Certification Program

Under Construction.

Status: In Development

We are building something rigorous. The SecMLOps School certification program is in active development — a project-based online course for practitioners who need to secure ML systems in production.

Be notified when enrollment opens.

share://PostShare

The Program

What We Are Building

You inherit an insecure fraud-detection service and take it to production-grade on one pipeline track — GitHub Actions, GitLab CI, or Azure DevOps. Every lab is a milestone on that single project. The final deliverable is your repository, running through your pipeline, with every control proven. There is no separate exam project: the exam scenarios are the last three milestones.

FormatSelf-paced online course
LevelIntermediate to advanced
PrerequisitesWorking knowledge of ML systems and basic security concepts
OutcomeSecMLOps School certification credential
TracksGitHub Actions · GitLab CI · Azure DevOps
AvailabilityTo be announced

Curriculum

Course Modules

01

SecMLOps Foundations & Threat Landscape

Structured threat modeling for ML architectures. Trust boundaries, data flows, and adversarial objectives specific to AI-enabled systems. The baseline project is introduced and every security gap catalogued.

02

Platforms, Identity & Secrets

Eliminating static credentials from code and history. Workload identity, OpenBao secret injection, and branch protection on your chosen CI/CD track.

03

Data Security & Lineage

Data integrity gates, schema validation, and poisoning detection. Proving provenance from raw source through feature engineering to training artifact.

04

Secure Code Gates

SAST, dependency scanning, and secret detection on every pull request. Hardening the pipeline itself — pinned actions, least-privilege runners, and audit logging.

05

Model Robustness & Evaluation Gates

Automated robustness checks before model registration. Accuracy floors, adversarial perturbation budgets, and gating weak candidates before they reach the registry.

06

Model Registry & Governance

Weights-only serialization, cryptographic signing, and evidence-gated promotion. A tampered byte triggers MODEL-LOAD-DENIED before the model ever serves traffic.

07

Container Security & SBOM

Hardened base images, non-root execution, minimal attack surface, and automated SBOM and ML-BOM generation. Trivy gates block vulnerable images from advancing.

08

Signing, Attestation & Provenance

Cosign image signing, SLSA provenance attestation, and supply-chain verification. Rogue keys are rejected at the registry boundary.

09

Registry & Admission Control

OCI registry policy enforcement and Kubernetes admission webhooks. Unsigned images, mutable tags, and root-running containers are denied before deployment.

10

Zero-Trust Serving

mTLS between services, RBAC on the model API, and network policy enforcement. Anonymous requests are redirected; wrong-group requests return 403; bypass attempts are blocked.

11

Offensive Validation of Staging

Attacking the test environment to find what hardening missed. TLS downgrade, misconfigured RBAC, and exposed debug endpoints — red runs that drive green fixes.

12

Attacking Models in Production

Model extraction, membership inference, and adversarial evasion against the live fraud classifier. Detection alerts, rate-limit budgets, and input validation defenses.

13

Vulnerability Management & Detection

Centralised findings hub, VEX triage, runtime scanning, and anomaly detection. Proven VEX exemptions reduce open counts without hiding real risk.

14

Promotion, Incident Response & the Hotfix Loop

Full gate promotion to production, the hotfix branch workflow, and a structured incident report. A red build never reaches an approver.

15

The Full SecMLOps Pipeline

Reconstruct the complete pipeline from memory. Self-check against the reference solution and prove every threat from Milestone 1 is closed — with a red run and a green run.

// curriculum subject to revision prior to launch

Instructor

IMG

Antonio Gonzalez-Torres, Ph.D., CISSP, CSSLP, CCSP, Professional DevSecOps Professional

Founder and Instructor — SecMLOps School

Antonio Gonzalez-Torres has spent twenty-five years at the point where software, security, and machine learning meet. He built and shipped software for the SOC platform at Walmart Global Tech as a Software Engineer III (containerized microservices, Helm on hybrid Kubernetes, GitOps pipelines that cut time-to-production from ten days to under two hours), led cybersecurity automation at Equifax, and today designs ML pipelines as a data scientist at Cherokee Nation Entertainment. He holds a Ph.D. in Computer Science (University of Salamanca, summa cum laude), is completing an M.S. in Cybersecurity at NYU, and is CISSP, CSSLP, CCSP, and Certified DevSecOps Professional. As a professor at he has supervised 15 master's theses and over 100 capstones, published 50+ peer-reviewed papers, and taught Cisco, Microsoft, and programming certification tracks with pass rates around 90 %.

// Instructor details coming soon.

Early Access

Be First to Know.

Leave your email and we will notify you when enrollment opens — along with early access to curriculum previews and field resources.

No spam. Unsubscribe at any time.

SM
SecMLOps School

The definitive training ground for practitioners securing machine learning systems in production.

© 2026 SecMLOps School. All rights reserved.

secure_ml_ops://v1.0.0