One-day intensive · All labs · Runs twice
AI Engineering for Security Teams
Build. Secure. Apply.
Every function on a security team faces the same problem: too much data, too few analysts, and adversaries moving faster than manual workflows allow. AI can change that — but only if your team knows how to build, deploy and secure it.
Dates
Saturday 14 or
Sunday 15 November
Venue
AC Hotel Bellevue
Bellevue, Washington
Instructor
Michael Glass
Glass Security Consulting
Price
$1,900
per seat
Abstract
An intensive, all-labs training that teaches security professionals a proven framework for engineering AI into every facet of their security operations.
You'll build your own LLM-powered toolkits from scratch using open-source software — from data ingestion and warehousing through transformation and operational deployment. Every concept is applied immediately through hands-on labs against a custom pretrained model built specifically for this course.
Who it's for
Intermediate-level security professionals who want to apply AI to real operational challenges in enterprise and application security environments.
Enterprise & SOC
Enterprise security or SOC operations.
AppSec & DevSecOps
Application security and DevSecOps.
Hunting & detection
Threat hunting and detection engineering.
You don't need to be an AI expert, but you should be comfortable with security fundamentals and ready to level up — using AI to automate analysis, improve detection and strengthen response workflows.
What you'll
be able to do
Build
Immediately build and operationalise AI agents and frameworks using open-source software, covering models, training, agents, MCP, RAG, CAG and the full data pipeline.
Secure
Threat model and secure AI and LLM systems — the thing modern enterprises are struggling with — using practical knowledge drawn from some of the top companies in the world.
Apply
Use AI today to hunt malware, generate SIGMA and YARA rules, detect anomalies, enrich logs, reduce noise and respond to threats, on hands-on exercises with real security data.
Outline
Course outline
The day runs in three movements: build the tooling, attack and defend it, then put it to work on real scenarios.
Build
AI engineering fundamentals. You construct agents and frameworks you can take home and deploy, including how to handle the security-specific data types that break most general-purpose approaches. You'll prepare, transform and operationalise your own data so the output is relevant to your environment rather than generic.
Secure
Red and blue teaming your AI. Hands-on exercises against the systems you built in class — attacking and defending models, assessing supply chain vulnerabilities, applying modern security policy frameworks, and working through the adversary techniques targeting AI systems in production today.
Apply
AI across the entire security team. Using the tools built in class, you work through real-world scenarios drawn from challenges we've seen security teams struggle with globally.
Labs to expect
Detection & response
Generate high-quality YARA and SIGMA rules from your own data. Tune models to hunt complex patterns and filter noise to raise signal-to-noise across your environment.
Incident response
Hunt APTs using real-world scenarios and logs, and learn to track them with high-quality signals.
SOC operations
Improve observability by adding contextual intelligence to anomalous behaviour, and automate triage workflows that free analysts for higher-order work.
Security engineering
Build agentic AI pipelines, augment queries, eliminate unnecessary noise, and deploy AI-driven automation that integrates with your existing stack.
Every lab is performed live and in class by students. No slides-only sections, no toy demos. You leave with working frameworks, proven techniques, and the engineering skills to make AI operationally effective across your security organisation.
Before you
arrive
Prerequisites
A basic understanding of cybersecurity concepts — SOC, logs, alerts, threat intel — and of security frameworks and how they're applied. Familiarity with enterprise or application security workflows, general comfort with CLI tools and APIs, and familiarity with Git.
What to bring
A laptop running Linux, Windows or macOS. And your favourite caffeine.
Provided on the day: access to the AI labs and all training material. Audience skill level is intermediate.
Certificate
Every student who completes the training receives a continuing education certificate in both forms — a printed copy and a digital version you can file for CPE records or add to your LinkedIn profile.
Your trainer
Michael Glass
Founder · Glass Security Consulting
Michael, who goes by Bluescreenofwin, is a Principal Security Engineer working in the financial AI space. He has provided security leadership for some of the largest companies in the world, including one of the largest streaming technology companies.
He specialises in AI, blue team, SecOps and cloud. He founded Glass Security Consulting to bring world-class cybersecurity instruction to information security professionals and hackers alike.
- HandleBluescreenofwin
- RolePrincipal Security Engineer, financial AI
- FounderGlass Security Consulting
- Specialises
- AI
- Blue Team
- SecOps
- Cloud
Register
Pick your day · AC Hotel Bellevue, WA
A one-day 8 hour training, run twice. Saturday and Sunday.
Lunch is on us: $25 credit
The first 10 students to register for Michael’s training receive a one-time $25 lunch reimbursement. Grab lunch wherever you like, keep the receipt (physical or electronic), and bring it to me for a cash reimbursement.
Cancellations can be made without a fee before August 31. After August 31, $200 is subtracted from the refund to cover non-refundable fees.
Part of the November 14–15, 2026 event — see the full event, venue and other trainings on that weekend.