Manager, AI-Native Security Operations
Listed on 2026-09-30
-
IT/Tech
Security Management & Operations, Cybersecurity, AI Engineer (Applied/Software)
Please Note:
This is a Utah-based hybrid position which will require some regular in-office days each week. Additionally, employment with BambooHR is contingent on passing both a background and credit check.
AI at BambooHR: At BambooHR, we believe in leveraging cutting-edge technology to empower people and transform HR. We’re actively integrating AI into our solutions and workflows to enhance efficiency and drive innovation. To that end, we’re looking to our existing team members and future hires to share this forward-thinking mindset: individuals who are curious about AI’s potential, eager to learn and adapt, and ready to explore how intelligent tools can elevate their work along with BambooHR’s impact on setting people free to do great work.
Join us in reimagining the future of HR!
Job Duties
BambooHR is rebuilding its Security Operations function around AI. We are not adding AI tooling to an existing SOC - we are redesigning how the work happens, so that automation and AI agents carry the volume and our people carry the judgment. We are looking for a manager to lead that team and own that transformation.
You will lead a team spanning detection engineering, threat intelligence and hunting, and incident response. Day to day, you will run a live operation: incidents, detections, hunts, on-call coverage, service-provider relationships, and the operational metrics that leadership works from. Running alongside that operation is the change itself — automating triage and enrichment so analysts stop working queues, building detection content we write, tune and own, and standing up threat intelligence as a program that produces detections and hunt hypotheses rather than reports that have no clear actionable insights.
The reason this role exists now is that the surface a security team defends is changing shape. As HR technology becomes more AI-driven and more agentic, autonomous software acts with real authority, machine identities multiply, and attacks accelerate. That surface grows faster than any security team can hire against, which is why we staff for judgment and build automation for volume.
This role sits at the center of that decision - and the person in it will spend a meaningful part of their time deciding, in writing, how much authority automated systems are allowed to hold.
- Leads and grows a team of security analysts, detection engineers, and threat intelligence practitioners.
- Recruits, interviews, hires, onboards and retains technical security talent in a competitive market.
- Oversees the daily workflow of the team: shift coverage, on-call rotation, incident assignment, and detection backlog priority.
- Provides constructive and timely performance evaluations, and builds development plans against the skills an AI-native SOC actually requires: detection-as-code, agent supervision, and intelligence tradecraft.
- Supports career growth and internal mobility across the broader security organization, treating it as a retention strategy rather than a loss.
- Handles discipline and termination of employees in accordance with company policy.
- Own daily security operations end to end - alert handling, shift coverage, on-call rotation, escalation quality, and detection backlog priority and rule retirement.
- Serve as incident commander for the majority of security incidents, and partner with the VP of Information Security on the most severe incidents and on executive communication.
- Manage security service-provider relationships, including service reviews, escalation quality, and tuning direction.
- Publish a regular operational metrics pack that the team and executive leadership both work from.
- Build…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).