AI Security
AI-Driven SOC Engineer
Master AI and machine learning in security operations — use LLMs, Security Copilots and autonomous AI agents to automate L1/L2 triage, threat hunting and incident response.
LEARNING OUTCOMES
What you will learn
LLMs and AI agents for security operations
AI-powered SIEM/XDR triage and enrichment
Autonomous SOC agents with LangChain and CrewAI
AI-driven SOAR playbooks and threat intel automation
Curriculum
Traditional vs AI-driven SOC, ML & deep learning basics, LLMs in cyber defense, alert prioritization and summarization, ethical AI and data privacy; labs with Python, OpenAI/Claude APIs and local LLMs (Ollama)
Microsoft Security Copilot, Splunk AI, Elastic AI, generative AI with SIEM/XDR, automated log analysis and alert enrichment, noise reduction and true-positive identification
AI agents with LangChain, AutoGen and CrewAI, designing an autonomous L1 agent, function calling and tool use, agentic alert workflows, human-in-the-loop guardrails
AI-driven SOAR, dynamic incident-response playbook generation, auto-isolating hosts and revoking tokens, automated stakeholder notification and root-cause summarization
Processing unstructured threat feeds, automatic IoC extraction, mapping TTPs to MITRE ATT&CK, synthetic threat scenario and attack simulation generation
Prompt injection, data poisoning and model inversion, securing LLM API keys and pipelines, adversarial attacks on AI detectors, NeMo Guardrails and Llama Guard
Build an end-to-end AI-powered SOC automation engine: ingest alerts, query threat-intel tools, auto-generate root-cause queries, produce incident reports and recommend or execute remediation
Tools covered: OpenAI API, Claude API, Ollama, LangChain, LlamaIndex, CrewAI, Python & Jupyter, Microsoft Sentinel & Defender XDR, Microsoft Security Copilot, KQL, SPL, VirusTotal & Threat Intel APIs
Program experience
Each cohort combines instructor-led sessions, guided practice, weekly assignments, capstone work and career preparation.