
Speaker
Willem Berroubache
Security Project Manager / K8s Leader / AI Security Expert · Orange
About
Currently, I work as Stream Manager for 5G Core Security Monitoring & APIs at Orange, a global leader in telecommunications. Before that, I have managed innovative 5G projects involving Edge Computing and Kubernetes in collaboration with Google. I have conducted studies and PoCs on Edge Computing, automated and deployed 5G NF, and provided Kubernetes training to teams. I contributed to building PaaS, CaaS, and BMaaS platforms with Cloud Native solutions. I'm also CNCF Golden Kubestronaut (x5 K8s certified), and AAIF Ambassador, x2 GCP Professional Certified (Architect and Security).
Session
Autonomous Threat Detection at Scale: What Agentic AI Changes for Security Operations
TalkSecurity operations at telco scale generate a volume of events that no human team and no static ruleset can handle alone. At Orange, we decided to take a different path: building a fully on-premises, autonomous threat detection platform orchestrated by AI agents. This talk shares what we've learned deploying this stack in a real production environment. We'll cover how we designed a multi-agent orchestration architecture where specialized agents handle ingestion, correlation, anomaly detection and response coordination in parallel, how we scaled ML inference on local GPU hardware, and how the whole system is structured to keep humans in the loop where it matters most. We'll also go deep on the protocols and standards that made this work at scale: how we leverage MCP to give agents structured, contextual access to tools and data sources, and how A2A enables our agents to communicate, delegate and collaborate with each other in a way that's both auditable and extensible. These aren't just implementation details — they're what makes the difference between a fragile prototype and a production-grade agentic system. One of the things that changed our perspective: the orchestrator's ability to adapt automatically to different operational contexts, whether it's 5G core network functions, fixed network infrastructure, or broader IT systems. Same platform, different threat landscapes, without rebuilding everything from scratch each time. Because autonomy doesn't mean removing people from the equation. It means giving them better signals, at the right moment, so they can make faster and more confident decisions. The agents handle the noise. The humans handle the judgment calls. We'll show how this shift changed the way our security teams operate day to day: less time chasing false positives, more time on what actually counts. And we'll be straight about what it takes to go from a promising PoC to something you'd trust in a production environment.
Speaking at
- View event →
Cloud Native AI Summit — Paris
December 2–3, 2026