Founder
Ali Korsi
Security Operations, Security Architecture, Security Data Engineering, Data, AI Security and Agent Security
Profile
Ali Korsi is the founder of KOR IT, a cybersecurity engineering and research organisation. His work sits at the intersection of security operations, security architecture, security data engineering, data, AI security and agent security — a combination that reflects how he arrived at the subject rather than a set of interests assembled after the fact.
The progression began in the SOC. Detection engineering, SIEM architecture and the daily reality of running large-scale security telemetry are the foundation of everything that followed. Working on the data side of security operations made the underlying problem clear early: detection quality is bounded by the quality, structure and lineage of the data it runs on, and most detection failures are data failures before they are logic failures. That led to security data engineering — telemetry architecture, pipelines, normalisation, data platforms — and from there to automation, detection-as-code and the treatment of detection content as versioned, testable engineering artefacts rather than console configuration.
The move into data and machine learning was continuous with that work, not a departure from it. Analytics and models were first a way to make security data more useful; they then became systems that themselves needed securing. That shift is where AI security entered the picture, and more recently agent security: autonomous systems with persistent memory, tool access and their own identity, which behave less like applications to be scanned and more like operational estates to be instrumented, governed and monitored.
The operational background is the point, and it is worth stating explicitly. Ali did not begin as an AI researcher, and the AI-security perspective is not a rewriting of his history. It is the direct product of years spent building SOC and SIEM capability and engineering security data — which is precisely what makes it possible to ask, of an agentic system, the questions a SOC actually has to answer: what would we see, in which telemetry, with what provenance, and how would anyone detect this after the fact.
Progression
How the AI-security work was arrived at.
Presented as stages rather than dated roles. The order matters: this is a security operations background that grew into AI security, not the reverse.
- Stage 01
SOC & SIEM engineering
Building and operating security monitoring capability: log onboarding, SIEM architecture, correlation content and the operational discipline of running detection at scale.
- Stage 02
Security data engineering
Moving upstream from detection to the data it depends on — telemetry architecture, ingestion pipelines, normalisation, retention design and the data platforms underneath security operations.
- Stage 03
Automation & detection-as-code
Treating detection content and platform configuration as engineering artefacts: version control, testing, pipelines, and automation of the repetitive work that otherwise limits a SOC's capacity.
- Stage 04
Data & machine learning
Applying analytics and machine learning to security data, and confronting the practical limits of models built on telemetry that was never designed for them.
- Stage 05
AI security
Turning the question around: securing the models and AI systems themselves — threat modelling, data and pipeline exposure, and the observability gaps that conventional security tooling leaves behind.
- Stage 06
Agent security & research
Researching autonomous agents as operational systems: runtime security, persistent memory as an attack surface, agent–tool boundaries, identity, and how any of it can be detected from a SOC.
Capabilities
Where the work sits.
Cybersecurity Engineering
Designing and building the systems a SOC runs on: SIEM architecture, detection content managed as code, and the automation that keeps it maintainable. The emphasis is on detection that can be tested, versioned and reasoned about rather than accumulated.
- SOC architecture
- SIEM architecture
- Detection Engineering
- Detection-as-Code
- Security automation
- Security analytics
Security Data Engineering
Treating security telemetry as an engineered data estate — sources, pipelines, schemas, lineage and retention — rather than as whatever happens to reach the SIEM. Detection quality is bounded by the data underneath it, so the data is designed first.
- Security telemetry architecture
- Data pipelines
- Security data platforms
- Observability
- Data governance
- Security data architecture
AI Security Engineering
Securing AI and agentic systems as operational estates: threat modelling, runtime and memory boundaries, and the agent–tool surface where privilege actually gets exercised. We instrument these systems so their behaviour is observable to the people responsible for it.
- AI threat modelling
- Agent security architecture
- AI observability
- Agent runtime security
- Memory security
- AI governance
- Agent–tool security
Security Research
Investigating problems that are not yet well covered by existing practice, through experimental architectures and working prototypes. Findings are measured where measurement is possible, and published with their limitations stated.
- Threat research
- Experimental architectures
- Security measurement
- Prototypes
- Technical publications
Technologies
Tools the work has actually run on.
Listed as experience, not as a logo wall and not as an endorsement of any vendor.
- Splunk Platform
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
- Splunk MLTK
- SmartStore
- Search Head Clustering
- Indexer Clustering
- DB Connect
- Languages & Runtimes
- Python
- JavaScript
- Node.js
- Java
- Automation & Delivery
- Terraform
- Ansible
- AWX
- GitLab CI
- Jenkins
- Cloud & Infrastructure
- AWS
- Azure
- GCP
- OpenStack
- Data & Machine Learning
- PostgreSQL
- MongoDB
- Qdrant
- MinIO
- Spark
- scikit-learn
- TensorFlow
- PyTorch
- Observability
- Prometheus
- Grafana
- Loki
- Tempo
- Security ecosystems
- Microsoft 365
- Active Directory
- Okta
- SailPoint
- Proofpoint
- Zscaler
- Netskope
- Palo Alto Networks
- Check Point
- SentinelOne
- AWS GuardDuty
- CloudTrail
Education
INP-ENSEEIHT
2014–2017
Engineering studies in computer science and applied mathematics.
CPGE preparatory studies
Classes préparatoires aux grandes écoles, MPSI → MP.
Certifications
- AWS Certified Solutions Architect – Associate
- Splunk Certified Admin
- SAFe Practitioner
Publications & projects
Work in the open.
Memory Poisoning: when the AI agent becomes the SOC's blind spot
Memory Poisoning : quand l'agent IA devient l'angle mort du SOC
Ali Korsi · KOR IT · September / October 2026
Agent Security Control Plane
Prototype control plane for governing how agents reach memory, tools, identities and data, with policy and telemetry as first-class layers.
AI Security · Agent Security
Memory Contract Specification
An experimental specification for runtime contracts that decide when a memory record is allowed to influence an agent. Principle: Trust Before Recall.
Agent Memory Security · Agent Security
Sovereign Agentic AI Lab
A self-hosted agentic AI environment on owned hardware, used to study inference, retrieval and agent security without external model dependencies.
AI Infrastructure · AI Security
Direct
ali.korsi@korit.orgGeneral enquiries
contact@korit.org