Zulia Shavaeva← Back to Zulia
Free AI and security guide/Learn

Learn / Paid options

Paid courses and certifications

7 of 48 postings name any certification, and in most of those it is listed as a plus, not a requirement. Free material covers the skills; what paid options add is structure, graded labs and a line on a CV that some screeners look for.

Costs, durations and prerequisites are copied from each provider's own page on the research date; "not stated" means the page did not say. Prices change; check before you pay.

Offensive certifications postings name

Cost
USD 1,749 once (Course + Cert Bundle, 90 days access, one exam attempt); USD 2,749/year (Learn One, one year access, two exam attempts); USD 1,699 once for the OSCP+ standalone exam
Duration
321h of content; 20+ modules plus 9 challenge labs; exam is 24 hours proctored
Format
self-paced
Prerequisite
As stated: no hard prerequisite, but OffSec suggests hands-on practical knowledge of Linux and Windows administration, networking and network scripting
Renewal
OSCP has no expiration date; the OSCP+ designation expires 3 years from issuance
In the 48 postings
Named in 2 of 48 postings: Sr. AI Red Team Engineer (listed); AI Red Team Engineer for LLM Security (required, one of a list).

Adds over free material: Gives the proctored 24-hour exam and the AD and AWS challenge labs that hiring managers in the two AI red team postings treat as the entry filter.

Free already covers: Enumeration, privilege escalation and the web attacks in the syllabus are all reachable free through PortSwigger Web Security Academy, HackTricks and free TryHackMe/HTB rooms, with no exam.

Cost
Starting at USD 1,749 (OffSec's Course + Cert Bundle price for a 200 or 300-level course); USD 2,749/year for Learn One
Duration
671h of content; 20+ modules plus 7 challenge labs
Format
self-paced
Prerequisite
As stated: completion of PEN-200 and a passed OSCP+, or equivalent knowledge and experience
In the 48 postings
Named in 2 of 48 postings: Sr. AI Red Team Engineer (listed); AI Red Team Engineer for LLM Security (required, one of a list).

Adds over free material: Teaches EDR and AV evasion, custom toolchains and in-memory payload delivery against hardened enterprise targets, which free labs rarely instrument realistically.

Free already covers: Public tradecraft writeups, MITRE ATT&CK technique pages and open source loaders cover much of the theory, but not a graded hardened environment.

Cost
Starting at USD 1,749 (as listed on the EXP-301 page)
Duration
932h of content (level 300)
Format
self-paced
Prerequisite
Not stated on the pages we could read; OffSec describes EXP-301 as an intermediate-level exploit development course
In the 48 postings
Named in 1 of 48 postings: Sr. AI Red Team Engineer (listed).

Adds over free material: Builds ROP chains, DEP and ASLR bypasses and read/write primitives with grading, which matters if your AI target includes native inference runtimes or C/C++ model loaders.

Free already covers: Free exploit development series and CTF binary challenges teach the same primitives without a certification or a fixed lab set.

Cost
USD 1,749 once (Course + Cert Bundle) or USD 2,749/year (Learn One), per OffSec's pricing page for any 200 or 300-level course
Duration
not stated
Format
self-paced
Prerequisite
Not stated on the pages we could read; OffSec positions WEB-300 as an advanced white box web application course
In the 48 postings
Named in 1 of 48 postings: AI Red Team Engineer for LLM Security (required, one of a list).

Adds over free material: Source code review, .NET deserialization, blind SQLi and authentication bypass chains under exam conditions, the skill set you need when the LLM feature is bolted onto a web app.

Free already covers: PortSwigger Web Security Academy covers SSRF, XSS, SQLi and auth bypass labs free, and OWASP guidance covers the review method.

CRTO (Red Team Ops)Zero-Point Security, certification
Cost
GBP 365 is listed against Red Team Ops on Zero-Point's legacy training site course list; the current course page stated no price in the text we could read
Duration
Study time: 20 hours (as stated on the course page)
Format
self-paced
Prerequisite
None stated; the course page lists the level as Practitioner
Renewal
None stated; the page states lifetime access, course updates at no extra cost, lab access with no expiry, and unlimited free exam attempts
In the 48 postings
Named in 1 of 48 postings: Sr. AI Red Team Engineer (listed).

