Zulia Shavaeva

AI security leader at AWS

Hi, I'm Zulia.

I help teams build and deploy AI securely. My work covers security reviews of AI applications, protecting sensitive data and controlling what agents can access.

I want AI to be easier to understand, and security easier to put into practice. I built this free guide so you can start from zero, build with AI or make informed decisions about it. There are specialist routes for security professionals too.

Free, no account. Try a short task, check your work and keep what you make.

Zulia Shavaeva, portrait by a lake

Start here

Learn AI and security

Start with what you want to do. The lessons and exercises here are free, with no account needed. Optional external courses may charge; these are labelled.

Zulia standing in front of a mossy cliff with a waterfall

About me

From software development to AI security

I lead security for the AWS Generative AI Innovation Center in EMEA. I work with delivery teams to review AI systems and deal with the risks before deployment.

I started in software development and taught algorithms and data structures at Durham University, where I studied Computer Science. At AWS I moved from DevOps into security, risk and compliance, then specialised in AI security. That is more than eight years across engineering and security, and more than a hundred engagements.

Day to day that means threat modelling and security reviews of AI applications, advice on data residency and retention, and checking what permissions teams hand to AI agents and their tools.

Teaching stayed part of the work. I run security workshops, and I mentor women moving into cloud and security. This guide is the foundation I wish someone had written down for me.

8+ yearsin software engineering, DevOps and security
100+engagements supported
40+scientists supported on AI engagement security
300+sign-ups to our community public-speaking programme

In practice

How I approach AI security

Security should be straightforward enough for people to understand, own and run. This is how I approach the work.

  1. 01

    Make security understandable

    I want teams to understand what a control does and how to use it. Explain the risk in plain language, make the safe way practical and check that it works in day-to-day delivery.

  2. 02

    Give people clear ownership

    A review is one point in time. Someone still has to run the system, handle incidents and keep the controls working. I care about clear owners and a culture where people can raise a problem early.

  3. 03

    Look across five layers

    I work through identity, data, the model, the application and infrastructure. Who can act? What can they access? How can the model fail? What checks does the application enforce? Where does it run? This is a way to organise the review, not a compliance standard.

  4. 04

    Check what agents can actually do

    Documents and tool responses can contain hostile instructions. I check what happens if the model follows one: what data it could reveal, which actions it could take and where the application requires approval. A prompt alone is not an access control.

  5. 05

    Build compliance into the design

    For AI, data use and accountability need attention from the start. I bring privacy, retention, residency and evidence into the design, with legal or compliance specialists where needed. A completed checklist does not prove the system is secure.

  6. 06

    Use frameworks to guide the work

    NIST AI RMF helps organise risk decisions, OWASP helps identify application risks and MITRE ATLAS helps map threats. I use them to ask better questions, choose controls and record evidence, with findings an engineer can reproduce and fix.

Speaking and teaching

Talks and community

I speak about AI security and help people prepare their first technical talk. Message me on LinkedIn about speaking or workshops.

  • GenAI security capture-the-flagSelected for AWS re:Invent 2026 GameDayAn AI security capture-the-flag exercise I wrote, covering prompt injection and data leaks through tool use.
  • Critical AWS security vulnerabilities: hiding in plain sightCommunity talk, ManchesterA talk on the AWS misconfigurations that survive a security review, and what to fix first.
  • Public-speaking programmeAWS Cloud Women ManchesterSupport for people preparing their first technical talk.
  • Security workshops for delivery teamsAWS Professional Services, EMEAHands-on sessions for customer-facing teams on securing GenAI engagements.
Zulia speaking to an audience beside a screen titled Critical AWS Security Vulnerabilities
Speaking at a community event in Manchester.

What I talk about

  • AI security foundations

    What traditional security still covers, and where models and agents introduce different risks.

  • Data and model attacks

    Poisoning, evasion and information leakage, explained through the system around the model.

  • Agents and their permissions

    Tool access, untrusted content and controls the application must enforce.

  • AI governance and compliance

    Turning obligations and risk decisions into ownership, controls and usable evidence.

  • Security operations and culture

    Clear responsibilities, incident handling and helping delivery teams own security.

  • Building and delivering AI

    Supply-chain risks and the trust boundaries involved when engineers work inside customer environments.

I help lead AWS Cloud Women Manchester. We run events and workshops for women learning cloud technology and developing their speaking skills. AWS Cloud Women Manchester on Meetup.

The full CV

My experience and selected work, with a downloadable PDF.