AI Security

AI-Driven SOC Engineer

Master AI and machine learning in security operations — use LLMs, Security Copilots and autonomous AI agents to automate L1/L2 triage, threat hunting and incident response.

Duration4 Weeks
LevelIntermediate to Advanced
FormatLive Online

LEARNING OUTCOMES

What you will learn

1

LLMs and AI agents for security operations

2

AI-powered SIEM/XDR triage and enrichment

3

Autonomous SOC agents with LangChain and CrewAI

4

AI-driven SOAR playbooks and threat intel automation

Curriculum

Module 1 · Foundations of AI in Security Operations

Traditional vs AI-driven SOC, ML & deep learning basics, LLMs in cyber defense, alert prioritization and summarization, ethical AI and data privacy; labs with Python, OpenAI/Claude APIs and local LLMs (Ollama)

Module 2 · AI-Powered SIEM & XDR Integration

Microsoft Security Copilot, Splunk AI, Elastic AI, generative AI with SIEM/XDR, automated log analysis and alert enrichment, noise reduction and true-positive identification

Module 3 · Building Autonomous SOC Agents (L1 Automation)

AI agents with LangChain, AutoGen and CrewAI, designing an autonomous L1 agent, function calling and tool use, agentic alert workflows, human-in-the-loop guardrails

Module 4 · AI in SOAR & Automated Playbooks

AI-driven SOAR, dynamic incident-response playbook generation, auto-isolating hosts and revoking tokens, automated stakeholder notification and root-cause summarization

Module 5 · Threat Intelligence Enrichment with AI

Processing unstructured threat feeds, automatic IoC extraction, mapping TTPs to MITRE ATT&CK, synthetic threat scenario and attack simulation generation

Module 6 · Securing AI & Adversarial AI Threats

Prompt injection, data poisoning and model inversion, securing LLM API keys and pipelines, adversarial attacks on AI detectors, NeMo Guardrails and Llama Guard

Module 7 · Capstone Project

Build an end-to-end AI-powered SOC automation engine: ingest alerts, query threat-intel tools, auto-generate root-cause queries, produce incident reports and recommend or execute remediation

Tools covered: OpenAI API, Claude API, Ollama, LangChain, LlamaIndex, CrewAI, Python & Jupyter, Microsoft Sentinel & Defender XDR, Microsoft Security Copilot, KQL, SPL, VirusTotal & Threat Intel APIs

Program experience

Each cohort combines instructor-led sessions, guided practice, weekly assignments, capstone work and career preparation.