Skip to content
Explore platformAI-FDE
AI-FDE

The platform adapts to you.
Now, so does the engineer.

The Imperum AI Forward Deployed Engineer (AI-FDE) embeds inside your SOC. The engineer writes custom agents, wires your stack and codifies your procedures on the Imperum platform until it runs your operation the way you run it.

For In-House SOCs and MSSP/MDR providersEmbedded on top of any license tierEvery build ships behind your approval gates
AI-FDE engagementIllustrative workflow
Your SOC Imperum platform
  • Ransomware runbook
  • HR leaver feed
  • Approval matrix
  • Noisy detection
AI-FDEInside your SOC
Continuous
  • Custom agentAgent Studio
  • Gated playbookAutomatio
  • New connectorDeveloper Studio
  • Triage modelCerebrum
An AI-FDE engagement, illustrated: a ransomware runbook, an HR leaver feed, an approval matrix and a noisy detection from your SOC become a custom agent, a gated playbook, a new connector and a Cerebrum triage model trained on your alerts, all shipped behind your approval gates.
01 - Why now

A quarter century of “adapt to the vendor” is over

Since the first commercial SIEMs shipped in 1999 and 2000, security vendors have imposed their way of working on the SOC: static products, fixed workflows and integrations that wait for the vendor's roadmap. The SOC did the adapting, and the numbers show how badly that went.

SOAR already showed where that road ends.

90%of SOAR licenses in shelfware territory, by rough industry estimates
12+ monthsburned on setup and integration before the first playbook delivered value

0

Agentic & Autonomous SOC vendors are selling AI without customization and fine-tuning. Sold alone, it stays a demo, with zero operational value until it learns your operation.

Triage

An out-of-the-box model doesn't know your crown jewels, your VIPs or your naming conventions, so it confidently triages someone else's network.

Response

Auto-containment without your approval matrix, change windows and asset criticality is a liability, so it ships switched off.

Noise

False-positive models only work when they are trained on your alert corpus. Untuned AI faithfully reproduces the noise it promised to kill.

Context

Your CMDB, HR system and internal APIs are in no vendor's catalog. Without those integrations the AI acts blind, or not at all.

Procedure

Your escalation rules, compliance regime and IR runbooks aren't in the box, so uncustomized agents improvise where you need policy.

Tenants

For MSSPs, generic agents can't tell customers apart. Per-tenant SLAs, service tiers and isolation all have to be engineered.

Trust

Analysts abandon AI they can't audit. Verdicts need your thresholds, your approval gates and explainable reasoning before anyone acts on them.

AI reversed the economics. An agentic platform can be programmed, and Imperum is the first to ship the person who programs it for you as part of the offering.

Their product, your problem

The static-product era

  • Fixed workflowsYour process bends around the tool's screens.
  • Roadmap integrationsYour internal API waits a quarter, or forever.
  • PS = configurationServices end where the options menu ends.
  • Custom = exceptionBespoke work is priced and delivered like a moonshot.
  • Knowledge stays tribalYour best analyst's judgment retires with them.

Your operation, compiled into the platform

The agentic era: Imperum + AI-FDE

  • New agent in daysAgent Studio, 2,700+ agent templates and seat-licensed deployment.
  • Runbook → automationNatural language compiled to approval-gated playbooks.
  • Any API becomes a connectorOpenAPI import + Developer Studio.
  • Custom is the productThe AI-FDE builds new capability on the platform.
  • Knowledge becomes agentsProcedures codified, versioned and yours.
Since 2022

Building toward this since 2022

While the incumbents froze, Imperum spent every year since 2022 on one goal: the most complete AI-powered TDIR platform, with threat detection, investigation and response unified under an Autonomous SOC with agentic AI. The AI-FDE program follows from it.

  1. 2022

    The commitment

    Imperum starts out AI-first from day one, instead of bolting AI onto a legacy console.

  2. 2023

    The TDIR foundation

    Detection, investigation and response come together on one data plane: ingestion at scale, detections, casebook, hunts and forensics.

