Massimiliano Albanese, Xinming Ou, Kevin Lybarger, Daniel H. Lende, Dmitry Goldgof, Faayed Al Faisal, Kritan Banstola, Arka Ghosh
Security Operations Centers (SOCs) face growing challenges in managing cybersecurity threats due to an overwhelming volume of alerts, a shortage of skilled analysts, and poorly integrated tools. Human-AI collaboration offers a promising path to augment the capabilities of analysts while reducing cognitive overload. To this end, we introduce an AI-driven human-machine co-teaming paradigm that leverages large language models (LLMs) to support threat intelligence, alert triage, and incident response workflows. We present a vision in which LLM-based agents learn from human analysts the tacit knowledge embedded in SOC operations, enabling them to progressively improve their performance on operational tasks. Our approach involves close collaboration with SOCs to refine this process and identify replicable patterns where human-AI co-teaming improves operational efficiency. To illustrate the feasibility of this paradigm, we report lessons learned from a preliminary case study conducted in partnership with a real SOC.