Securing AI systems and using AI to defend systems. Spans prompt-injection defense, model and data exfiltration risk, secure agent design, and AI-augmented secu
AI security skill defends both directions: securing AI systems (prompt injection, agent tool abuse, data leakage, model theft) and wielding AI in defense (SOC automation, threat detection). It sits at the intersection of two talent shortages, and prices accordingly.
Among the hottest niches in security: every agent deployment creates attack surface, regulators expect controls, and practitioners fluent in both AI and security remain genuinely scarce.
Agent threat modeling: mapping what an injected or manipulated agent could do with its tools, then bounding it, least privilege, approval gates, sandboxing. It's where incidents are currently being born.
Directly: appsec and pentest instincts transfer; add the LLM attack/defense canon and hands-on agent red-teaming. Six focused months puts most security engineers in the AI-security market.