Founding Cohort — Now Forming

The researchers who analyze the breaches are the ones who teach the response.

ODA3 Institute curriculum is built by researchers who analyzed the actual breaches — not career trainers who studied them afterward. The research team that forensically reconstructed the OAuth pivot attack chain is the same team building the AI Incident Response curriculum. There is no separation between research and teaching at ODA3 Institute because the research is the teaching.

ODA3 Institute is forming its founding faculty and research team. Founding instructors do not inherit a curriculum — they help develop it from cited public-source research and published framework requirements.

All faculty applications are reviewed by the ODA3 Institute research team. Appointments are confirmed based on verified production experience, domain expertise, and alignment with ODA3 Institute's evidence standards. Academic-only backgrounds without production experience are not eligible for instructor roles.
Faculty Overview

Learn from researchers, not trainers.

ODA3 Institute faculty are active researchers and standards contributors — not career trainers. They analyzed the vulnerabilities they teach practitioners to defend against, and they wrote the controls they teach practitioners to implement. ODA3 Institute was established in March 2026. We are forming our founding faculty cohort now — the standard below reflects what every faculty member is held to from the first appointment, not a target we are working toward.

Appointment standard

Every faculty appointment requires verified production experience in the relevant domain. Academic-only backgrounds are not eligible for instructor roles.

Curriculum standard

Every curriculum element is expected to identify a cited source basis and an applicable framework control or learning objective.

Update standard

Curriculum review is planned quarterly and upon material source or framework changes. Faculty may contribute documented research updates within their domain.

Evidence standard

Faculty research contributions are evidence-tiered to the same standard as ODA3 Institute published research — Primary Verified, Secondary Verified, Reported, Estimate.

These are not aspirational standards. They are appointment criteria. Every ODA3 Institute faculty member is held to all four from the first day of their engagement.

Founding Cohort

Roles we are building — now open for application.

These are recruiting profiles, not existing faculty. Founding faculty are expected to help develop the planned curriculum from cited public incident analysis and ODA3 Institute normative controls. Contributor recognition will follow the applicable appointment and publication terms.

ASDASO

AI Security Architect

Practitioners who have designed and implemented AI security controls in production — token lifecycle management, OAuth security architecture, agentic pipeline defense, AI supply chain assurance.

Builds: OC-AISF through OC-AISEX — 11 courses in the ASD Foundation–Expert curriculum.

Minimum: 5 years production implementation experience.

ACSCDF

SOC & Detection Leader

Practitioners who have deployed AI-augmented threat detection, behavioral baseline monitoring, AI-mediated breach forensics, or incident response for AI system compromises.

Builds: 25 courses across the ACS and CDF domains.

Minimum: 5 years SOC leadership, detection engineering, or DFIR — active incident response required.

ASOASD

AI Security Researcher

Researchers who have documented real AI attack chains — prompt injection, model extraction, distillation attacks, MCP exploitation, or agentic escalation.

Builds: 9 courses — AI Red Teaming Foundation through Full-Scope AI Red Team Operations Expert.

Minimum: Verified original research with publication record, CVE attribution, or documented incident contribution.

GRCALS

AI Governance & Compliance Practitioner

Practitioners who have implemented AI governance frameworks — EU AI Act readiness, ISO 42001 certification, NIST AI RMF deployments, or board-level AI risk reporting.

Builds: 9 courses, GRC Foundation through Board-Level AI Risk Reporting Expert — the highest-urgency domain given the the amended EU AI Act timetable EU AI Act deadline.

Minimum: 5 years direct regulatory implementation experience.

ISASFD

Industry AI Specialist

Practitioners who have deployed or secured AI systems in regulated industry environments — financial services, healthcare, critical infrastructure, or government and defense.

Builds: 20 courses spanning financial services, healthcare, government, critical infrastructure, and sustainability — the broadest domain in the curriculum.

Minimum: 5 years in a regulated industry with direct AI deployment or security responsibility.

Opportunities

Four roles. One founding cohort. Permanent recognition in everything ODA3 Institute publishes.

The cohort closes when all domain positions are filled — not on a fixed date.

