AI Security & Privacy Engineering

Make security and privacy decisions for AI systems in production

AI systems create engineering questions around sensitive data, model access, agent permissions, testing, and ownership. This five-week program focuses on those decisions: map data flows, threat model and red team an AI workflow, test controls, and work through sandboxing, observability, evaluations, and governance.

Bring a current AI security or privacy problem from your work and use the sessions to examine it with Katharine Jarmul and other experienced engineers.

Live online. Two 2-hour sessions a week, for 5 weeks.

Next cohort: October 14, 2026

Limited places per cohort. Mon & Wed, 03:00PM - 05:00PM CEST

USD1,470 per cohort
Most companies reimburse for professional development.
Download our "Convince your manager" template.

Katharine Jarmul

Katharine Jarmul

InfoQ Certified AI Security & Privacy Engineering Cohort facilitator

Katharine Jarmul

Facilitated by Katharine Jarmul

Group

Confidential peer group

QCon

Bring a problem from your work

QCon

Access 100+ QCon videos

InfoQ

InfoQ publication may follow

Certification

Earn an InfoQ certification

InfoQ and QCon focus on technical decisions, production experience, and the trade-offs software teams encounter in practice.
Amazon Logo Airbnb Logo american airlines Logo AE Logo Conde Nast Logo Ebay Logo Meta Logo Apple Logo Etsy Logo JPMorgan Logo Nasa Logo netflix Logo Oracle Logo Paypal Logo Goldman Logo spotify Logo SalesForce Logo uber Logo tesla Logo accentrue Logo charles Logo Fedex Logo Hulu Logo Google Logo Intuit Logo mckinsey Logo microsoft Logo workday Logo youtube Logo

Upcoming AI Security & Privacy Engineering cohorts

October

Two 2-hour sessions a week · 5 weeks

InfoQ Certified AI Security & Privacy Engineering Program

(GMT+2 - Berlin time)

  • Calendar Dates: Oct 14, 19, 21, 26, 28, Nov 2, 4, 9, 11, 16
  • Clock Time: Mon & Wed, 03:00PM - 05:00PM CEST
  • Location Location: Online (Zoom)

Most companies reimburse for professional development.
Download our "Convince Your Manager" template.

What participants say about InfoQ cohorts

The single most valuable outcome has been improving how I write and think. I can now articulate trade-offs in a way that improves my proposals at work.

Chinmay Sawaji,
Senior Software Engineer @Klaviyo

This cohort gave me structured time each week to step back and think about what it really means to be an architect.

David Holliday,
Product manager / Product Owner @Munich Re

The Architecture Canvas was a game changer. We've made different decisions because of how we're structuring conversations. It wasn't just theory.

Ian Hockett,
Staff Software Engineer @Exact Sciences

These cohorts bring together senior engineers from different companies to work through the decisions behind security and privacy engineering for production AI. The value is the peer group, working on the same problems in different contexts.

Katharine Jarmul
InfoQ Certified AI Security & Privacy Engineering Cohort facilitator

Katharine Jarmul

The 5-week learning journey.

Security and privacy decisions in AI rarely sit in one part of the stack. A team may need to trace where personal or confidential data enters an AI workflow, decide which threats apply to that architecture, limit what an agent can access, and test whether the controls behave as expected. The five weeks follow that work from data handling and threat modeling through controls, evaluations, and governance.

Learning journey

WEEK 1:

Working with Sensitive Data + AI

Identify where personal, confidential, or regulated data enters an AI workflow and where it can move from there. The exercises cover data minimization, sanitization, and privacy controls before information reaches a model.

WEEK 2:

Threat Modeling and Red Teaming

Identify the security and privacy threats that apply to the architecture you are working with. Use approaches including STRIDE, LINDDUN, and Plot4AI, then red team an LLM workflow to see which assumptions hold and which do not.

WEEK 3:

Guardrails, Data Flow Controls and Sandboxes

Look at controls for model inputs and outputs, data-flow sanitization, and sandboxing for agentic workflows. The focus is architectural: which component enforces a control, what an agent should be allowed to access, and what happens when a control fails.

WEEK 4:

Observability, Testing and Evaluations

Define what needs to be observable in an AI system without collecting more sensitive data than necessary. Build a small evaluation suite or use observability tooling such as Arize Phoenix to turn failure cases into checks you can repeat.

WEEK 5:

Governance and Auditing

Work through who owns AI security, privacy, safety, and audit requirements across engineering and the wider organization. The week closes with the group capstone presentations, where each group explains the risks it identified, the controls it chose, how it would test them, and where responsibility sits.

Who this program is for

This program is for experienced engineers and technical leaders responsible for AI systems where security, privacy, access, or sensitive data are part of the design.

We recommend 5+ years in software engineering, architecture, AI/ML engineering, security, privacy engineering, or technical leadership. A security job title is not required. Regulated industries are a strong fit because data handling, auditability, and ownership are explicit constraints, but the same questions appear in SaaS, internal AI platforms, customer-facing AI products, and agentic systems.

