Workshop description
Security automation has always run on rules: if this alert fires, take that action. It’s fast, predictable, and cheap — until the input doesn’t fit the rule. As AI gets added into playbooks, SOAR pipelines, and ChatOps bots, automation engineers face a design question that has nothing to do with model size or prompt tricks: where, exactly, does AI belong in the loop, and where should a deterministic rule stay in charge?
This workshop is a practical, code-first answer to that question. After a short framing session on when logic should stay deterministic versus when a step genuinely needs AI reasoning, participants will build their own AI-driven decision layer on top of a working security playbook — from live-coded example to hands-on task. You’ll learn how to structure an AI’s decision so it plugs cleanly back into existing automation actions, and the one guardrail every engineer should add the moment an AI system starts acting on real permissions.
No prior AI experience is required — just a laptop and curiosity. If you build or maintain automation of any kind, you’ll leave with a reusable framework and working code you can adapt to your own systems.
Speaker biography
Eva Georgieva is a security engineer and consultant with 6+ years spanning offensive and defensive security, now focused on building security automation pipelines for SOC and DevSecOps teams. Her work centers on penetration testing, security operations, and designing automation — including SOAR platforms like Cortex XSOAR — that helps security teams move faster without losing control. She regularly speaks at security conferences on the practical intersection of automation, AI, and applied offensive/defensive security. More of her work is available at evaincybersec.com.