  3. 2024

    The agents arrive

    Virtus agentic AI ships, with autonomous triage and eight-phase Pilot investigations across the whole connector estate.

  4. 2025

    The agentic platform

    Agent Studio and its 2,700+ agent templates, Cerebrum per-tenant learning and Optimus Detection-as-Code make the platform programmable.

  5. 2026

    Autonomous SOC + AI-FDE

    Three license tiers, an MSSP fabric and the first embedded engineer program in SecOps.

02 - The role

One role, three accountabilities

An AI-FDE is a hybrid technical role. The engineer embeds in your organization, physically or virtually, to customize, integrate and deploy production-grade AI where frontier models meet messy enterprise reality.

Engineering

Builds custom agents, playbooks, connectors, normalization profiles and integrations on the platform. Every build is production-grade: versioned, tested, approval-gated, documented and yours.

Operations alignment

Sits in your stand-ups and post-incident reviews, turns what your analysts actually do into what the platform does automatically, and measures it against your baseline.

Product feedback loop

Gaps found in your SOC are filed against the Imperum roadmap with AI-FDE priority, so your operational needs steer the product.

03 - Two audiences

Two audiences, two backlogs

In-House SOC

The platform learns your organization: its tools, its rules, its people.

Outcomes contracted

  • Lower: MTTT / MTTR
  • Lower: False positives
  • Higher: Autonomy rate
  • Higher: Codified coverage
  • Your procedures, codifiedIR runbooks become Pilot-executed playbooks under your approval matrix.
  • Your systems, connectedCMDB, HR, ticketing and proprietary apps become connectors through OpenAPI import.
  • Your noise, killedCerebrum tuned on your alert corpus, with a triage-accuracy baseline and an improvement loop.
  • Your constraints, respectedAir-gapped and sovereign deployment, local LLMs and Veil PII redaction.
  • Your team, enabledMagister mentorship and agent-authoring training until you ship unassisted.

MSSP / MDR Provider

The AI-FDE builds your service, not just your instance.

Outcomes contracted

  • Tenant onboarding in days
  • Higher: Alerts per analyst
  • Higher: Margin per tenant
  • Lower: Service time-to-market
  • Tenant onboarding as codeHierarchy import, tenant isolation, connector packs and SLA maps per contract tier.
  • A service catalog you sellBronze, Silver and Gold agent bundles, built, versioned and deployed per tenant.
  • Your brand in frontA white-label self-service portal, per-tenant reporting packs and war-room links.
  • Detection estate as a serviceVirtus Optimus across every customer stack you manage.
  • Your fabric, extendedPlatform API and MCP wire Imperum into the MDR stack you already run.
04 - Engagement

How an engagement runs

Four phases, each ending on an exit criterion.

  1. 01Weeks 1–2

    Embed & Discover

    Sit with the SOC. Map alert flow, tools, procedures and pain. Baseline MTTT/MTTR, false-positive rate and volumes.

    Exit: Signed capability map + prioritized backlog

  2. 02Weeks 2–4

    Design

    Agent and playbook designs, a connector plan, the approval matrix and, for MSSPs, the tenant model. Success metrics are agreed.

    Exit: Design review accepted

  3. 03Sprint cadence

    Build & Deploy

    Agents, playbooks, connectors, normalization and ML tuning, shipped weekly behind approval gates and in shadow mode where risk requires it.

    Exit: Each increment live in production

  4. 04Continuous

    Operate & Transfer

    Joint operation, metric reviews, analyst training and documentation until your team ships changes unassisted.

    Exit: Capability is yours

Governance

Ways of working, security and governance

AreaHow it works
AccessYour RBACNamed accounts under your RBAC. Every AI-FDE action lands in the platform audit trail like any analyst's, and high-risk actions pass the same approval gates.
DataYour deploymentWork happens in your deployment: cloud, on-prem or air-gapped. Veil PII redaction applies to any cloud LLM traffic, and fully local LLM operation is available.
CodeYours to keepEverything the AI-FDE builds is delivered as reviewable artifacts (agent definitions, playbook YAML, connector definitions, normalization profiles) and remains yours.
Clearances and residencyAvailableRegional and clearance-holding AI-FDEs are available for sovereign engagements.
GovernanceWeekly, monthly, quarterlyA weekly demo, a monthly metric review against the contracted outcomes and a quarterly roadmap session with Imperum product.
05 - Licenses

One engineer. Every license.