Full-time

Research Fellow

Leads source-bounded AI security research, public incident analysis, normative control development, and published research output. The most senior research role in the founding cohort.

Qualifications: Demonstrated original research capability, verifiable prior incident analysis, publication record in AI security or adversarial ML. PhD not required.

10–15 hrs/week

Standards Contributor

Drafts SHALL/SHOULD/MAY control specifications, conducts control validation cycles, and develops crosswalk mappings to NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, EU AI Act, GDPR, and MITRE ATLAS. The control specification is the product — not a summary, not guidance.

Qualifications: Working knowledge of at least two aligned regulatory frameworks. Independence declaration required.

Project-based

Instructor

Develops and delivers ODA3 Institute training programs, workshops, and certification examinations. Instructors are practitioners first — they deliver curriculum they have personally implemented in production.

Qualifications: Minimum 5 years practitioner experience in the target domain. Production implementation experience is non-negotiable.

5–10 hrs/month

Industry Advisor

Senior practitioner role providing real-world context, implementation feedback, and industry relevance validation. Not an honorary title — a documented contribution role with specific deliverables and a standing documented research-contribution expectation.

Qualifications: Active CISO, Security Architect, AI Governance Lead, Compliance Officer, or equivalent role.

Pedagogy

The teaching philosophy every ODA3 Institute faculty member is held to.

Four principles intended to apply consistently across the planned nine-domain curriculum. A faculty member who cannot demonstrate all four in their trial curriculum contribution is not appointed.

Research-to-Practice

Every module is expected to identify its public-source basis and relevant normative control specifications.

Test: can you trace each teaching scenario to a cited source, documented limitation, and applicable control requirement?

Adversarial Mindset

Curriculum applies MITRE ATT&CK and MITRE ATLAS techniques to cited public incident material before developing defensive exercises.

Test: can you demonstrate the attack chain before you teach the defense?

Standards Literacy

Practitioners learn SHALL/SHOULD/MAY semantics per RFC 2119, control rationale tied to incident evidence, and crosswalk mapping across six regulatory frameworks — the actual normative specification language, not checklists.

Test: can you explain SHALL vs. SHOULD to a compliance officer who has never read RFC 2119?

Evidence-Review Currency

The planned curriculum will be reviewed when material public evidence, standards, or ODA3 framework requirements change.

Test: can you document the source change, its relevance, and the resulting module update?

Founding Cohort

Domain coverage status.

Nine planned training domains and ninety-five courses in curriculum development. Status updates as curriculum and faculty gates are completed.

DomainCodeCoursesFaculty status
AI Security: DefensiveASD11Open — priority launch domain
AI Security: Offensive & Red TeamingASO9Open — priority launch domain
AI Foundations & ToolingAFT13Open
Applied AI for CybersecurityACS13Open — priority launch domain
Cybersecurity & DFIRCDF12Open
Governance, Risk & ComplianceGRC9Open — highest urgency · the amended EU AI Act timetable EU AI Act deadline
AI Leadership & StrategyALS10Open
Startup & FounderSFD5Open
Industry-Specific AI & SecurityISA20Open
Founding Cohort

Apply as a Founding Instructor.

Founding Instructor status carries permanent recognition in all published curriculum, access to the applicable cited research materials and control framework during development, co-authorship credit, and revenue participation from curriculum you build — disclosed in full at appointment. Applications are reviewed on a rolling basis. Apply now regardless of your domain's launch priority — founding status is determined by appointment order, not development start date.

Minimum qualification: 5 years verified practitioner experience in AI security, cybersecurity, AI governance, or a regulated industry domain. Production implementation experience required — not lab environments, not academic projects. ODA3 Institute verifies instructor credentials before appointment using the same rigor applied to research findings.

Process: Submit application → Credential verification (14 days) → Domain assessment call (60 minutes) → Trial curriculum contribution → Founding appointment. Total process: approximately 6–8 weeks.

ODA3 Institute verifies every credential claim before appointment. Fabricated experience, misrepresented qualifications, or undisclosed conflicts of interest result in permanent ineligibility. All faculty engagements are governed by GEL v1.0. Faculty enquiries via the Contact page. Response within 5 business days.