Manager, AI-Native Security Operations
Bamboohr17 · Utah | Hybrid
About this role
**Manager, AI-Native Security Operations** > **Location & checks:** Utah-based hybrid role with some regular in-office days each week. Employment is contingent on passing a background and credit check. --- ## AI at BambooHR BambooHR is integrating AI into its solutions and workflows to improve efficiency and drive innovation. This role is part of rebuilding Security Operations around an AI-native approach—where automation and AI agents handle volume and people provide judgment. --- ## Essential Job Duties ### Supervisory Responsibilities - Lead and grow a team of security analysts, detection engineers, and threat intelligence practitioners. - Recruit, interview, hire, onboard, and retain technical security talent. - Oversee daily workflow (shift coverage, on-call rotation, incident assignment, detection backlog priority). - Provide performance evaluations and development plans for an AI-native SOC (detection-as-code, agent supervision, intelligence tradecraft). - Support career growth and internal mobility across the broader security organization. - Handle discipline and termination in accordance with company policy. ### Run the Operation - Own daily security operations end to end: alert handling, shift coverage, on-call rotation, escalation quality, and detection backlog priority/rule retirement. - Serve as incident commander for most security incidents; partner with the VP of Information Security on severe incidents and executive communication. - Manage security service-provider relationships (service reviews, escalation quality, tuning direction). - Publish an operational metrics pack for both the team and executive leadership. ### Automate the Volume, Not the Analyst - Build and enforce an automated incident runbook program for the incident types driving most alert volume. - Automate Tier-1 triage and expand Tier-2 workflows so routine work resolves without human touch; escalations should arrive as assembled cases (timeline, scope, blast radius). - Redirect reclaimed capacity toward deeper investigation, detection engineering, and threat intelligence. ### Own the Detections - Run detection engineering as a product: maintain a prioritized backlog, manage rules in version control with CI validation, and own the full lifecycle (write, test, deploy, measure, retire). - Build in-house detection capability using BambooHR’s own security telemetry so detections can be explained to engineers, auditors, and customers. ### Build Threat Intelligence & Hunting into Programs - Stand up a formal threat intelligence program (intelligence requirements, collection plan, threat model grounded in risks to employee and payroll data). - Ensure every intelligence output results in a detection, hunt hypothesis, or control change. - Run hypothesis-driven hunting on a regular cadence and make intelligence useful beyond the SOC. ### Build the AI-Native SOC - Lead the shift from AI-assisted work (agents draft, humans approve) to delegated work (agents act within explicit, written authority boundaries). - Keep key decisions human: adversary reasoning, incident command when consequences are real, disclosure decisions, and non-delegable calls. - Build coverage for AI-era threats (prompt injection/tool abuse, autonomous software with real authority, and machine identity at scale). - Partner across security engineering, product security, identity & access management, and governance/risk for shared platforms, threats, and audit obligations. --- ## What Y
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.