Tools for Building an AI-Enabled SOC
Building an effective security operations capability such as a security operations center (SOC) has always been a challenging endeavor. Balancing the need to successfully integrate the people, processes, and technologies required to support your mission requires a deep understanding of your network and your threat landscape. New AI tools and technologies present both challenges and opportunities. These tools can complicate your operational environment but might be used by malicious actors to enhance their attacks. But AI can also be leveraged to build out and enable your SOC by covering gaps in tools, your workforce, and automation.
What Will Attendees Learn?
How AI has changed the way SOC teams operate
Ways to deploy AI tools in security operations settings
How the SEI is using structured knowledge to build more effective SOCs
Speaker Details
Dr. Justin Novak
A Senior Security Operations
Researcher in the CERT Division of the Software Engineering Institute (SEI), who
leads a team as part of the Security Operations Division that supports the U.S.
Department of State, Department of War, and United States Treasury. In this
role, his main focus is on capacity building for incident responders—both at
the individual and organizational level. At the SEI, he is also involved in
research on the development and operation of Computer Security Incident
Response Teams (CSIRTs), Sector CSIRTs, and SOCs, focusing on incident response
and incident management.
Christopher Ian Rodman
A Senior Cybersecurity Operations Researcher within the CERT Division of the Software Engineering Institute, where he supports U.S. government agencies in strengthening the operational capacity of international Computer Security and Incident Response Teams (CSIRTs) for U.S. allies and partner nations. His work focuses on advancing incident response readiness, security operations maturity, and analytical tradecraft for teams operating in complex threat environments. His technical background spans database and infrastructure administration, application performance engineering, crisis management, incident response, data loss prevention, and vulnerability management, supported by an MS in Information Security and Assurance from Robert Morris University.
Since joining the Software Engineering Institute in 2018, he has developed high‑fidelity cybersecurity exercise and training simulations and conducted research on Security Operations Center performance in both domestic and international contexts. He also teaches Host‑Based Digital Forensics as an adjunct instructor at Carnegie Mellon University’s (CMU’s) Information Networking Institute and has previously taught at the University of Pittsburgh’s School of Computing and Information and CMU’s Heinz College of Public Policy.
Event Topic
Artificial Intelligence, Cybersecurity, DefenseRelevant Audiences
All Military, All Federal Government