AI-Driven IT & Security Operations
Duration
4 Days
Level
Advanced Level
Design and Tailor this course
As per your team needs
Overview
AI-Driven IT & Security Operations
This course is designed for experienced IT and Security professionals to strengthen enterprise security posture and operational resilience using Generative AI, Agentic AI, and AIOps. The program focuses on applying AI across IT operations, cloud and network security, endpoint protection, SIEM/SOC operations, compliance, and automated incident response, aligned with CIS service line requirements.
Participants will gain hands-on experience with enterprise-grade security tooling, real-world attack and defense scenarios, and AI-driven workflows to improve detection, response, and compliance outcomes.
Audience
This course is intended for mid to senior-level professionals from the CIS service line, including:
- IT Operations Engineers
- Security Operations (SOC) Analysts
- Cloud Security Engineers
- Infrastructure & Network Security Engineers
- Incident Response & Threat Hunting Professionals
- Technical Leads responsible for security and compliance
Prerequisites
- 5+ years of experience in IT infrastructure or security roles
- Hands-on experience with enterprise IT environments (on-prem and/or cloud)
- Working knowledge of Windows and Linux administration
- Understanding of networking concepts (firewalls, VPNs, routing, DNS)
- Basic familiarity with security concepts such as logging, monitoring, and access control
Prior exposure to SIEM tools, cloud security, or compliance frameworks is beneficial but not mandatory.
Curriculum
- GenAI and Agentic AI concepts for IT and security operations
- Platforms: ChatGPT, Copilot, security-focused AI assistants
- Prompt engineering for security analysis and IT automation
- Security, privacy, and governance considerations
Hands-on Lab: Secure GenAI environment setup and security-focused prompt design
- SCCM & Intune: policy automation, compliance monitoring, remediation
- Endpoint hardening and configuration baselines
- Citrix / AVD security and access controls
Hands-on Lab: Generate secure device compliance policies using GenAI
- M365 security and governance automation
- Entra ID / Active Directory security
- Conditional access, identity lifecycle automation, GPO hardening
Hands-on Lab: Create conditional access policies and identity automation scripts
- Secure cloud architecture principles
- IAM, encryption, and guardrails
- Cloud workload hardening and posture management (CSPM)
Hands-on Lab: Implement cloud security guardrails using AI-assisted IaC
- Secure router and switch configurations
- Firewall, VPN, and NAC policy optimization
- Hybrid connectivity security patterns
Hands-on Lab: Generate secure network and firewall configurations using GenAI
- Secure backup strategies
- RTO/RPO alignment and testing
- Ransomware resilience and recovery automation
Hands-on Lab: Design secure DR strategies with AI-assisted planning
- SIEM concepts and enterprise architectures
- Wazuh (primary): agents, rules, FIM, vulnerabilities, dashboards
- Splunk & Elastic overview
- AI-assisted rule tuning and correlation
Hands-on Lab: Deploy and configure Wazuh for enterprise monitoring
- Threat hunting methodologies
- Use of AI for detection and investigation
- Automated incident response and SOAR workflows
Hands-on Lab: Build AI-assisted detection rules and response playbooks
- Incident lifecycle management
- Log analysis and correlation
- AI-assisted RCA and investigation
Hands-on Lab: Perform AI-driven root cause analysis on a simulated incident
- Data classification and protection
- Compliance frameworks: GDPR, HIPAA, PCI-DSS, SOC 2
- Audit readiness and evidence automation
Hands-on Lab: Create compliance checklists and automated controls using GenAI
- AIOps concepts for security
- Predictive analytics and anomaly detection
- Reducing false positives and alert fatigue
Hands-on Lab: Implement AI-driven anomaly detection and alert optimization
- End-to-end security operations scenario
- Coordinated detection, response, and recovery
- Security maturity roadmap for CIS teams
Hands-on Lab: Capstone project integrating SIEM, automation, and compliance
Duration
4 Days
Level
Advanced Level
Design and Tailor this course
As per your team needs