When someone first proposed the idea of letting computer science students run her security operations centre (SOC), Sharon Kelley, chief information security officer (CISO) at the New Jersey Institute of Technology (NJIT) – one of the US’s foremost research universities – says her initial reaction was, to put it mildly, somewhat less than enthusiastic.
“My boss came to me and said ‘Hey, we have this great idea, you’re going to have a student SOC’,” she says. “I was like, ‘No we’re not. I have a tiny team, I have no time, and you want me to train them?’
“First of all, I’ve never actually been a security analyst,” says Kelley. “I have that under me. I have people who do that. How am I supposed to train students to be analysts, and even if I was an analyst, who’s to say I’m the right person to do it? And mainly, I don’t have the patience. I said, ‘Absolutely not, we’re not doing this, you’re out of your mind!’”
Like many in the cyber trade, Kelley’s background actually lies in the marginally more straightforward world of computer science, which she studied in college but didn’t really fit her.
Nevertheless, she persisted with technology and after graduating became a network engineer, working in the higher education sector for many years before jumping into the world of financial services, where she caught the security bug. Then came stints in security for law enforcement and retail organisations, before she allowed herself to be lured back into academia.
“I had forgotten why I left higher education in the first place,” she says. “It’s an … interesting vertical, kind of like the Wild West.”
“I’m certainly never bored,” says Kelley. “It’s not like a lot of heavily regulated environments. I’ll talk to people in finance, and they’ll say, ‘What do you mean your faculty members have admin rights on their computer?’. ‘Well, yes, it’s higher ed’. ‘What do you mean you have students on your network?’. ‘Well, where else are they going to connect?’”
Rolling with the punches
It’s true that academia is a naturally and necessarily permissive environment, and for security leads who commonly lament being the person who says no to everything, that can be a shock. Kelley says she has learned to roll with the punches.
“Higher ed is a very interesting and difficult environment to work in,” she says. “It’s never well-funded. It is highly volatile, and you get new people in and out all the time – a high turnover of customers, if you will.”
In NJIT’s case, its role as a research centre also brings a diverse set of users – thousands of students from outside the US are drawn to its Newark-based campus, minutes across the Hudson River from New York City. Many of them are not native English speakers, and Kelley says she has had to learn to account for differing cultural norms in the course of her work.
“You don’t think that that applies to things like security, but it does,” she says. “In some cultures, there is less of a desire to question authority all the time, so we find that a lot of our international students tend to fall victims to scams a lot easier than some other people do.
“We try to give them information and say, for example, ‘You’re going to get job scams – don’t fall for them; no one is willing to pay you $500 a week for five hours of work’. We also had a student fall victim to a fake Ice [Immigration and Customs Enforcement] email about a year and a half ago – they paid Ice, quote unquote, $250, I think. I was like, ‘You’re never getting that back. That money’s gone!’”
Strength in numbers
But back to security operations. History shows Kelley did change her mind and let NJIT’s students loose in the SOC. It was a conversation on the fringes of a technology conference that persuaded her.
Sitting down one day with her Splunk contacts – NJIT was already all-in with Splunk for holistic management and observability across various campus data lakes and use cases – and fellow university IT leader, Louisiana State University’s Craig Woolley, who had done something similar already, she started to understand how such an endeavour actually works in practice.
Crucially, Kelley learned during this conversation, she wasn’t going to have to spend any time in a classroom with a laser pointer and a PowerPoint deck.
“He [Woolley] went over the programme with me and I was hooked,” she says. “I went down to LSU to see how they run it … they’ve created this programme that’s very cookie-cutter but customisable to suit your environment. They had taken a couple of years, figured it all out, so I was like, ‘We’re in, thank you for inventing the wheel, I’m going to slap it on my car’.”
The SOC itself is built on an Amazon Web Services (AWS) stack and backed by managed detection and response (MDR) services provided by Atlanta, Georgia-based security consultancy TekStream – now a partner of both LSU and NJIT.
This service is in turn underpinned by the power of Splunk using its security information and event management (Siem) and security orchestration, automation and response (Soar) tools – giving the students direct exposure to a widely adopted cyber platform and teaching them how to manage and respond to complex security incidents.
And like LSU, NJIT has also engaged with TekStream’s “whole-of-state” approach to security. This is a public sector-centric philosophy in which the word “state” literally means an actual US state, and is predicated on the idea of collaboration across multiple state-wide bodies.
As such, the student-powered programme is spreading, with LSU’s initial project now wrapping a security blanket around other higher education institutions in the state of Louisiana, and a second initiative – dubbed TigerSOC after LSU’s tiger mascot, Mike – offering commercial services to private sector customers as well, helping organisations across the US enhance their resilience while investing in affordable, home-grown security talent.
