Jake Lozano

Security Detection Engineer · Builder & Founder

I build systems people can trust. I detect the threats, and build the infrastructure that stops the next ones.

Security by training, builder by instinct.

What I do

Detection engineering. Detections are code: versioned, tested against real adversary behavior, and measured by what they cut rather than what they fire. I've measured the real false-positive rate at enterprise scale: what's actually feeding analyst queues, not what the SIEM reports. That analysis drove the case to replace the stack. The metric isn't coverage; it's confidence when a security event goes live.

Platform engineering. Four years of incident response showed me exactly where analyst workflows break: triage that doesn't scale, automation you can't trust, and no record of why an agent did what it did. Periheliax is what I'm building, on my own, to close that gap.

What I'm building

Periheliax. A control plane for AI in the SOC. Any agent reaching into your security tools, whether it's built in-house, bought, or an analyst pointing Claude at an API, gets gated, observed, and sealed into an audit trail. Strictly for security platforms, where a wrong call is an incident, not an inconvenience.

in development · periheliax.com

IR-Bridge. A lean, agentic-first IR triage tool. A detection arrives as raw JSON and an agent does the legwork: parse, enrich, and a structured verdict on the timeline. Everything an analyst needs on one page, nothing they don't.

build-in-public · read the writeup →

Glimpse. A private, invite-only social app for the people who actually matter. No algorithm, no audience, no performance. The same instinct that catches what's malicious, pointed at building something worth trusting.

invite-only · glimpsefeed.com

Writing

Notes from the field: detection engineering, AI in the SOC, and building trustworthy systems.

Read the blog →

Contact

Building something, or want to compare notes on what's broken in the SOC? Reach out.

hello@jakelozano.dev