Uploaded August 2026 | Updated September 2026, 2 hours ago
Dr. Stephen Coston (Centene, US), William Rodriguez (Centene, US)
Modern security operations are facing a structural breaking point. Hybrid-cloud environments generate massive volumes of fragmented evidence across AWS, Azure, SaaS platforms, and endpoints yet the ability to reconstruct a coherent, defensible narrative has not kept pace. What slows investigations is no longer detection it is interpretation under uncertainty.
As organizations introduce AI to accelerate triage and correlation, a deeper problem emerges: Can we trust the outputs? Can we explain them? And will they hold up when it matters most under audit, regulation, or legal scrutiny?
This session introduces a practical, end-to-end framework for transforming fragmented logs into chronologically consistent, forensically defensible “living timelines.” Built on the Open Cybersecurity Schema Framework (OCSF), the approach redefines incident response as a schema-driven, evidence-centric system rather than a collection of tools.
At the core is a six-layer pipeline Ingest → Normalize → AI Assist → Validate → Timeline → Export designed to operate within existing SOC environments such as Splunk, Sentinel, and Databricks. The architecture treats AI not as an authority, but as an accelerator. Large language models enhance field inference, semantic clustering, and narrative construction, while human-in-the-loop controls ensure that decision authority never leaves the analyst.
What differentiates this model is not speed alone but trust by design. Every transformation is versioned, explainable, and hash verified. Confidence scoring, prompt traceability, and workflow logging create a system where outputs can be audited, reproduced, and defended. The framework embeds evidentiary principles aligned to Daubert, Frye, and Durant, ensuring that AI-assisted investigations meet the standards of scientific reliability, general acceptance, and procedural fairness.
Attendees will walk away with more than concepts they will gain a deployable blueprint: a reproducible architecture, governance checklist, AI transparency maturity model, and schema-first playbooks ready for operational use.
This session advances a critical shift in thinking:
As AI becomes embedded in security operations, the role of cybersecurity must evolve from analyzing events to protecting the integrity of decisions, evidence, and outcomes at machine speed.
---
The presenters Willam Rodriguez and Dr. Stephen Coston, serve as a Lead Security Architect and Director of Security Operator leading hybrid-cloud and AI-augmented incident-response initiatives for a large U.S. healthcare insurer. His work spans log normalization, SOC automation, AI governance, and evidence reliability frameworks. He has designed log-to-timeline pipelines aligned to OCSF and has published on AI governance, bias mitigation, and forensically sound automation in security operations
Dr. Stephen Coston is an AI-enabled security operations architect and cybersecurity strategist operating at the forefront of cloud security, AI governance, and next-generation Security Operations Center (SOC) design. He architects security systems where artificial intelligence functions as core decision infrastructure, transforming how organizations detect, investigate, and respond to threats. His work enables the compression of investigation timelines from hours to minutes while preserving human judgment, auditability, and operational control at scale. Stephen leads initiatives that integrate AI into the fabric of security operations, redefining decision velocity, and elevating the role of analysts from reactive responders to supervisory decision-makers. His focus spans human–AI collaboration, security data architecture, and the emerging attack surface of adversarial AI where model behavior, data pipelines, and automation pathways become targets. With deep experience in incident response and digital forensics, he has led complex investigations across enterprise environments, translating technical signals into actionable intelligence under high-stakes conditions. As a speaker, researcher, and contributor to the evolving field of AI in cybersecurity, Stephen advances a clear thesis: as AI becomes embedded in operational systems, security must evolve from protecting data to protecting decisions. Disclaimer: All thoughts are my own and does not reflect my employer or any of there subsidiaries.
Dr. Stephen Coston (Centene, US), William Rodriguez (Centene, US)
Modern security operations are facing a structural breaking point. Hybrid-cloud environments generate massive volumes of fragmented evidence across AWS, Azure, SaaS platforms, and endpoints yet the ability to reconstruct a coherent, defensible narrative has not kept pace. What slows investigations is no longer detection it is interpretation under uncertainty.
As organizations introduce AI to accelerate triage and correlation, a deeper problem emerges: Can we trust the outputs? Can we explain them? And will they hold up when it matters most under audit, regulation, or legal scrutiny?
This session introduces a practical, end-to-end framework for transforming fragmented logs into chronologically consistent, forensically defensible “living timelines.” Built on the Open Cybersecurity Schema Framework (OCSF), the approach redefines incident response as a schema-driven, evidence-centric system rather than a collection of tools.
At the core is a six-layer pipeline Ingest → Normalize → AI Assist → Validate → Timeline → Export designed to operate within existing SOC environments such as Splunk, Sentinel, and Databricks. The architecture treats AI not as an authority, but as an accelerator. Large language models enhance field inference, semantic clustering, and narrative construction, while human-in-the-loop controls ensure that decision authority never leaves the analyst.
What differentiates this model is not speed alone but trust by design. Every transformation is versioned, explainable, and hash verified. Confidence scoring, prompt traceability, and workflow logging create a system where outputs can be audited, reproduced, and defended. The framework embeds evidentiary principles aligned to Daubert, Frye, and Durant, ensuring that AI-assisted investigations meet the standards of scientific reliability, general acceptance, and procedural fairness.
Attendees will walk away with more than concepts they will gain a deployable blueprint: a reproducible architecture, governance checklist, AI transparency maturity model, and schema-first playbooks ready for operational use.
This session advances a critical shift in thinking:
As AI becomes embedded in security operations, the role of cybersecurity must evolve from analyzing events to protecting the integrity of decisions, evidence, and outcomes at machine speed.
---
The presenters Willam Rodriguez and Dr. Stephen Coston, serve as a Lead Security Architect and Director of Security Operator leading hybrid-cloud and AI-augmented incident-response initiatives for a large U.S. healthcare insurer. His work spans log normalization, SOC automation, AI governance, and evidence reliability frameworks. He has designed log-to-timeline pipelines aligned to OCSF and has published on AI governance, bias mitigation, and forensically sound automation in security operations
Dr. Stephen Coston is an AI-enabled security operations architect and cybersecurity strategist operating at the forefront of cloud security, AI governance, and next-generation Security Operations Center (SOC) design. He architects security systems where artificial intelligence functions as core decision infrastructure, transforming how organizations detect, investigate, and respond to threats. His work enables the compression of investigation timelines from hours to minutes while preserving human judgment, auditability, and operational control at scale. Stephen leads initiatives that integrate AI into the fabric of security operations, redefining decision velocity, and elevating the role of analysts from reactive responders to supervisory decision-makers. His focus spans human–AI collaboration, security data architecture, and the emerging attack surface of adversarial AI where model behavior, data pipelines, and automation pathways become targets. With deep experience in incident response and digital forensics, he has led complex investigations across enterprise environments, translating technical signals into actionable intelligence under high-stakes conditions. As a speaker, researcher, and contributor to the evolving field of AI in cybersecurity, Stephen advances a clear thesis: as AI becomes embedded in operational systems, security must evolve from protecting data to protecting decisions. Disclaimer: All thoughts are my own and does not reflect my employer or any of there subsidiaries.










