AI security leader at AWS
Hi, I'm Zulia.
I help teams build and deploy AI securely. My work covers security reviews of AI applications, protecting sensitive data and controlling what agents can access.
I want AI to be easier to understand, and security easier to put into practice. I built this free guide so you can start from zero, build with AI or make informed decisions about it. There are specialist routes for security professionals too.
Free, no account. Try a short task, check your work and keep what you make.

Start here
Learn AI and security
Start with what you want to do. The lessons and exercises here are free, with no account needed. Optional external courses may charge; these are labelled.
Pick a learning route
New to AI or security? Start with the foundations. Or choose a route for developers, leaders, technical presales or sales. Each has lessons, a first task and a way to check your work.
See the routes →Explore an AI security career
Already work in technology or security? Answer 16 questions for a suggested specialist career path and study plan. The quiz does not assess job readiness or choose among the beginner routes.
Take the career quiz →Go deeper on one skill
Thirteen skill pages with reading, exercises and practice questions, plus seven specialist career paths. Free resources first; anything paid is labelled.
Open the Learn library →
About me
From software development to AI security
I lead security for the AWS Generative AI Innovation Center in EMEA. I work with delivery teams to review AI systems and deal with the risks before deployment.
I started in software development and taught algorithms and data structures at Durham University, where I studied Computer Science. At AWS I moved from DevOps into security, risk and compliance, then specialised in AI security. That is more than eight years across engineering and security, and more than a hundred engagements.
Day to day that means threat modelling and security reviews of AI applications, advice on data residency and retention, and checking what permissions teams hand to AI agents and their tools.
Teaching stayed part of the work. I run security workshops, and I mentor women moving into cloud and security. This guide is the foundation I wish someone had written down for me.
In practice
How I approach AI security
Security should be straightforward enough for people to understand, own and run. This is how I approach the work.
- 01
Make security understandable
I want teams to understand what a control does and how to use it. Explain the risk in plain language, make the safe way practical and check that it works in day-to-day delivery.
- 02
Give people clear ownership
A review is one point in time. Someone still has to run the system, handle incidents and keep the controls working. I care about clear owners and a culture where people can raise a problem early.
- 03
Look across five layers
I work through identity, data, the model, the application and infrastructure. Who can act? What can they access? How can the model fail? What checks does the application enforce? Where does it run? This is a way to organise the review, not a compliance standard.
- 04
Check what agents can actually do
Documents and tool responses can contain hostile instructions. I check what happens if the model follows one: what data it could reveal, which actions it could take and where the application requires approval. A prompt alone is not an access control.
- 05
Build compliance into the design
For AI, data use and accountability need attention from the start. I bring privacy, retention, residency and evidence into the design, with legal or compliance specialists where needed. A completed checklist does not prove the system is secure.
- 06
Use frameworks to guide the work
NIST AI RMF helps organise risk decisions, OWASP helps identify application risks and MITRE ATLAS helps map threats. I use them to ask better questions, choose controls and record evidence, with findings an engineer can reproduce and fix.
Speaking and teaching
Talks and community
I speak about AI security and help people prepare their first technical talk. Message me on LinkedIn about speaking or workshops.
- GenAI security capture-the-flagSelected for AWS re:Invent 2026 GameDayAn AI security capture-the-flag exercise I wrote, covering prompt injection and data leaks through tool use.
- Critical AWS security vulnerabilities: hiding in plain sightCommunity talk, ManchesterA talk on the AWS misconfigurations that survive a security review, and what to fix first.
- Public-speaking programmeAWS Cloud Women ManchesterSupport for people preparing their first technical talk.
- Security workshops for delivery teamsAWS Professional Services, EMEAHands-on sessions for customer-facing teams on securing GenAI engagements.

What I talk about
- AI security foundations
What traditional security still covers, and where models and agents introduce different risks.
- Data and model attacks
Poisoning, evasion and information leakage, explained through the system around the model.
- Agents and their permissions
Tool access, untrusted content and controls the application must enforce.
- AI governance and compliance
Turning obligations and risk decisions into ownership, controls and usable evidence.
- Security operations and culture
Clear responsibilities, incident handling and helping delivery teams own security.
- Building and delivering AI
Supply-chain risks and the trust boundaries involved when engineers work inside customer environments.
I help lead AWS Cloud Women Manchester. We run events and workshops for women learning cloud technology and developing their speaking skills. AWS Cloud Women Manchester on Meetup.
The full CV
My experience and selected work, with a downloadable PDF.