Adds over free material: Hands-on Cobalt Strike adversary simulation with a licensed copy provided in the labs, plus unlimited exam retries at no extra cost.

Free already covers: Free C2 frameworks, Active Directory attack labs and public adversary emulation plans cover the concepts, but not licensed Cobalt Strike practice.

Cost
not stated on the provider page
Duration
11 modules; self-paced, sold by access duration (lab extensions in 30-day increments for Course & Cert Bundle learners)
Format
self-paced
Prerequisite
As stated: advanced level, for experienced cybersecurity practitioners, red teamers and AI professionals; solid cybersecurity fundamentals and basic familiarity with AI systems including LLMs
Renewal
OSAI does not expire; the OSAI+ designation expires 3 years from issuance, maintained by one of three continuing education paths. Passing OSAI+ may qualify for 40 CPE points, self-submitted to ISC2
In the 48 postings
Not named in any of the 48 postings.

Adds over free material: The first graded, proctored AI red team exam from a provider the two AI red team postings already name, against live LLM and agent-integrated targets.

Free already covers: OWASP LLM Top 10, prompt injection writeups and free CTF-style prompt hacking games cover most attack classes with no proctored assessment.

Cost
not stated on the provider page
Duration
3 days instructor-led or 18 hours self-paced; 18 CPEs
Format
mixed
Prerequisite
None stated; the page requires a bring-your-own 64-bit Intel system with VT-x, 16 GB RAM, 100 GB free disk and VMware Workstation Pro 17+ or Fusion Pro 13+, and states Apple Silicon cannot be used
Renewal
Not stated on the course page
In the 48 postings
Not named in any of the 48 postings.

Adds over free material: Twenty-one hands-on exercises in a keepable VM covering direct and indirect prompt injection, RAG exploitation, agentic systems, MCP server attacks and AI architectural flaws, with an exam behind it.

Free already covers: OWASP GenAI guidance, MITRE ATLAS and public prompt injection research describe the same attack classes, and open MCP servers can be attacked locally for free.

Governance, general and cloud certifications postings name

Cost
USD 799 non-member, USD 649 member (exam only). Optional AIGP online training is USD 1,195 non-member / USD 995 member, 13 CPEs.
Duration
100 questions, 2.75 hours plus a 15-minute break; exam must be taken within one year of purchase
Format
exam only
Prerequisite
none stated
Renewal
2-year term; 20 continuing education credits plus a maintenance fee (covered by IAPP membership, otherwise USD 250 at recertification)
In the 48 postings
Named in 1 of 48 postings: a plus.

Adds over free material: It forces one structured pass over AI law, risk and lifecycle governance vocabulary and gives a credential that governance hiring managers already recognise.

Free already covers: The NIST AI Risk Management Framework, the EU AI Act text, ISO/IEC 42001 summaries and OWASP LLM guidance are free and cover most of the same subject matter.

Cost
USD 550 per exam (CIPP/A, CIPP/C, CIPP/CN, CIPP/E, CIPP/US), list price on the IAPP store
Duration
not stated
Format
exam only
Prerequisite
none stated
In the 48 postings
Named in 1 of 48 postings: a plus.

Adds over free material: Gives the privacy law grounding that AI governance work keeps running into, in a jurisdiction-specific form (EU, US, Canada, Asia).

Free already covers: Regulator guidance and the statutes themselves (GDPR text, state privacy laws, EDPB opinions) are free to read.

Cost
not stated on the provider page
Duration
90-question exam; six-month eligibility period from registration to sitting the exam
Format
exam only
Prerequisite
An active CISM or CISSP certification is required, plus a US$50 application processing fee; five years from passing the exam to apply
Renewal
ISACA Continuing Professional Education policy applies; the annual credit number is not stated on the page we fetched
In the 48 postings
Not named in any of the 48 postings.

Adds over free material: It is the only AI-specific management credential that sits directly on top of CISM or CISSP, covering AI governance and programme management, AI risk, and AI technologies and controls in three exam domains.

