Architecture
The sociotechnical side of architecture. Trade-offs and communication, decentralized decision-making, platform engineering, AI architecture decisions.
AI systems create engineering questions around sensitive data, model access, agent permissions, testing, and ownership. This five-week program focuses on those decisions: map data flows, threat model and red team an AI workflow, test controls, and work through sandboxing, observability, evaluations, and governance.
Bring a current AI security or privacy problem from your work and use the sessions to examine it with Katharine Jarmul and other experienced engineers.
Live online. Two 2-hour sessions a week, for 5 weeks.
Next cohort: October 14, 2026
Limited places per cohort. Mon & Wed, 03:00PM - 05:00PM CEST
USD1,470
per cohort
Most companies reimburse for professional development.
Download our
"Convince your manager"
template.
InfoQ Certified AI Security & Privacy Engineering Cohort facilitator
Facilitated by Katharine Jarmul
Confidential peer group
Bring a problem from your work
Access 100+ QCon videos
InfoQ publication may follow
Earn an InfoQ certification
(GMT+2 - Berlin time)
Most companies reimburse for professional development.
Download our "Convince Your Manager" template.
The single most valuable outcome has been improving how I write and think. I can now articulate trade-offs in a way that improves my proposals at work.
Chinmay Sawaji,
Senior Software Engineer @Klaviyo
This cohort gave me structured time each week to step back and think about what it really means to be an architect.
David Holliday,
Product manager / Product Owner @Munich Re
The Architecture Canvas was a game changer. We've made different decisions because of how we're structuring conversations. It wasn't just theory.
Ian Hockett,
Staff Software Engineer @Exact Sciences
Security and privacy decisions in AI rarely sit in one part of the stack. A team may need to trace where personal or confidential data enters an AI workflow, decide which threats apply to that architecture, limit what an agent can access, and test whether the controls behave as expected. The five weeks follow that work from data handling and threat modeling through controls, evaluations, and governance.
Identify where personal, confidential, or regulated data enters an AI workflow and where it can move from there. The exercises cover data minimization, sanitization, and privacy controls before information reaches a model.
Identify the security and privacy threats that apply to the architecture you are working with. Use approaches including STRIDE, LINDDUN, and Plot4AI, then red team an LLM workflow to see which assumptions hold and which do not.
Look at controls for model inputs and outputs, data-flow sanitization, and sandboxing for agentic workflows. The focus is architectural: which component enforces a control, what an agent should be allowed to access, and what happens when a control fails.
Define what needs to be observable in an AI system without collecting more sensitive data than necessary. Build a small evaluation suite or use observability tooling such as Arize Phoenix to turn failure cases into checks you can repeat.
Work through who owns AI security, privacy, safety, and audit requirements across engineering and the wider organization. The week closes with the group capstone presentations, where each group explains the risks it identified, the controls it chose, how it would test them, and where responsibility sits.
This program is for experienced engineers and technical leaders responsible for AI systems where security, privacy, access, or sensitive data are part of the design.
We recommend 5+ years in software engineering, architecture, AI/ML engineering, security, privacy engineering, or technical leadership. A security job title is not required. Regulated industries are a strong fit because data handling, auditability, and ownership are explicit constraints, but the same questions appear in SaaS, internal AI platforms, customer-facing AI products, and agentic systems.
Designed for:
Each week has two live sessions and a small amount of independent work, built around the methods for
that week and the problems participants bring from their own systems.
Review the assigned technical material or QCon talk before the sessions.
Join two 2-hour live sessions each week with your facilitator and your cohort.
Between sessions, test a tool, framework, or design approach against a current problem. Independent work is time-boxed.
Bring the result back to the group: what the control caught, what it missed, and what would need to change before production.
4 hours of live sessions per week, split across two 2-hour sessions, plus up to 2 hours of independent work. Designed to fit around your job.
Throughout the cohort, your working group develops a security and privacy assessment for an AI product architecture, covering data exposure, threat models, controls, testing, and ownership. In week 5, each group gives a 20-minute presentation followed by discussion. Selected work may later be developed into an InfoQ article .
Apply the methods from the program to an AI architecture and document the risks, controls, tests, and ownership decisions.
Work through threat models, controls, and ownership with engineers from different companies, industries, and contexts, using methods such as LINDDUN, Plot4AI, red teaming, sandboxing, and evaluations.
Selected capstone work may be developed into a technical article for InfoQ after the program.
Complete the participation and capstone requirements to earn the InfoQ Certified AI Security & Privacy Engineering certification.
Katharine Jarmul is the author of Practical Data Privacy (O'Reilly), available in three languages. Her work focuses on privacy and security in machine learning and AI systems, and she has spent around a decade in machine learning and AI, roughly eight of those years on privacy and security. She gave the opening keynote at InfoQ Dev Summit Munich 2025 and has spoken at QCon. During the program, Katharine facilitates the technical exercises and discussions across sensitive-data handling, threat modeling, controls, testing, and governance.
Author of Practical Data Privacy, privacy & security expert in ML and AI systems
No. Sessions are not recorded. This is a deliberate choice to keep all conversations private and confidential, so that participants feel safe sharing real challenges, ongoing decisions, and truthful perspectives from their organizations.
Participants are expected to attend at least 4 of the 5 weeks. Consistent attendance is one of the criteria for receiving your InfoQ certification.
If you do need to miss a session:
You can contact us for any payment questions at payments@qconferences.com .
We accept PayPal and major credit cards. A payment charged to your credit card or PayPal account is processed directly by us in the funds stated on the website.
The Terms of Participation can be found at https://certification.qconferences.com/terms-conditions .
Registration fees are not refundable.