“Craig calls it the neighbourhood,” says Kelley, who has been happy to reap the benefits of strength in numbers.
While in the natural world, trees can “warn” each other about pests or predators by flooding connective fungal networks with chemical signals, here, relevant incident data, indicators of compromise (IoCs) and the like are drawn down from the Splunk environment and fed to the other institutions in the neighbourhood in minutes, and vice versa.
For example, says Kelley: “On our VPN [virtual private network], we get massive amounts of brute force attempts on people’s accounts, for example, [so] that immediately goes out and then everybody else has those IP addresses that those are coming from, and their firewalls get updated to block this stuff.”
Building cyber careers
Two distinct cohorts of students have now worked in NJIT’s SOC under Kelley, with the second group coming on board in June 2026, and she describes the scheme as a great success, not only benefiting NJIT, but also the students’ CVs.
“When they get out, they have basically a portfolio, a report card of all the incidents they worked, their close rate, all that important information, so that they can say when they graduate, they had a real job working real incidents,” she says.
“A lot of times college kids get fast food jobs – which are also real, hard jobs – but they were actually working security events and learning about the network and learning Splunk and coding languages, and all these different things. We’ve turned it into experiential learning and workforce development.”
If proof were needed that the scheme is working out, recruiters are taking notice. In fact, one of Kelley’s star performers was poached before he even graduated for an internship and potentially a job.
“I explain to them, ‘This is a commitment, you’re going to do two years in this student SOC and we’re going to pay you’. This kid came to me – he was one year in – he was supposed to do another year with me. He said, ‘I got another internship and I wouldn’t have got it without this year’. I said, ‘Well that’s the whole point, we’ll miss you but, run, fly, be free’. It’s been wonderful.”
Can CISOs trust the agentic SOC?
With enhancements to Splunk’s agentic SOC stack high on the agenda at Splunk .Conf 2026, Kelley is also now exploring the use of AI agents, and more specifically, given her security role, how to incorporate them into the environment in such a way as they can be trusted – trust in agents also being the overriding theme of this year’s event.
At .Conf in Denver, Colorado, Kelley participated in a panel session on agentic with Splunk customers from other verticals, and while she is clear that those in other industries will see things differently, ultimately, everybody agreed that data is key.
“What data? What data is it touching? What data are you sharing? What are they sharing this data with? Do you know where your data is? Is your data classified appropriately? That’s important, and if you don’t have that, there’s never going to be any trust with agentic AI,” she says.
On top of that data visibility – which was arguably Splunk’s original bread and butter and remains at the heart of everything the now Cisco-backed supplier sells – Kelley highlights the need for more appropriate guardrails, especially when working with third-party suppliers.
To create trust is to work with a vendor that you can have honest conversations with, and work with on co-development, and watch it every step of the way Sharon Kelley, New Jersey Institute of Technology
NJIT has already been working with another external supplier to create external AI agents for a set of very specific and closely scoped tasks – not yet cyber-focused ones.
Kelley says: “To create trust is to work with a vendor that you can have honest conversations with, and work with on co-development, and watch it every step of the way. It comes down to the harness. AI is the model and the harness, and the harness is where you’re building the guardrails, which you have to do.”
Kelley declares herself no AI refusenik, even though as a CISO she is well aware lots of people expect her to be. Nevertheless, she tempers her enthusiasm with a certain measured caution as she looks ahead to the future agentic SOC.
“I’m okay with it,” she says. “The idea is great. [Agentic] is going to solve problems that we have.
“[But] do we have all the agreements in place? Are we sure that we’re working with the right company? Let’s make sure that the guardrails are in place. Let’s make sure that these agents don’t get spicy together and decide to do what Anthropic’s agents did, or OpenAI when they start creating their own language, or convincing the other agents to sacrifice themselves.
“Trust is very hard,” she concludes. And in the world of the agentic SOC, if there is no trust, there is really no SOC at all.
IT leaders across the UK and Ireland are increasingly aware of the value dedicated chief information security officers (CISOs) can offer their organisations, and 73%…
The Central Bank of the United Arab Emirates (CBUAE) has launched a programme to speed up the digitisation of the country’s financial sector. The nine…
Table of Contents Putting archives into production NetApp simplifies the job Functional evolution As satellites move through space, the imagery and data readings that arrive…
The government is “looking into” reported problems with a second Post Office IT system that was used before the controversial Horizon software, in the latest…
A critical remote code execution (RCE) vulnerability in Microsoft Message Queuing (MSMQ) stands out as the most serious issue patched by Microsoft in its June…