
Cloud Security Podcast Why AI Can't Replace Detection Engineers: Build vs. Buy & The Future of SOC
41 snips
Jan 21, 2026 Antoinette Stevens, Principal Security Engineer at Ramp, brings her expertise in detection engineering to a lively discussion about the role of AI in security operations. She emphasizes the importance of human judgment over AI's limitations, such as hallucinations. Antoinette advocates for an engineering-led approach and warns about the shrinking entry-level job market, pushing for software skills in security roles. The conversation covers the necessity of building robust detection programs while treating AI as a supportive tool, not a replacement. Plus, she shares her personal interests, from wine certification to comedy!
AI Snips
Chapters
Transcript
Episode notes
Adopt An Engineering-Led Detection Workflow
- Use an engineering-led approach: source-control detections and add test suites to validate rules before production.
- Evaluate build vs buy by comparing long-term maintenance and support costs for each option.
Test Detections With Mocked Or Real Activity
- Validate detection rules with real tests: run the activity or mock uniform logs (e.g., CloudTrail) to ensure alerts trigger as expected.
- Automate these validations into CI to prevent noisy or broken rules from reaching production.
AI Is A Force Multiplier For Skilled Engineers
- AI speeds up engineers who already can code but will slow or produce fragile outcomes for those who can't review generated code.
- Knowing architecture and coding basics is essential to safely use AI-generated tooling.
