Phase 9: Career & Portfolio · 55 min · arXiv · MITRE ATLAS · Python
Staying Current & Capstone Demo
The OWASP LLM Top 10 has already been revised multiple times since you started this course — the field doesn't wait for you to finish studying it.
Hiring signal: AI security hiring managers explicitly ask what a candidate reads and follows, because the threat landscape shifts monthly — a new jailbreak technique, a new indirect-injection CVE, a new MITRE ATLAS case study. Candidates who can name a specific, working habit (which arXiv categories, which vendor blogs, how they track ATLAS updates) and who can walk through a coherent, connected demo of real project work read as substantially more hire-ready than candidates with the same skills and no visible way of staying current.
What you will learn
- Build a repeatable, time-boxed habit for tracking arXiv cs.CR/cs.LG, vendor security blogs, and MITRE ATLAS updates without drowning in volume
- Distinguish which source is appropriate for which kind of claim: peer-reviewed research, unreviewed preprint, vendor-published finding, or living taxonomy
- Assemble a structured capstone demo script that connects all 4 course projects into one coherent, rehearsed narrative
- Build a dated first-90-days learning plan for a new AI security role that keeps the staying-current habit running past day one
The Problem
Every other lesson in this course teaches you something that is true today. This lesson is about what happens the day after you finish the course, when the thing you learned starts to decay. A jailbreak taxonomy from six months ago is missing Crescendo-style multi-turn techniques that didn't have a name yet. A guardrail architecture from a year ago doesn't account for MCP-based tool poisoning, because MCP didn't exist in its current form. The OWASP GenAI Security Project has revised the LLM Top 10 multiple times since its first release — if the version in your head is two revisions behind, that's not a minor gap, it's a specific, checkable thing an interviewer can catch in under a minute.
This is different from most engineering fields in degree, not just in kind. Backend engineering practices shift over years. AI security threat techniques shift over weeks, because the attack surface is a frontier model's behavior, and frontier labs ship new models — with new failure modes — every few months. A candidate who can name the exact habit they use to track this ("I read arXiv cs.CR twice a week, I follow these four vendor blogs, I check MITRE ATLAS for new case studies monthly") reads as someone who will still be useful in six months. A candidate who can't reads as someone whose skills have an expiration date the hiring manager just can't see yet.
The other half of this lesson is more immediate: you are about to finish this course and you have four real projects sitting in four separate directories. A capstone demo is not a fifth project — it's the connective narrative that turns four disconnected deliverables into one coherent story of what you can do. Hiring managers don't remember four isolated case studies as well as they remember one throughline: "this candidate built a detector, then audited a live agent system, then red-teamed it, then hardened it for production." That's not four skills. That's the whole job.
A habit beats a one-time read
Reading one long "state of AI security" roundup article the week before an interview is not the same as having a habit. Interviewers can tell the difference, because a habit produces specific, dated recall ("I saw a new indirect injection technique on arXiv about three weeks ago that used tool-call arguments as the injection vector") while a one-time cram produces generic recall ("prompt injection is still a big problem"). The goal of this lesson isn't to make you read more — it's to make what you already read leave a trace you can point to.
Primary Sources: arXiv cs.CR and cs.LG
arXiv is where new attack techniques and defenses show up first — usually months before they're distilled into a vendor blog post or a conference talk. Two categories matter most for AI security work:
- cs.CR (Cryptography and Security) — this is where prompt injection papers, jailbreak technique papers (TAP, PAIR, Crescendo-style multi-turn attacks), adversarial robustness papers, and model extraction/inversion papers land first.
- cs.LG (Machine Learning) — broader, but relevant because training-time attacks (poisoning, backdoors), alignment research, and evaluation methodology papers that inform red teaming practice often land here instead of cs.CR.
The discipline that makes this sustainable is treating arXiv as a firehose you sample, not a reading list you clear. Nobody reads every cs.CR paper. A workable habit: skim the daily listing titles for 5-10 minutes, twice a week, read abstracts for anything that mentions a technique category you work with (injection, jailbreak, extraction, poisoning, agent/tool security), and only read the full paper for the handful per month that are directly relevant to something you're building or defending.
The distinction that matters for how you cite these sources: arXiv preprints are not peer-reviewed. A paper claiming a novel attack with a 95% success rate has not been through the scrutiny a published, peer-reviewed result has. That doesn't mean ignore it — some of the most operationally important AI security findings (including the original indirect prompt injection work) were disseminated as preprints or blog posts, not journal papers, because the field moves faster than review cycles. It means: when you cite a preprint in a threat model or a report, say so ("per an unreviewed arXiv preprint from [month/year]"), rather than presenting it with the same confidence as an established, reproduced result.
Unlock the full lesson
You've read the first 2 sections. The rest of this lesson covers Vendor Security Blogs: Where Frontier Labs Publish What They Find, Tracking MITRE ATLAS Updates, The Capstone Demo: Connecting Your Four Projects, A First-90-Days Plan for a New AI Security Role, Build It, What to Practice — plus a hands-on lab, quiz, and project artifact.
Create a free account to unlock Phase 0 and Phase 1 of every course — no credit card.
Browse all courses · View pricing · DeVenture Academy