InfoQ is running two five-week online certification cohorts in October 2026. AI Security & Privacy Engineering, starting October 26, examines how to protect sensitive data and test security controls in an AI product. AI-Assisted Engineering, starting October 19, focuses on the checks around coding agents changing an existing codebase. Both give experienced practitioners time to apply those methods with facilitators and peers from other organizations.
In the InfoQ AI Security and Privacy Program cohort, participants bring a current work problem and trace where sensitive information enters an AI workflow and where it might go next. They use threat modeling and red teaming to examine the architecture, then test controls and consider what failures the system must make visible. For the group capstone, they assess an AI product architecture and explain the risks identified, the controls chosen, how those controls would be tested, and who owns the decisions.
Katharine Jarmul, author of Practical Data Privacy, facilitates the security cohort. Her work focuses on privacy and security in machine learning and AI systems. Katharine delivered the opening keynote at InfoQ Dev Summit Munich 2025 and has presented at QCon. Katharine describes the approach:
"An AI security review has to follow the data and the decisions across the whole system. In the cohort, we’ll map where sensitive information can go, test the controls we choose, and make clear who owns the risks that remain."
In the InfoQ AI-Assisted Engineering Program cohort, participants work on a shared brownfield repository. They build context for the agent, limit its permissions, add tests and sensors, and separate generation from review before moving checks into CI. For the capstone, they present the resulting harness. They also submit a rule or agent skill drawn from recurring review findings and compare five weeks of logged results with their initial predictions.
Zichuan Xiong, Head of AIOps at Thoughtworks, has led architecture and delivery work since 2008 and now builds agentic systems for software operations. He co-facilitates the cohort and the harness engineering training session at QCon San Francisco. Zichuan describes the engineering question:
"A coding agent can make a change quickly, but the harder question is what it was allowed to do and how we know the change is sound. We’ll build context and limit permissions before putting checks around an agent working in an existing codebase."
His co-facilitator, Premanand Chandrasekaran, Head of Technology at Thoughtworks, has spent two decades leading engineering teams focused on continuous delivery and internal quality. Premanand describes how the checks can become part of the workflow:
"Reviewing every agent change by hand does not tell us which checks should become part of the engineering workflow. We’ll put independent review and CI checks to work, then compare five weeks of results with what we expected at the start."
The confidential peer groups let participants compare their choices with senior engineers working under different constraints, such as probing whether a control addresses the risk it was chosen for, or showing what the harness catches and whether the logged results support the original prediction. The AI Security & Privacy Engineering and AI-Assisted Engineering pages provide full syllabi and cohort details.