The AI-FDE sits on top of all three Imperum license models. Whichever tier you run, the engineer adapts it to your operation.

AI Forward Deployed Engineer (AI-FDE)

Embedded on top of any tier: custom agents, playbooks, connectors, tuning and enablement, delivered inside your SOC.

Autonomous SOC

Your SOC, on autopilot

  • AI Agents the native agents and pipelines, including Virtus Pilot and Virtus Triage
  • Agent Studio build your own from 2,700+ agent templates
  • Case Prioritizer and Case Router
  • Cerebrum per-tenant false-positive ML
  • Magister analyst mentorship and QA

SecOps Platform

Autonomous SOC, hyperautomation, forensics and investigation

Superset of Autonomous SOC
  • Everything in Autonomous SOC plus:
  • Automatio playbook hyperautomation
  • Detection Lake rules, threat intel, vulnerabilities and anomalies
  • Endpoints agents, hunts and forensics
  • MSSP, Defensum CTEM and Cognitio

The Portal

MSSP/MDR, bring your own stack

  • MSSP multi-tenant fabric with tenant isolation
  • Case Router cross-tenant assignment
  • Case Prioritizer 8-signal scoring
  • Runs alongside the stack you already own
  • Fastest path to AI-powered MDR delivery

Standalone add-ons attach to any tier, and the AI-FDE deploys and customizes them too: Scriptorium (air-gapped document intelligence), Virtus Optimus (Detection-as-Code) and Virtus Sentinel (AI security posture).

Packages

Three ways to engage

Launch

12 weeks

One AI-FDE, outcome-scoped: platform live, top-5 use cases codified, team enabled. Fixed scope, fixed price.

  • Best for: first deployment
  • Deliverables contract
  • Enablement included
Book a Demo

Scale

6 months

One AI-FDE embedded on sprint cadence, with a rolling backlog governed by a joint steering call.

  • Best for: growing SOCs and providers onboarding tenants
  • Weekly demos, monthly metric reviews
  • Quarterly product roadmap session
Book a Demo

Resident

12 months, dedicated

A dedicated AI-FDE (or pod) with quarterly OKRs tied to your SOC or service KPIs.

  • Best for: MSSPs running Imperum as the delivery engine
  • Roadmap escalation rights
  • Regional or cleared engineers available
Book a Demo

Commercial terms, rate cards and regional availability on request.

06 - Platform surfaces

Built on surfaces made to be reshaped

The AI-FDE model works because the platform was designed for it. Every surface below ships today.

1,500+
connectors
29,000+
connector actions
2,700+
agent templates
15
node types in Agent Studio

Agent Studio

A visual agent builder with a debug toolbar: run, pause, step and breakpoints.

Automatio

Natural language to executable YAML playbooks.

Marketplace

The connector catalog, with Connector, Ingestion and ECS views per connector.

Developer Studio

OpenAPI import and connector-as-code.

Normalizer

ECS 8.11 profiles for any log source.

Cerebrum

A per-tenant false-positive classifier, promoted from shadow to active.

Scriptorium + local LLMs

Air-gapped and sovereign, with Veil redaction.

07 - The bench

The AI-FDE bench

Every Imperum AI-FDE comes from the operational side of security: people who have carried the pager in a SOC or run delivery inside an MSSP before they ever wrote a line of agent code.

85+
combined years in SOC & IR operations
40+
MSSP/MDR tenants onboarded by the bench
6
languages covered across the bench
100%
platform-certified on every Imperum surface

Arda Kaya

Principal AI-FDE
  • 14 yrs SOC
  • Ex-MSSP delivery lead

Built and ran a 40-analyst MSSP SOC across three countries before joining Imperum. Specializes in tenant onboarding automation, Case Router tuning and per-tenant SLA engineering.