Designed for:

  • Senior Software Engineers
  • Staff & Principal Engineers
  • AI/ML Platform Engineers
  • Security & Privacy Engineers
  • Software Architects
  • Technical Leads & Engineering Managers
Experience

How each week works

Each week has two live sessions and a small amount of independent work, built around the methods for that week and the problems participants bring from their own systems.

Format

1

Review the assigned technical material or QCon talk before the sessions.

2

Join two 2-hour live sessions each week with your facilitator and your cohort.

3

Between sessions, test a tool, framework, or design approach against a current problem. Independent work is time-boxed.

4

Bring the result back to the group: what the control caught, what it missed, and what would need to change before production.

Time commitment

4 hours of live sessions per week, split across two 2-hour sessions, plus up to 2 hours of independent work. Designed to fit around your job.

Capstone project

Throughout the cohort, your working group develops a security and privacy assessment for an AI product architecture, covering data exposure, threat models, controls, testing, and ownership. In week 5, each group gives a 20-minute presentation followed by discussion. Selected work may later be developed into an InfoQ article .

What you leave with.

Applied learning

An assessment you've worked through

Apply the methods from the program to an AI architecture and document the risks, controls, tests, and ownership decisions.

Senior Peer Groups

Better decisions

Work through threat models, controls, and ownership with engineers from different companies, industries, and contexts, using methods such as LINDDUN, Plot4AI, red teaming, sandboxing, and evaluations.

InfoQ publication

Publication may follow

Selected capstone work may be developed into a technical article for InfoQ after the program.

Get Certified

Get certified

Complete the participation and capstone requirements to earn the InfoQ Certified AI Security & Privacy Engineering certification.

Your facilitator: Katharine Jarmul

Katharine Jarmul is the author of Practical Data Privacy (O'Reilly), available in three languages. Her work focuses on privacy and security in machine learning and AI systems, and she has spent around a decade in machine learning and AI, roughly eight of those years on privacy and security. She gave the opening keynote at InfoQ Dev Summit Munich 2025 and has spoken at QCon. During the program, Katharine facilitates the technical exercises and discussions across sensitive-data handling, threat modeling, controls, testing, and governance.

Credentials

  • Author of Practical Data Privacy (O'Reilly)
  • Privacy & security expert in ML and AI systems
  • InfoQ Dev Summit Munich 2025 opening keynote speaker; QCon speaker

Katharine Jarmul

Author of Practical Data Privacy, privacy & security expert in ML and AI systems

Frequently asked questions

Will the sessions be recorded?

No. Sessions are not recorded. This is a deliberate choice to keep all conversations private and confidential, so that participants feel safe sharing real challenges, ongoing decisions, and truthful perspectives from their organizations.

What happens if I miss a session?

Participants are expected to attend at least 4 of the 5 weeks. Consistent attendance is one of the criteria for receiving your InfoQ certification.

If you do need to miss a session:

  • Connect with your peers through the private Slack channel to catch up on key discussions.
  • Review the session materials and slides shared in the Google Drive folder.
  • Complete the homework assignment for that week.
  • Post any questions in Slack — your facilitator, peers and the InfoQ team will be available to help.
Who can I contact for questions relating to payment?

You can contact us for any payment questions at payments@qconferences.com .

What payment methods do you accept?

We accept PayPal and major credit cards. A payment charged to your credit card or PayPal account is processed directly by us in the funds stated on the website.

What are the Terms of Participation?

The Terms of Participation can be found at https://certification.qconferences.com/terms-conditions .

What is the Cancellation and Refund policy?

Registration fees are not refundable.

Do you offer a template to help convince my manager?

Yes, we've developed a template you can use to explain to your manager how you can benefit from the cohort participation.

Do you offer in-person cohorts as well?

Yes, in-person cohorts are offered at select QCon conferences, such as QCon London and QCon San Francisco.

Can I pay for tickets by invoice?

You can opt to pay by invoice during the registration process by selecting the "Do You Want to Pay Later by Invoice?" checkbox.

Your invoice reflects the ticket price in effect at the time your payment is due. Invoices are generally due 30 days from the date the order is submitted, or 7 days before the event start date—whichever comes first. To ensure all funds are cleared, the "Pay by Invoice" option will be disabled 14 days prior to each event (subject to change without notice). All invoices must be paid in full no later than 7 days before the event begins.

Please note that only participants who have paid in full will be admitted or receive access credentials. Credit card or PayPal payment is required if you are registering after the invoice deadline or prefer immediate confirmation. Once processed, a receipt marked "Paid" will be emailed to you for your records.

What is the Privacy Policy, and how is my data being protected?

Our Privacy Policy details how we collect, use, and protect your data. You can find it at https://www.infoq.com/privacy-policy .

Can I register as a freelancer or self-employed professional?

Yes. The program is open to freelancers and the self-employed. When registering, simply enter your trading name or "Independent" in the Company Details section.

Who is behind the InfoQ Certified AI Security & Privacy Engineering Program?

The program is a collaborative initiative between InfoQ and QCon, both of which are practitioner-driven brands owned by C4Media Inc.

What is InfoQ?

InfoQ is a practitioner-driven community news site focused on facilitating the spread of knowledge and innovation in professional software development.

Are scholarships or complimentary seats available?

We do not offer scholarships or complimentary seats for the InfoQ Certification at this time. Should this change for future cohorts, we will announce it via our official channels.

What is the code of conduct?

We are dedicated to providing a safe and inclusive experience for everyone. Our Code of Conduct can be found at https://certification.qconferences.com/code-conduct .

How will I gain access to the online cohort sessions?

Participants who registered for the online cohorts will receive an email with detailed instructions on how to join the sessions during the week prior to the start of the cohort.

What are the technical requirements for participation?

To ensure an optimal experience, you will need:

  • A stable internet connection: High-speed access for video conferencing.
  • Zoom: The latest version of the Zoom desktop client.
  • Slack: Access to our private workspace for peer networking and coordination.
  • A laptop or desktop: While mobile devices are supported, a computer is highly recommended for collaborative work and session participation.
How is the program structured?

The program runs for five weeks, with two 2-hour live sessions each week — four live hours a week — plus independent work between sessions and a group Capstone project.

Are there any discounts for Certification alumni?

Yes, alumni enrolling in a second Certification program receive a $147 discount. To claim your alumni code, please email certification@qconferences.com when ready to register for your second program.

What is the weekly time commitment?

Plan for 4 hours of live sessions each week, split across two 2-hour workshops, plus up to 2 hours of independent work. This is a significant time investment because we are not just watching talks.

We are undertaking the challenging, practical work of applying these frameworks to real-world challenges alongside your senior peer group.

Is this an introductory AI security course?

No. The program is for experienced technical people with at least five years of relevant experience. It starts from system design, threat models, controls, testing, and organizational constraints rather than introductory material on AI or cybersecurity. Each week is structured around a real decision you are working on, not a case study.

Why a cohort instead of just watching the talks?

The program is built around decisions that depend on architecture and context. A sandbox may be appropriate for one agent workflow and irrelevant to another. A privacy control can reduce one risk while introducing operational cost elsewhere. An evaluation is useful only if it reflects the failures that matter for the system.

The cohort format gives you time to examine those choices against specific systems and hear how engineers in other organizations are handling similar constraints. That is why the program is built around a confidential peer group, live exercises, expert facilitation, and a group capstone rather than self-paced study.

This cohort gives you the confidential peer group and an experienced facilitator to do that work, and you'll earn the InfoQ Certified AI Security & Privacy Engineering Program certification as a result.

What is the Capstone project, and where can I see examples?

The Capstone project is the final milestone. Each working group assesses an AI product architecture across the areas covered in the program, explaining the main security and privacy risks, the controls selected, how those controls would be tested, and who owns the relevant decisions. In Week 5, each group gives a 20-minute presentation followed by discussion with the cohort. Selected work may later be developed into a technical article for InfoQ — examples can be found on InfoQ.com .

What are the criteria for receiving the certification?

Certification is awarded based on two factors: consistent attendance and active participation in the live sessions, and the successful completion of the group Capstone project.

Who is this cohort for?

This is for experienced engineers and technical leaders responsible for AI systems where security, privacy, access, or sensitive data are part of the design: senior software engineers, staff and principal engineers, software architects, AI/ML platform engineers, security and privacy engineers, technical leads, and engineering managers. We recommend at least 5 years of relevant experience.

Do I need to be a security or privacy engineer?

No. Security and privacy engineers are part of the audience, but the program also applies to senior software engineers, staff and principal engineers, architects, AI/ML platform engineers, technical leads, and engineering managers who are responsible for AI systems.

Is this only for regulated industries?

No. Regulated industries are a strong fit because privacy, compliance, and auditability are explicit system constraints. The same technical questions apply when an AI system handles confidential company data, customer information, proprietary data, or takes autonomous actions.

What will I work on during the five weeks?

The syllabus covers sensitive data in AI workflows; threat modeling and red teaming; guardrails, data-flow controls, and sandboxes; observability, testing, and evaluations; and governance and auditing.

The exercises include mapping data flows, using threat-modeling methods, red teaming, testing controls, building evaluations, and defining ownership.

How do I earn the certification?

Certification is awarded based on active participation in the cohort and successful completion of the group capstone, presented in Week 5.

InfoQ online cohorts

AI Engineering

Building AI systems that hold up in production. AI-native engineering, RAG and context pipelines, AI agents, platform and infrastructure, evals and reliability.

Download Syllabus

Date: Dates to be announced

More Cohorts coming soon

We're adding more cohorts over the coming weeks. To be the first to know when they are live, sign up for our email notifications.

Get email updates

Be the first to know when a cohort opens.

Join the waitlist to get early access and updates on the InfoQ Online Certification Programs and our conferences. Be the first to know when a cohort opens.

We'll only email you with relevant updates about this program and our conferences.

Experience