Free already covers: The same ground is largely covered free by the NIST AI RMF, OWASP's LLM and agentic security material and ISO/IEC 42001 overviews.

Cost
USD 749 (US and all regions not otherwise listed, and Asia Pacific, Middle East, Africa); EUR 719.04 in EMEA; GBP 606.69 in the UK. Reschedule USD 50, cancellation USD 100.
Duration
not stated
Format
exam only
Prerequisite
5 years required work experience, stated on the certification page. Exam-only purchase must be scheduled and sat within 365 days.
In the 48 postings
Named in 3 of 48 postings: Cyber - AI Security - Senior - Consulting (a plus); Information Security Architect - AI (listed); Security Engineer, AI (a plus).

Adds over free material: Covers the eight domains an AI security architect is expected to already know, including IAM, security architecture and engineering, and software development security, and is the credential most often listed by name in the GRC and architect postings here.

Free already covers: Nothing free replaces the credential itself, but the underlying material (NIST SP 800 series, cloud provider architecture guidance, OWASP) is all free.

Cost
USD 599 (US and all regions not otherwise listed, and Asia Pacific, Middle East, Africa); EUR 575.04 in EMEA; GBP 485.19 in the UK
Duration
not stated
Format
exam only
Prerequisite
not stated on the pages we read
In the 48 postings
Named in 2 of 48 postings: Cyber - AI Security - Senior - Consulting (a plus); Secure AI Engineer Manager (listed).

Adds over free material: Vendor-neutral cloud security coverage that satisfies the generic 'cloud security cert' wording in the field delivery posting without committing to one provider.

Free already covers: CSA Cloud Controls Matrix and the free guidance from AWS, Azure and Google cover the same control areas at no cost.

Cost
not stated on the provider page
Duration
150-question exam covering four job practice domains
Format
exam only
Prerequisite
Pass the exam, pay the US$50 application processing fee, and submit an application demonstrating experience requirements; the years of experience are not stated on the page we fetched
Renewal
ISACA Continuing Professional Education policy applies; credit numbers not stated on the page we fetched
In the 48 postings
Named in 2 of 48 postings: Cyber - AI Security - Senior - Consulting (a plus); Information Security Architect - AI (listed).

Adds over free material: Management-level framing of security programme, risk and incident management, which is the language the GRC and consulting postings in this set use, and it is the prerequisite route into AAISM.

Free already covers: NIST Cybersecurity Framework, NIST AI RMF and ISO summaries cover the concepts free; what you buy is the exam and the credential.

Cost
not stated on the provider page
Duration
Six-month eligibility period from registration to sitting the exam
Format
exam only
Prerequisite
Pass the exam, pay the US$50 application processing fee, submit an application demonstrating experience requirements, and comply with the Information Systems Auditing Standards
Renewal
ISACA Continuing Professional Education policy applies; credit numbers not stated on the page we fetched
In the 48 postings
Named in 1 of 48 postings: Information Security Architect - AI (listed).

Adds over free material: Audit and control testing discipline, which is what AI model and pipeline assurance work actually looks like day to day.

Free already covers: Control catalogues (NIST SP 800-53, ISO summaries) and AI audit guidance published free by standards bodies cover much of the content.

CompTIA Security+CompTIA, certification
Cost
not stated on the provider page
Duration
not stated
Format
exam only
Prerequisite
none stated
In the 48 postings
Named in 1 of 48 postings: a plus.

Adds over free material: Entry-level coverage of core security functions for people crossing in from IT or development rather than from a security role.

Free already covers: Free vendor and community training covers the same fundamentals; nothing in Security+ V7 is AI-specific.

AWS Certified Security - Specialty (SCS-C02)Amazon Web Services, certification
Cost
300 USD
Duration
170 minutes, 65 multiple choice or multiple response questions
Format
exam only
Prerequisite
No certification prerequisite. AWS states it is intended for people with five years of IT security experience and two or more years securing AWS workloads.
Renewal
Valid for 3 years; recertify by passing the latest version of the exam
In the 48 postings
Named in 2 of 48 postings: Sr. Security Solutions Architect, AI-Applied Guidance (a plus); Secure AI Engineer Manager (listed).

