HomeCourses › AI Security & Red Teaming

AI Security & Red Teaming

Secure, red-team, and defend production AI systems

10 phases. 55 lessons. 55 labs. 4 projects. The OWASP LLM Top 10, prompt injection and jailbreaking, adversarial ML, RAG and agent security, guardrails, red teaming with Garak and PyRIT, AI governance and compliance, and production security architecture. You build the threat models, detectors, guardrails, and red team reports that AI security teams actually ship.

10 phases · 55 lessons · 55 labs · 4 projects

Take ML & AI Engineering first — this course builds on it.

Outcomes you will have by the end

What you will be able to do

OWASP LLM Top 10 · Prompt Injection Defense · Red Teaming · Guardrails · MITRE ATLAS · AI Compliance

Every phase, every lesson, every project

The technologies you will use

OWASP LLM Top 10 · Garak · PyRIT · Promptfoo · NeMo Guardrails · Guardrails AI · MITRE ATLAS · Adversarial Robustness Toolbox · Langfuse · Docker · Python · FastAPI

Roles this course prepares you for

What AI security engineering actually is

AI security blends offensive security (red teaming) and defensive engineering (guardrails, monitoring, compliance) around a new class of system: one that reasons over natural language and can be manipulated through it. It is not traditional AppSec with an LLM bolted on — the attack surface, the failure modes, and the defenses are structurally different.

What you do every day

You scan models with Garak, run multi-turn attacks with PyRIT, build and tune guardrail pipelines, review agent codebases for excessive agency, write threat models for new AI features, and respond when a guardrail bypass makes it to production. You write red team reports that get read by engineering leadership, not just other security engineers.

Why companies are hiring for this now

Every company shipping an LLM feature now has an attack surface that didn't exist two years ago: prompt injection, jailbreaks, RAG poisoning, agent privilege escalation. AI security engineering job postings grew 124% year-over-year, and 89% of them require prompt injection and jailbreak expertise specifically. There is no large pool of experienced candidates yet — this is a wide-open niche.

What this course is not

It is not a general cybersecurity course with a few AI slides added. It is not a theory course — you will not just read the OWASP LLM Top 10, you will exploit and defend against every category of it. And it does not pretend the field has a finished playbook: you will learn the frameworks that exist (MITRE ATLAS, NIST AI RMF) and the reasoning skills to handle the attack patterns that show up in your job next month, which no course has documented yet.

Common questions

What background do I need for the AI Security & Red Teaming course?

Python proficiency and a basic understanding of LLM APIs (OpenAI, Anthropic) and what RAG and agents are. No prior security experience required — Phase 0 and Phase 1 teach security fundamentals and the OWASP LLM Top 10 from scratch. We recommend the ML & AI Engineering course as a foundation, but it is not required.

Is this standalone or does it require the ML & AI Engineering course?

Fully standalone. If you already know Python and the basics of LLMs, RAG, and agents, you can start here directly. If you're newer to AI engineering, completing Phase 01 of the ML & AI Engineering course first will make Phases 2–4 easier.

How is this different from the security content in the ML & AI Engineering course?

The ML & AI Engineering course covers evaluation and safety in one 6-lesson phase (Phase 08) as part of a broader AI engineering curriculum. This course goes roughly 10x deeper: 55 lessons dedicated entirely to security — the full OWASP LLM Top 10, prompt injection and jailbreaking, adversarial ML, RAG/agent security, guardrail frameworks, red teaming with Garak and PyRIT, AI governance and compliance, and production security architecture.

How long does this course take?

120–160 hours of structured content. Most engineers complete it in 4–6 months at 8–10 hours per week. Phases 0–1 (free) can be completed in about a week and give you a real sense of the field before you commit further.

Do I need a GPU or special hardware?

No. Every lab runs on CPU. The adversarial ML labs (Phase 3) use small models specifically so they run locally without GPU access. Red teaming labs (Phase 6) call hosted or free-tier LLM APIs.

What specific jobs does this course prepare me for?

AI Security Engineer, AI Red Team Engineer, DevSecOps for AI Pipelines, AI Security Architect, AI Governance & Compliance Engineer, LLM Application Security Engineer, Adversarial ML Researcher/Engineer, and AI Security Consultant. Every phase maps to specific hiring signals for these roles.

How is AI red teaming different from traditional penetration testing?

Traditional pentesting focuses on the CIA triad — confidentiality, integrity, availability. AI red teaming focuses on context-specific harms: bias, manipulation, factuality, and safety, alongside traditional security concerns. The attack surface is also different — you're attacking model behavior through natural language and retrieved content, not just network and application boundaries. This course follows the Microsoft AI Red Team methodology, which was built specifically for this difference.

Is this field established enough to have a reliable curriculum?

The field is young and moving fast — there is no 20-year-old playbook to teach from. This course is built from the frameworks that do exist and are stable: OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and the tools security teams actually use in production (Garak, PyRIT, NeMo Guardrails, Promptfoo). You will also learn to reason from first principles, because you will encounter attack patterns in the job that no course has documented yet.

Key terms in this course

Agent · Guardrails · Prompt Injection · Red Teaming · RAG (Retrieval-Augmented Generation) · Embedding · Inference · MCP (Model Context Protocol)

Continue your learning path

Agentic AI Engineering · Responsible AI Engineering · ML & AI Engineering · Security Review for Vibe Coders

Start the AI Security & Red Teaming course

Create a free account — the opening phases of 24 of 30 courses are free, no credit card. Or see Pro pricing.

All courses · Pricing · About · FAQ · Glossary