CF CloudFrame Job Scanner Open Dashboard →
Verified Active Opening

Manager, AI-Native Security Operations

Bamboohr17 • Utah | Hybrid

Job Description

<p><em>Please Note: This is a Utah-based hybrid position which will require some regular in-office days each week. Additionally, employment with BambooHR is contingent on passing both a background and credit check.</em></p> <p><strong>AI at BambooHR:</strong> At BambooHR, we believe in leveraging cutting-edge technology to empower people and transform HR. We’re actively integrating AI into our solutions and workflows to enhance efficiency and drive innovation. To that end, we’re looking to our existing team members and future hires to share this forward-thinking mindset: individuals who are curious about AI’s potential, eager to learn and adapt, and ready to explore how intelligent tools can elevate their work along with BambooHR’s impact on setting people free to do great work. Join us in reimagining the future of HR!</p> <p><strong>Essential Job Duties</strong></p> <p>BambooHR is rebuilding its Security Operations function around AI. We are not adding AI tooling to an existing SOC - we are redesigning how the work happens, so that automation and AI agents carry the volume and our people carry the judgment. We are looking for a manager to lead that team and own that transformation.</p> <p>You will lead a team spanning detection engineering, threat intelligence and hunting, and incident response. Day to day, you will run a live operation: incidents, detections, hunts, on-call coverage, service-provider relationships, and the operational metrics that leadership works from. Running alongside that operation is the change itself — automating triage and enrichment so analysts stop working queues, building detection content we write, tune and own, and standing up threat intelligence as a program that produces detections and hunt hypotheses rather than reports that have no clear actionable insights.</p> <p>The reason this role exists now is that the surface a security team defends is changing shape. As HR technology becomes more AI-driven and more agentic, autonomous software acts with real authority, machine identities multiply, and attacks accelerate. That surface grows faster than any security team can hire against, which is why we staff for judgment and build automation for volume. This role sits at the center of that decision - and the person in it will spend a meaningful part of their time deciding, in writing, how much authority automated systems are allowed to hold.</p> <p><strong>Supervisory Responsibilities:</strong></p> <ul> <li>Leads and grows a team of security analysts, detection engineers, and threat intelligence practitioners.</li> <li>Recruits, interviews, hires, onboards and retains technical security talent in a competitive market.</li> <li>Oversees the daily workflow of the team: shift coverage, on-call rotation, incident assignment, and detection backlog priority.</li> <li>Provides constructive and timely performance evaluations, and builds development plans against the skills an AI-native SOC actually requires: detection-as-code, agent supervision, and intelligence tradecraft.</li> <li>Supports career growth and internal mobility across the broader security organization, treating it as a retention strategy rather than a loss.</li> <li>Handles discipline and termination of employees in accordance with company policy.</li> </ul> <p><strong>Duties/Responsibilities:</strong></p> <p><strong>Run the operation</strong></p> <ul> <li>Own daily security operations end to end - alert handling, shift coverage, on-call rotation, escalation quality, and detection backlog priority and rule retirement.</li> <li>Serve as incident commander for the majority of security incidents, and partner with the VP of Information Security on the most severe i

Job Reference ID: CF-159438 • Posted on CloudFrame Job Scanner