Adds over free material: Tests the IAM, encryption, data protection and detection controls you need to reason about when an AI workload runs on Bedrock, SageMaker or EKS, and it is the cert the AWS-facing architect posting named.

Free already covers: AWS Skill Builder digital courses, the free exam guide PDF and AWS security documentation cover the syllabus without payment.

AI-specific paid training (not named by any posting)

Cost
not stated on the provider page
Duration
3 days instructor-led or 18 hours self-paced, 18 CPEs
Format
mixed
Prerequisite
none stated; you must bring a laptop meeting the stated spec (64-bit Intel i5/i7, Intel VT enabled, 16 GB RAM, 100 GB free, VMware Workstation Pro 17+ or Fusion Pro 13+; Apple Silicon is explicitly not supported)
In the 48 postings
Not named in any of the 48 postings.

Adds over free material: A retained VM with 21 exercises (15 full labs, 5 mini labs, a setup lab) plus Marimo workbooks covering direct and indirect prompt injection, RAG exploitation, agentic systems, MCP server attacks and AI API flaws, with a proctored GIAC exam (GAIPT) behind it.

Free already covers: OWASP Top 10 for LLM Applications, MITRE ATLAS and Microsoft's free AI Red Teaming 101 material on Microsoft Learn already list the same attack classes and PyRIT gives you free tooling to try them.

Cost
not stated on the provider page
Duration
7 hours self-paced, 7 CPEs
Format
self-paced
Prerequisite
at least intermediate Python; 16 GB RAM, 20 GB free disk, Rancher Desktop or Docker (Intel and ARM both supported); internet access needed during class
In the 48 postings
Not named in any of the 48 postings.

Adds over free material: Dockerised labs where you build RAG, contextual RAG and agentic RAG yourself and wire in access-control enforcement and prompt-injection defences, so you can review a retrieval pipeline you have actually built.

Free already covers: Vendor and framework docs plus OWASP LLM guidance already explain RAG architecture and the injection risks at concept level, and open tutorials show how to stand a RAG stack up.

Cost
not stated on the provider page
Duration
3 days instructor-led or 18 hours self-paced, 18 CPEs
Format
mixed
Prerequisite
not stated
In the 48 postings
Not named in any of the 48 postings.

Adds over free material: Structured practice in using AI tooling as part of an offensive engagement, with the GIAC Offensive AI Analyst (GOAA) exam as the proof point.

Free already covers: Open-source offensive AI tooling, conference talks and the MITRE ATLAS case studies cover most of the individual techniques without a fee.

Cost
HTB Academy subscription rates from 12 October 2026: Student $10/mo, Silver $30/mo, Gold $95/mo, Platinum $125/mo, Silver Annual $550/yr (EUR 469 / GBP 416), Gold Annual $1,400/yr (EUR 1,195 / GBP 1,060); individual modules can still be bought with cubes and this path requires 970 cubes
Duration
12 modules, 230 sections; no hour estimate given
Format
self-paced
Prerequisite
none stated; path difficulty is listed as Hard and modules run Medium to Hard
In the 48 postings
Not named in any of the 48 postings.

Adds over free material: Graded browser labs that take you from ML fundamentals through prompt injection, output handling abuse, data-pipeline poisoning and gradient-based adversarial attacks, aligned to Google's Secure AI Framework, with an exam-backed certificate at the end.

Free already covers: Free playgrounds such as prompt-injection challenge sites, OWASP LLM and Agentic guidance, and Microsoft's free AI Red Teaming 101 series cover the same attack list without labs that are graded.

Certified AI Security Professional (CAISP)Practical DevSecOps, certification
Cost
not stated on the provider page
Duration
7 chapters, 30+ guided exercises, 60 days browser-based lab access, 36 CPE points, one exam attempt included
Format
self-paced
Prerequisite
basic Linux command line (ls, cd, mkdir); familiarity with Python, Go or Ruby helps but is not required
In the 48 postings
Not named in any of the 48 postings.

