BambooHR

Manager, AI-Native Security Operations

Utah · Hybrid · Posted today

Opens job-boards.greenhouse.io

Get a version of your resume written for this job.

Salary
Not listed
Job type
Not specified
Work mode
Hybrid
Source
Greenhouse (employer's hiring system)

Skills mentioned

Incident Response, SaaS, LLM, SOC 2, ISO 27001

About the role

Please Note: This is a Utah-based hybrid position which will require some regular in-office days each week. Additionally, employment with BambooHR is contingent on passing both a background and credit check.

AI at BambooHR: At BambooHR, we believe in leveraging cutting-edge technology to empower people and transform HR. We’re actively integrating AI into our solutions and workflows to enhance efficiency and drive innovation. To that end, we’re looking to our existing team members and future hires to share this forward-thinking mindset: individuals who are curious about AI’s potential, eager to learn and adapt, and ready to explore how intelligent tools can elevate their work along with BambooHR’s impact on setting people free to do great work. Join us in reimagining the future of HR!

Essential Job Duties

BambooHR is rebuilding its Security Operations function around AI. We are not adding AI tooling to an existing SOC - we are redesigning how the work happens, so that automation and AI agents carry the volume and our people carry the judgment. We are looking for a manager to lead that team and own that transformation.

You will lead a team spanning detection engineering, threat intelligence and hunting, and incident response. Day to day, you will run a live operation: incidents, detections, hunts, on-call coverage, service-provider relationships, and the operational metrics that leadership works from. Running alongside that operation is the change itself — automating triage and enrichment so analysts stop working queues, building detection content we write, tune and own, and standing up threat intelligence as a program that produces detections and hunt hypotheses rather than reports that have no clear actionable insights.

The reason this role exists now is that the surface a security team defends is changing shape. As HR technology becomes more AI-driven and more agentic, autonomous software acts with real authority, machine identities multiply, and attacks accelerate. That surface grows faster than any security team can hire against, which is why we staff for judgment and build automation for volume. This role sits at the center of that decision - and the person in it will spend a meaningful part of their time deciding, in writing, how much authority automated systems are allowed to hold.

Supervisory Responsibilities:

  • Leads and grows a team of security analysts, detection engineers, and threat intelligence practitioners.
  • Recruits, interviews, hires, onboards and retains technical security talent in a competitive market.
  • Oversees the daily workflow of the team: shift coverage, on-call rotation, incident assignment, and detection backlog priority.
  • Provides constructive and timely performance evaluations, and builds development plans against the skills an AI-native SOC actually requires: detection-as-code, agent supervision, and intelligence tradecraft.
  • Supports career growth and internal mobility across the broader security organization, treating it as a retention strategy rather than a loss.
  • Handles discipline and termination of employees in accordance with company policy.

Duties/Responsibilities:

Run the operation

  • Own daily security operations end to end - alert handling, shift coverage, on-call rotation, escalation quality, and detection backlog priority and rule retirement.
  • Serve as incident commander for the majority of security incidents, and partner with the VP of Information Security on the most severe incidents and on executive communication.
  • Manage security service-provider relationships, including service reviews, escalation quality, and tuning direction.
  • Publish a regular operational metrics pack that the team and executive leadership both work from.

Automate the volume, not the analyst

  • Build and enforce an automated incident runbook program covering the incident types behind the majority of alert volume.
  • Drive the automation of Tier-1 triage and a growing share of Tier-2 workflows, so routine work resolves without a human touching it and escalations arrive as an assembled case with clear timeline, scope, and blast radius, rather than a raw alert.
  • Redirect reclaimed capacity upward rather than out of the team - into deeper investigation, detection engineering, and threat intelligence.

Own the detections

  • Run detection engineering as a product: a prioritized backlog including rules in version control with CI validation, and a full lifecycle of write, test, deploy, measure and retire.
  • Build in-house detection capability against our own security telemetry, so detection content is something we write, tune and can explain to an engineer, an auditor or a customer.

Build threat intelligence and hunting into programs

  • Stand up a formal threat intelligence program: approved intelligence requirements, a collection plan mapped to real sources, and a threat model grounded in the risks that actually apply to employee and payroll data.
  • Ensure every finished intelligence product ends in a detection, a hunt hypothesis, or a control change.
  • Run a hypothesis-driven hunting program on a regular cadence, and make intelligence genuinely useful to teams outside the SOC.

Build the AI-native SOC

  • Lead the team through the shift from AI-assisted work (where agents draft and humans approve) to delegated work (where agents act inside explicit, written authority boundaries).
  • Protect what stays human - adversary reasoning, incident command when consequences are real, disclosure decisions, and the calls that should not be delegated to a machine.
  • Build detection and response coverage for AI-era threats: prompt injection and tool abuse, autonomous software operating with real authority, and machine identity at scale.
  • Partner across security engineering, product security, identity and access management, and governance and risk on shared platforms, shared threats, and shared audit obligations.

