance obligations (NIST AI RMF, ISO/IEC 42001, EU AI Act) into enforceable engineering controls and policy-as-code, and produces the AI-specific detection content and incident-response playbooks the enterprise SOC consumes.

Where this track sits on the ladder

Paired repositories

  • Solutions repo: security-solutions — reference implementations for each module and project.

Ownership contract at a glance

This track owns the engineering craft of AI/ML security and governance end-to-end. It defers up to agentic-safety-engineer (level 40) for frontier-agent red-team methodology, to senior-ai-governance-architect (level 50) for control-library architecture, and to head-of-ai-governance (level 60) for program leadership. It defers sideways to its peer ai-evaluation-engineer (level 35) for release-assurance methodology, and to ai-risk-engineer (level 25) for harm modelling and risk quantification. It is out of scope for legal opinion (owned by counsel) and SOC-side incident handling (owned by enterprise Security Operations — this track authors the AI-specific detection content and playbooks the SOC consumes).

See CURRICULUM.md Ownership rule and .aicg/job-requirements.json ownership_rule for the full deferral contract.

Status

This packet was bootstrapped on 2026-08-04. Requirement themes, ownership rule, and the module + project plan are ready; live job-posting evidence is deferred to the next autonomous research cycle (WebSearch / WebFetch not authorised in the bootstrap session — see JOB_REQUIREMENTS.md "Status — bootstrap session"). Legacy content under lessons/mod-001-* .. lessons/mod-012-* is preserved for reuse under the migration map in .aicg/curriculum-plan.json ownership_links[].

License

MIT — see LICENSE.

Maintained by VeriSwarm.ai

About

AI Infrastructure Security Engineer Learning Track - ML infrastructure security, model security, and compliance

Topics

Resources

Code of conduct

Contributing

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages