← Every path

H2-CAIE · Specialist path

AI Security Engineering

H2 Certified AI Security Engineer

Secure the AI systems everyone is now shipping, and turn AI into a defender. LLM application security, prompt injection and tool sandboxing, agent and MCP security, AI for security operations, adversarial ML, and the model supply chain.

6 courses · 19 lessons · ~33 h of guided work

Assumes Foundation + T-Shaped core; CSWE and CSDE recommended

What you leave with

A hardened LLM application, an agent with real tool sandboxing and MCP security, an AI triage service for your own security operations, and a secured model supply chain.

Models
Claude / open models
Protocol
MCP
Sandboxing
Tool isolation
Sec ops
The H2 triage service
Supply chain
Model provenance

Syllabus

6 courses · every lesson graded · minutes are guided work

  1. Course 01

    Securing LLM applications

    The new attack surface an LLM feature opens, and how to build one that does not leak its system prompt, its data or its keys.

    4 lessons · ~7 h

    Tools Claude API, an LLM app framework

    1. 01The LLM attack surfaceWhere an LLM feature widens the surface; trust the model gives you and does not.90 min
    2. 02Input and output handlingTreating model input and output as untrusted; the boundaries to enforce.120 min
    3. 03Context isolationKeeping tenant data, system prompts and secrets out of reach of the prompt.120 min
    4. 04Keys and cost controlProtecting the API key and bounding spend against abuse.90 min

    Course checkHarden an LLM feature so a probe cannot extract the system prompt, reach the backend, or exfiltrate data.

    You leave withAn LLM application with input and output handling, isolated context, and no path from a prompt to the backend or the secrets.

  2. Course 02

    Prompt injection and tool sandboxing

    The defining LLM vulnerability. Direct and indirect injection, and sandboxing the tools a model can call so a hijacked prompt cannot become a hijacked system.

    3 lessons · ~6 h

    Tools Tool isolation, capability scoping

    1. 01Direct and indirect injectionInjection from the user and from retrieved content; why the model cannot tell them apart.120 min
    2. 02Tool sandboxingEvery tool scoped to least privilege; a hijacked prompt confined to what the tool may do.120 min
    3. 03Defenses that holdIsolation, allow-lists and human-in-the-loop where the action is dangerous.90 min

    Course checkDefend an LLM with tools against direct and indirect injection; a hijacked prompt must not reach a dangerous tool.

    You leave withAn LLM with sandboxed tools that resists direct and indirect prompt injection, proven against a campaign.

  3. Course 03

    Agent and MCP security

    Autonomous agents that act on the world, and the Model Context Protocol that connects them to tools and data, secured so an agent cannot exceed its authority.

    3 lessons · ~6 h

    Tools MCP, agent frameworks, authorization

    1. 01Agents that actThe risk when a model does things, not just says things; blast radius by design.90 min
    2. 02MCP securityAuthorizing and auditing MCP tool calls; the trust model of the protocol.120 min
    3. 03Bounding authorityScopes, approvals and audit so a manipulated agent stays inside its lane.120 min

    Course checkGive an agent tools via MCP and prove it cannot act outside its granted authority even when manipulated.

    You leave withAn agent with MCP-connected tools, each authorized and audited, that cannot exceed its authority under manipulation.

  4. Course 04

    AI for security operations

    Turn the technology into a defender. LLM-assisted triage, detection and investigation, built the way H2's own CVE triage and scanner are, with the model kept honest.

    3 lessons · ~5 h

    Tools The H2 triage service, the H2 scanner, Claude API

    1. 01Where AI helps securityTriage, summarization and investigation; where it must not be trusted alone.90 min
    2. 02Building a triage serviceAn LLM step that ranks by exploitability; H2's CVE triage as the pattern.120 min
    3. 03Keeping it honestGuarding against a crafted input gaming the model; human review where it counts.90 min

    Course checkBuild an AI triage step that ranks findings by exploitability and is resistant to being fooled by crafted input.

    You leave withAn AI triage service for your own security operations, modeled on H2's, that helps analysts and cannot be gamed by a crafted finding.

  5. Course 05

    Adversarial machine learning

    Attacks on the models themselves: evasion, poisoning, extraction and inference, and the defenses that raise the cost of each.

    3 lessons · ~5 h

    Tools ML tooling, adversarial libraries

    1. 01Evasion and poisoningFooling a model at inference and corrupting it at training; both demonstrated.120 min
    2. 02Extraction and inferenceStealing a model and inferring its training data; the privacy angle.90 min
    3. 03DefensesWhat raises the cost of each attack, and what does not work despite the hype.90 min

    Course checkDemonstrate an evasion and a poisoning attack on a model, then apply defenses that measurably reduce their success.

    You leave withDemonstrated evasion, poisoning and extraction attacks on a model, with defenses that measurably raise the attacker's cost.

  6. Course 06

    The model supply chain

    A model is a dependency you rarely inspect. Provenance, integrity and the poisoned-weights risk, secured the way the DevSecOps path secures code.

    3 lessons · ~5 h

    Tools Model signing, provenance, the DevSecOps toolchain

    1. 01Models as dependenciesWhat you inherit when you pull weights; the trust you extend without noticing.90 min
    2. 02Provenance and integritySigning and verifying models; detecting tampering before deploy.120 min
    3. 03Poisoned weightsThe backdoored-model risk and the checks that catch it.90 min

    Course checkVerify a model's provenance and detect a tampered set of weights before it is deployed.

    You leave withA model supply chain with provenance and integrity checks that refuse a tampered or unverified model at deploy time.

Certification course

H2 Certified AI Security Engineer

$799 · one price · courses + 90-day labs + exam

48-hour practical: your LLM application and agent face a prompt-injection campaign, a tool-abuse attempt, a data-exfiltration probe and a poisoned model. Repel each and prove the agent could not exceed its authority.

Opens when Foundation is complete and the 6 course checks are passed. One proctored attempt, plus a free retake if you fail by a margin. The credential is an Open Badges 3.0 credential, signed and verifiable.

Create an account to enrol