What You Need to Get the Job Done

  • 5+ years in security operations, incident response, or detection engineering, including 2+ years directly managing a team of security analysts or detection engineers.
  • Experience running a SOC or detection function at a SaaS or cloud-native company, ideally one with a multi-tenant product and a live compliance calendar (SOC 2 and/or ISO 27001).
  • Hands-on detection engineering credibility. You have personally written, tested, tuned and retired detections, and you are comfortable treating detection content as code in version control with CI validation.
  • Experience owning a managed detection relationship (MDR or MSSP).
  • Direct experience automating SOC workflows through SOAR, runbook automation, or LLM- and agent-based triage and enrichment. You can speak concretely about what was automated, what the false-negative rate was, and how you measured it.
  • Working fluency with modern security data platforms — data lake or lakehouse architectures — and comfort querying telemetry directly rather than only through a vendor console.
  • Incident command experience under real pressure, including executive and cross-functional communication during an active incident.
  • Strong people leadership: hiring, coaching, performance management, and the judgment to lead a technical team through significant change honestly rather than through reassurance.
  • Excellent written communication. This role publishes runbooks, authority boundaries, intelligence requirements, and metrics that executives read.
  • Excellent prioritization, and the ability to say no with a reason. The defended surface grows faster than any team does, and protecting your team from over-commitment is part of the job.
  • Comfort working in an AI-forward environment where agents write and test code, participate in design review, and run triage.
  • Ability to function well in a high-paced and at times stressful environment, including on-call escalation.
  • Bachelor's degree in Computer Science, Information Security, or a related field - or equivalent practical experience. Practical experience is weighted more heavily than the degree.
  • At least five years of related security operations experience required.
  • Physical requirements can include prolonged periods of sitting at a desk and working on a computer.
  • Must be available for on-call escalation and to lead incident response outside standard business hours when incident severity requires it.

What Will Make Us REALLY Love You

  • Experience securing AI or agentic systems - prompt injection, tool abuse, and third-party or autonomous code holding execution authority.
  • Prior experience standing up a threat intelligence program from zero: intelligence requirements, collection planning, intel-to-detection pipeline, and adversary emulation.
  • Experience transitioning detection capability in-house from a managed provider.
  • Experience with non-human identity at scale - service accounts, workload identity, machine credentials - and its detection implications.
  • Background in HR, payroll, or fintech SaaS, or other environments where employee data and payment fraud are primary adversary objectives.
  • Experience with cyber resilience practice: backup immutability verification, recovery drills, and recovery-time objectives measured against contractual commitments.
  • Experience building or supervising LLM agents in production, including evaluation, guardrail design, and human-in-the-loop review patterns.
  • Public contribution to the detection engineering or threat intelligence community - detection rules, open-source tooling, conference talks, or published research.
  • Security certifications (GCIA, GCIH, GCFA, GDAT, GCTI, OSCP, CISSP) preferred, not required.

What You'll Love About Us

  • A Great Company Culture that has been recognized by multiple organizations like Inc, and Salt Lake Tribune
  • Comprehensive health, life, and disability insurance
  • Generous leave policies that include 4 weeks of vacation, 12 company holidays, parental leave, and volunteer time off so you can enjoy quality of life
  • 401k plans with up to 6% company match
  • $2000 Paid-Paid Vacation bonus
  • EAP through Headspace
  • Check out all our benefits that benefit you

About Us

At BambooHR, we're building something different: we're building a people intelligence platform that transforms HR and sets people free to do great work! We're a proven market leader driving innovation while building lasting success through thoughtful, sustainable growth. Here, you'll find a place that champions growth: both professional and personal, both individual and collective. 

We invest in potential, giving you the space to stretch your capabilities and turn good ideas into reality while providing the safety net of a supportive, values-driven culture. Our approach combines meaningful work with meaningful lives, offering competitive benefits, professional development, and the flexibility to thrive both in and outside the office. 

What sets us apart isn't just what we do, but how we do it: with openness, integrity, and a shared commitment to doing the right thing. Join us in creating HR software that makes work better for everyone, while we make work better for you.

BambooHR is committed to the full inclusion of all qualified individuals and will ensure that persons with disabilities are provided reasonable accommodations throughout the hiring process.  If you would like to request accommodations, please let your recruiter know.

BambooHR is An Equal Opportunity Employer--M/F/D/V
Because our team members are trusted to handle sensitive information, we require all candidates that receive and accept employment offers to complete a background check before being hired.

For information on California Privacy Policy, click here.

Our process utilizes AI as an assistant to efficiently process and analyze candidate data. Recruiters and hiring managers maintain full oversight and accountability, ensuring that all final selection and rejection decisions are human-made and based solely on objective job qualifications. Please see our General Privacy Notice and California Privacy Notice for more details.

See our AI Guidelines for Candidates for details on how BambooHR uses AI in recruiting, how we expect candidates to use AI, and what is not allowed. 

Job ID gh-bamboohr17-6190324004 · Original posting ↗