Skip to content
KOR IT

Founder

Ali Korsi

Security Operations, Security Architecture, Security Data Engineering, Data, AI Security and Agent Security

Cybersecurity Architect · Data & AI Security

Profile

Ali Korsi is the founder of KOR IT, a cybersecurity engineering and research organisation. His work sits at the intersection of security operations, security architecture, security data engineering, data, AI security and agent security — a combination that reflects how he arrived at the subject rather than a set of interests assembled after the fact.

The progression began in the SOC. Detection engineering, SIEM architecture and the daily reality of running large-scale security telemetry are the foundation of everything that followed. Working on the data side of security operations made the underlying problem clear early: detection quality is bounded by the quality, structure and lineage of the data it runs on, and most detection failures are data failures before they are logic failures. That led to security data engineering — telemetry architecture, pipelines, normalisation, data platforms — and from there to automation, detection-as-code and the treatment of detection content as versioned, testable engineering artefacts rather than console configuration.

The move into data and machine learning was continuous with that work, not a departure from it. Analytics and models were first a way to make security data more useful; they then became systems that themselves needed securing. That shift is where AI security entered the picture, and more recently agent security: autonomous systems with persistent memory, tool access and their own identity, which behave less like applications to be scanned and more like operational estates to be instrumented, governed and monitored.

The operational background is the point, and it is worth stating explicitly. Ali did not begin as an AI researcher, and the AI-security perspective is not a rewriting of his history. It is the direct product of years spent building SOC and SIEM capability and engineering security data — which is precisely what makes it possible to ask, of an agentic system, the questions a SOC actually has to answer: what would we see, in which telemetry, with what provenance, and how would anyone detect this after the fact.

Progression

How the AI-security work was arrived at.

Presented as stages rather than dated roles. The order matters: this is a security operations background that grew into AI security, not the reverse.

  1. Stage 01

    SOC & SIEM engineering

    Building and operating security monitoring capability: log onboarding, SIEM architecture, correlation content and the operational discipline of running detection at scale.

  2. Stage 02

    Security data engineering

    Moving upstream from detection to the data it depends on — telemetry architecture, ingestion pipelines, normalisation, retention design and the data platforms underneath security operations.

  3. Stage 03

    Automation & detection-as-code

    Treating detection content and platform configuration as engineering artefacts: version control, testing, pipelines, and automation of the repetitive work that otherwise limits a SOC's capacity.

  4. Stage 04

    Data & machine learning

    Applying analytics and machine learning to security data, and confronting the practical limits of models built on telemetry that was never designed for them.

  5. Stage 05

    AI security

    Turning the question around: securing the models and AI systems themselves — threat modelling, data and pipeline exposure, and the observability gaps that conventional security tooling leaves behind.

  6. Stage 06

    Agent security & research

    Researching autonomous agents as operational systems: runtime security, persistent memory as an attack surface, agent–tool boundaries, identity, and how any of it can be detected from a SOC.

Capabilities

Where the work sits.

Cybersecurity Engineering

Designing and building the systems a SOC runs on: SIEM architecture, detection content managed as code, and the automation that keeps it maintainable. The emphasis is on detection that can be tested, versioned and reasoned about rather than accumulated.

  • SOC architecture
  • SIEM architecture
  • Detection Engineering
  • Detection-as-Code
  • Security automation
  • Security analytics

Security Data Engineering

Treating security telemetry as an engineered data estate — sources, pipelines, schemas, lineage and retention — rather than as whatever happens to reach the SIEM. Detection quality is bounded by the data underneath it, so the data is designed first.

  • Security telemetry architecture
  • Data pipelines
  • Security data platforms
  • Observability
  • Data governance
  • Security data architecture

AI Security Engineering

Securing AI and agentic systems as operational estates: threat modelling, runtime and memory boundaries, and the agent–tool surface where privilege actually gets exercised. We instrument these systems so their behaviour is observable to the people responsible for it.

  • AI threat modelling
  • Agent security architecture
  • AI observability
  • Agent runtime security
  • Memory security
  • AI governance
  • Agent–tool security

Security Research

Investigating problems that are not yet well covered by existing practice, through experimental architectures and working prototypes. Findings are measured where measurement is possible, and published with their limitations stated.

  • Threat research
  • Experimental architectures
  • Security measurement
  • Prototypes
  • Technical publications

Technologies

Tools the work has actually run on.

Listed as experience, not as a logo wall and not as an endorsement of any vendor.

Splunk Platform
  • Splunk Enterprise
  • Splunk Enterprise Security
  • Splunk Cloud
  • Splunk MLTK
  • SmartStore
  • Search Head Clustering
  • Indexer Clustering
  • DB Connect
Languages & Runtimes
  • Python
  • JavaScript
  • Node.js
  • Java
Automation & Delivery
  • Terraform
  • Ansible
  • AWX
  • GitLab CI
  • Jenkins
Cloud & Infrastructure
  • AWS
  • Azure
  • GCP
  • OpenStack
Data & Machine Learning
  • PostgreSQL
  • MongoDB
  • Qdrant
  • MinIO
  • Spark
  • scikit-learn
  • TensorFlow
  • PyTorch
Observability
  • Prometheus
  • Grafana
  • Loki
  • Tempo
Security ecosystems
  • Microsoft 365
  • Active Directory
  • Okta
  • SailPoint
  • Proofpoint
  • Zscaler
  • Netskope
  • Palo Alto Networks
  • Check Point
  • SentinelOne
  • AWS GuardDuty
  • CloudTrail

Education

  • INP-ENSEEIHT

    2014–2017

    Engineering studies in computer science and applied mathematics.

  • CPGE preparatory studies

    Classes préparatoires aux grandes écoles, MPSI → MP.

Certifications

  • AWS Certified Solutions Architect – Associate
  • Splunk Certified Admin
  • SAFe Practitioner