  • MSSP operations
  • Multi-tenant
  • SLA design

Marta Villanueva

Senior AI-FDE, Detection
  • 11 yrs SOC
  • Detection engineering

Former SIEM engineering lead at a European bank who owned 4,000+ detection rules across three platforms. Runs the Virtus Optimus and Cerebrum engagements that kill noisy rules.

  • Sigma
  • Detection-as-Code
  • ML tuning

Daniel Okafor

Senior AI-FDE, DFIR
  • 13 yrs IR & forensics
  • Ex-national CERT

Led incident response at a national CERT, with hundreds of engagements from ransomware to APT. Builds Pilot investigation pipelines, forensic playbooks and approval-gated response.

  • Virtus Pilot
  • Forensics
  • IR playbooks

Lea Novak

AI-FDE, Integration
  • 9 yrs SecOps eng
  • API & automation

Integration engineer who has wired everything from mainframe ITSM to homegrown CMDBs into SOC workflows. Owns OpenAPI connector generation, Platform API and MCP integrations.

  • Developer Studio
  • Platform API + MCP
  • ECS normalization

Selim Rahmani

AI-FDE, Sovereign & Air-Gap
  • 12 yrs gov SOC
  • Cleared engagements

A decade in government and defense SOCs. Delivers air-gapped Imperum with local LLMs, Scriptorium document intelligence and Veil-enforced data boundaries, so data never leaves the building.

  • Air-gapped
  • Local LLMs
  • Scriptorium

Emma Jensen

AI-FDE, Enablement
  • 10 yrs SOC lead
  • Analyst training

Former SOC team lead who grew L1s into hunters. Runs the Operate & Transfer phase: Magister mentorship programs, agent-authoring training and the handover that makes you self-sufficient.

  • Magister
  • Enablement
  • Agent authoring

For a quarter century, the biggest vendors told SOCs how to work, because their products could not change. We built Imperum so the product changes instead of the customer, and the AI-FDE program puts the person who changes it inside your team.

Senad ArucFounder and CEO

Questions about the AI-FDE.

1Is the AI-FDE just professional services under a new name?

No. Classic professional services configure the options a static product already has. The AI-FDE builds new capability on a programmable platform, and every build is tested with the platform's debug tooling, gated by approvals and documented before it ships.

2How does an engagement run?

In four phases. Embed & Discover takes weeks 1 to 2 and Design weeks 2 to 4. Build & Deploy follows on a sprint cadence, and Operate & Transfer continues until your team can carry on alone. Each phase closes on its exit criterion, from a signed capability map to increments live in production.

3What access does the engineer get inside our SOC?

The same kind an analyst gets: named accounts under your role-based access control. Their actions are recorded in the platform audit trail, and anything high-risk waits at your approval gates.

4Where does our data go during the engagement?

Nowhere new. The work happens inside your own cloud, on-prem or air-gapped deployment. When a cloud LLM is used, Veil redacts personal data first, and the whole engagement can run on local LLMs instead.

5Which Imperum license do we need?

Any of them. The engineer works on top of Autonomous SOC, SecOps Platform and The Portal, and also deploys the standalone add-ons.

6What happens when the engagement ends?

You keep what was built. Agent definitions, playbooks, connectors and normalization profiles stay in your platform as reviewable artifacts, and by then your team has been trained to change them.

7Why not buy the platform without the engineer?

Because an autonomous SOC product sold alone is a demo, not an operation: generic AI triaging generic alerts. The engineer is how the platform learns your crown jewels, your approval matrix and your alert corpus.

Have any other questions? Talk to our team

Get a platform.Keep an engineer.

Available for Autonomous SOC and SecOps Platform customers, and MSSP/MDR partners on The Portal.

Film · 1:00

Imperum AI Fabric

One minute on the AI Fabric appliance: the agents, Agent Studio, routing, pools, Veil and token metering.