Adds over free material: Hands-on labs that pair the OWASP LLM Top 10 and MITRE ATLAS tactics with things you build and break yourself (chatbot, fine-tuned model, RAG system, TextAttack and BackdoorBox exercises) plus an exam and lifetime instructor support channel.

Free already covers: The OWASP LLM Top 10 and MITRE ATLAS are free and already give the taxonomy, mitigations and real incident write-ups this syllabus is organised around.

Certified MCP Security Expert (CMCPSE)Practical DevSecOps, certification
Cost
not stated on the provider page
Duration
30+ guided exercises, 60 days browser-based lab access, 36 CPE points, one exam attempt included
Format
self-paced
Prerequisite
not stated
In the 48 postings
Not named in any of the 48 postings.

Adds over free material: One of the few paid exams scoped to Model Context Protocol specifically: attacking, assessing and hardening MCP servers including tool poisoning, prompt injection, supply chain and agentic defences.

Free already covers: The MCP specification, OWASP agentic security guidance and public MCP tool-poisoning research already describe these attack patterns, and you can run a vulnerable MCP server locally for free.

CompTIA SecAI+ (CY0-001 V1)CompTIA, certification
Cost
not stated on the provider page
Duration
60-minute exam, maximum 60 multiple-choice and performance-based questions; CertMaster Perform is listed at 30-60 hours and CertMaster Labs at 15-25 hours
Format
exam only
Prerequisite
recommended 3-4 years in IT with 2+ years hands-on cybersecurity, and Security+, CySA+, PenTest+ or equivalent
In the 48 postings
Not named in any of the 48 postings.

Adds over free material: A single vendor-neutral exam that covers securing AI systems (40% of the exam), AI-assisted security operations (24%) and AI GRC (19%), useful where an employer or contract wants a named credential rather than a portfolio.

Free already covers: NIST AI RMF, ENISA and CISA guidance, plus free vendor learning paths, cover the same governance and AI-in-SOC ground; the exam objectives PDF is itself free to read.

Cost
not stated on the provider page
Duration
16 hours on-demand, 16 CPE credits, six courses plus assessments
Format
self-paced
Prerequisite
familiarity with cybersecurity principles, roles and frameworks recommended but not required
In the 48 postings
Not named in any of the 48 postings.

Adds over free material: CPE credit and a Credly badge for structured coverage of AI regulation alignment, secure-by-design AI planning and AI blind spots in security tooling, which suits GRC leads who need ISC2 CPEs anyway.

Free already covers: NIST AI RMF, the EU AI Act text, ISO/IEC 42001 summaries and free regulator guidance cover the alignment and governance content without a fee.

Cost
not stated on the provider page
Duration
11 modules, self-paced; sold via Course and Cert Exam Bundle, Learn One or Learn Enterprise from 31 March 2026; lab extensions in 30-day increments for bundle learners
Format
self-paced
Prerequisite
advanced level: solid cybersecurity fundamentals and basic familiarity with AI systems including LLMs; aimed at experienced practitioners, red teamers and AI professionals
Renewal
OSAI does not expire; the OSAI+ designation expires 3 years from issuance and is maintained through one of three continuing education paths
In the 48 postings
Not named in any of the 48 postings.

Adds over free material: A proctored offensive exam against AI-integrated environments from the vendor whose other certs the red-team postings do ask for, worth 40 ISC2 CPE points on a pass.

Free already covers: Microsoft's free AI Red Teaming material and PyRIT, plus OWASP LLM guidance and public jailbreak research, teach the techniques; what you cannot get free is the graded exam.

Cost
not stated on the provider page
Duration
not stated on the page I fetched; the AIRTP+ exam is a 24-hour practical assessment and the on-demand version of the masterclass is listed as 25 hours
Format
mixed
Prerequisite
not stated
In the 48 postings
Not named in any of the 48 postings.

Adds over free material: Practice in the HackAPrompt playground with instructors from Microsoft's AI Red Team and top bug bounty hunters, plus explicit training in writing up reproducible findings and impact, which is the part clients pay for.

Free already covers: Free HackAPrompt-style challenge playgrounds, the team's own published research and OWASP LLM guidance cover prompt injection and jailbreak technique at no cost.