Five tracks, built backward from real AI security job postings. Every module ends in something you can show a hiring manager, not just a box you ticked.
This outline turns the five-track model into concrete modules. Each module is anchored to a skill that shows up repeatedly in real offense, defense, and detection job descriptions, and each one produces a demonstrable artifact: a solved challenge, a tool campaign, a hardened app, or a framework-aligned report. Content is deliberately not the moat, since everyone teaches the same frameworks. The moat is rigor, reputation, and results a candidate can point to.
We lead with Offense because it is the newest role, has the lowest barrier to entry, and is the easiest to show off. Defense, Governance, Adversarial ML, and Supply Chain are mapped here so the full path is visible, and so the government and defense audience can see where the procurement-recognized language lives.
Modules are reverse-engineered from the skills and named tools that recur across real AI security listings, so learning maps directly to hiring.
You finish a module by producing an artifact: a challenge solve, a testing campaign, a defended app, or a report. That artifact is the credential.
Guild Marks accrue as you go. Mastering a track opens the door to the flagship Guild Seal, the proctored credential that carries real weight.
The tech-focused incumbents teach the same frameworks, but they were built for engineers and are not set up to speak to commanders or align with defense procurement. This curriculum deliberately runs the same student from a browser-based first jailbreak all the way to a NIST-aligned authorization package. That arc is the differentiator: it produces people who can both break an AI system and explain the risk in the language a program office signs against.
Every module here is scoped to end in a portfolio artifact, because that is what AI security actually hires on. The certificate is the record of the work, never a substitute for it.