Cloud Security Podcast

Why AI Can't Replace Detection Engineers: Build vs. Buy & The Future of SOC

41 snips
Jan 21, 2026
Antoinette Stevens, Principal Security Engineer at Ramp, brings her expertise in detection engineering to a lively discussion about the role of AI in security operations. She emphasizes the importance of human judgment over AI's limitations, such as hallucinations. Antoinette advocates for an engineering-led approach and warns about the shrinking entry-level job market, pushing for software skills in security roles. The conversation covers the necessity of building robust detection programs while treating AI as a supportive tool, not a replacement. Plus, she shares her personal interests, from wine certification to comedy!
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Adopt An Engineering-Led Detection Workflow

  • Use an engineering-led approach: source-control detections and add test suites to validate rules before production.
  • Evaluate build vs buy by comparing long-term maintenance and support costs for each option.
ADVICE

Test Detections With Mocked Or Real Activity

  • Validate detection rules with real tests: run the activity or mock uniform logs (e.g., CloudTrail) to ensure alerts trigger as expected.
  • Automate these validations into CI to prevent noisy or broken rules from reaching production.
INSIGHT

AI Is A Force Multiplier For Skilled Engineers

  • AI speeds up engineers who already can code but will slow or produce fragile outcomes for those who can't review generated code.
  • Knowing architecture and coding basics is essential to safely use AI-generated tooling.
Get the Snipd Podcast app to discover more snips from this episode
Get the app