Yes, we've developed a template you can use to explain to your manager how you can benefit from the cohort participation.
Yes, in-person cohorts are offered at select QCon conferences, such as QCon London and QCon San Francisco.
You can opt to pay by invoice during the registration process by selecting the "Do You Want to Pay Later by Invoice?" checkbox.
Your invoice reflects the ticket price in effect at the time your payment is due. Invoices are generally due 30 days from the date the order is submitted, or 7 days before the event start date—whichever comes first. To ensure all funds are cleared, the "Pay by Invoice" option will be disabled 14 days prior to each event (subject to change without notice). All invoices must be paid in full no later than 7 days before the event begins.
Please note that only participants who have paid in full will be admitted or receive access credentials. Credit card or PayPal payment is required if you are registering after the invoice deadline or prefer immediate confirmation. Once processed, a receipt marked "Paid" will be emailed to you for your records.
Our Privacy Policy details how we collect, use, and protect your data. You can find it at https://www.infoq.com/privacy-policy .
Yes. The program is open to freelancers and the self-employed. When registering, simply enter your trading name or "Independent" in the Company Details section.
The program is a collaborative initiative between InfoQ and QCon, both of which are practitioner-driven brands owned by C4Media Inc.
InfoQ is a practitioner-driven community news site focused on facilitating the spread of knowledge and innovation in professional software development.
We do not offer scholarships or complimentary seats for the InfoQ Certification at this time. Should this change for future cohorts, we will announce it via our official channels.
We are dedicated to providing a safe and inclusive experience for everyone. Our Code of Conduct can be found at https://certification.qconferences.com/code-conduct .
Participants who registered for the online cohorts will receive an email with detailed instructions on how to join the sessions during the week prior to the start of the cohort.
To ensure an optimal experience, you will need:
The program runs for five weeks, with two 2-hour live sessions each week — four live hours a week — plus independent work between sessions and a group Capstone project.
Yes, alumni enrolling in a second Certification program receive a $147 discount. To claim your alumni code, please email certification@qconferences.com when ready to register for your second program.
Plan for 4 hours of live sessions each week, split across two 2-hour workshops, plus up to 2 hours of independent work. This is a significant time investment because we are not just watching talks.
We are undertaking the challenging, practical work of applying these frameworks to real-world challenges alongside your senior peer group.
No. The program is for experienced technical people with at least five years of relevant experience. It starts from system design, threat models, controls, testing, and organizational constraints rather than introductory material on AI or cybersecurity. Each week is structured around a real decision you are working on, not a case study.
The program is built around decisions that depend on architecture and context. A sandbox may be appropriate for one agent workflow and irrelevant to another. A privacy control can reduce one risk while introducing operational cost elsewhere. An evaluation is useful only if it reflects the failures that matter for the system.
The cohort format gives you time to examine those choices against specific systems and hear how engineers in other organizations are handling similar constraints. That is why the program is built around a confidential peer group, live exercises, expert facilitation, and a group capstone rather than self-paced study.
This cohort gives you the confidential peer group and an experienced facilitator to do that work, and you'll earn the InfoQ Certified AI Security & Privacy Engineering Program certification as a result.
The Capstone project is the final milestone. Each working group assesses an AI product architecture across the areas covered in the program, explaining the main security and privacy risks, the controls selected, how those controls would be tested, and who owns the relevant decisions. In Week 5, each group gives a 20-minute presentation followed by discussion with the cohort. Selected work may later be developed into a technical article for InfoQ — examples can be found on InfoQ.com .
Certification is awarded based on two factors: consistent attendance and active participation in the live sessions, and the successful completion of the group Capstone project.
This is for experienced engineers and technical leaders responsible for AI systems where security, privacy, access, or sensitive data are part of the design: senior software engineers, staff and principal engineers, software architects, AI/ML platform engineers, security and privacy engineers, technical leads, and engineering managers. We recommend at least 5 years of relevant experience.
No. Security and privacy engineers are part of the audience, but the program also applies to senior software engineers, staff and principal engineers, architects, AI/ML platform engineers, technical leads, and engineering managers who are responsible for AI systems.
No. Regulated industries are a strong fit because privacy, compliance, and auditability are explicit system constraints. The same technical questions apply when an AI system handles confidential company data, customer information, proprietary data, or takes autonomous actions.
The syllabus covers sensitive data in AI workflows; threat modeling and red teaming; guardrails, data-flow controls, and sandboxes; observability, testing, and evaluations; and governance and auditing.
The exercises include mapping data flows, using threat-modeling methods, red teaming, testing controls, building evaluations, and defining ownership.
Certification is awarded based on active participation in the cohort and successful completion of the group capstone, presented in Week 5.
The sociotechnical side of architecture. Trade-offs and communication, decentralized decision-making, platform engineering, AI architecture decisions.
Building production software with AI coding agents. Codebase comprehension, agent permissions and sandboxing, sensors and self-correction, independent review, CI for unattended agents.
Securing and governing AI systems in production. Sensitive data handling, threat modeling and red teaming, controls and sandboxes, observability and evals, governance and auditing
Date: October 14, 2026
Time: Mon & Wed, 03:00PM - 05:00PM CEST
Building AI systems that hold up in production. AI-native engineering, RAG and context pipelines, AI agents, platform and infrastructure, evals and reliability.
Date: Dates to be announced
We're adding more cohorts over the coming weeks. To be the first to know when they are live, sign up for our email notifications.
Get email updatesJoin the waitlist to get early access and updates on the InfoQ Online Certification Programs and our conferences. Be the first to know when a cohort opens.
We'll only email you with relevant updates about this program and our conferences.