Hacker Valley Studio
Hacker Valley Studio
Hacker Valley Studio·Aug 19, 2026·34m·Episode #439

Humans First: Adobe's Rule for Building AI Security Tools with John Gillis

Show notes

Imagine how much investigation time your SOC could get back if the busywork just disappeared. Ron sits down with John Gillis, Staff Security AI Engineer at Adobe, who built an in-house AI investigation platform from scratch.

John's system runs on more than 30 specialized agents that reason through cases instead of following a script. In one run, that meant over 140 detections investigated in under four hours at an 80 to 85% quality rating. Ron and John dig into the hard lesson that made John rip out his own tooling and rebuild it around function calling, why "humans first" drives every decision his team makes, and whether AI SOC is actually different from SOAR or just the same promise with way better marketing.

Underneath all of it is the one thing John says decides whether any of this actually works: context. Give the AI too little and it's guessing, give it too much and it drowns just like a human would. Listen to find out what it actually takes to build an AI SOC that reasons instead of just automates.

Impactful Moments

00:00 - Introduction
02:05 - The rewind: how SOAR promised to save the SOC in 2015
03:35 - Meet John Gillis, Adobe's Staff AI Security Engineer
05:30 - What cybersecurity looked like before AI at enterprise scale
07:00 - The "humans first" strategy behind Adobe's AI investigator
09:30 - Why careless context management is the biggest pitfall in agent design
14:45 - Solving the speed problem: is it tooling, process, or people?
17:10 - From monolith to microservices: rebuilding the platform for scale
24:05 - What actually makes an AI agent's "persona" work
26:00 - John's prediction for the SOC three years from now
28:50 - The three skills every security practitioner needs for 2026
32:10 - Final verdict: is AI SOC really different, or SOAR with new branding?

Links

Connect with John Gillis on LinkedIn: https://www.linkedin.com/in/john-gillis/

If you're a researcher ready to make an impact, check out the announcement about Adobe’s new home for the Adobe Bug Bounty Program here: https://blog.adobe.com/security/a-new-home-for-the-adobe-bug-bounty-program

Check out Adobe’s Bug Bounty profile on Intigriti: https://app.intigriti.com/programs/adobe/adobepublic/detail

Learn more about Adobe: https://www.adobe.com/

– 

Check out our upcoming events: https://www.hackervalley.com/livestreams


Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com

Become a sponsor of the show: https://hackervalley.com/work-with-us/