01
AI-native security operations
I can re-platform a security function so people and AI agents operate it together, through one set of controls, permissions and audit trail.
people & agents
- SOC analysts
- Customer-facing teams
- Slack LLM agent
- Claude Code
one control plane
Security Hub
web UI · MCP server
systems
- Cloud SIEM
- WAF & CDN
- Threat intelligence
- Production data
- Tickets & runbooks
control-plane
A security operations platform with a web UI and an MCP server, so analysts and AI tools such as Claude Code run the SOC through the same tools.
agents
Production LLM agents with a tool and playbook architecture, an authorisation layer, guardrails and observability. Governed actions for non-engineers.
detection
LLM and vision-model pipelines for phishing and malicious content, benchmarked across providers and deployed into live approval paths.
workflows
AI-assisted triage, investigation, threat modelling and code review in the team's daily work, with the human accountable for the decision.
governance
The AI usage policy, AI spend governance and the security review of AI features for an engineering organisation.
writing
Articles on multi-agent incident response, LLM-driven WAF analysis, threat modelling with GenAI and hybrid human-and-agent SOC teams.