Compliance and Security Lead

TEEMA

San Francisco (CA)

On-site

USD 207,000 - 276,000

Full time

14 days+
Application generator

Get a reply from this recruiter — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

TEEMA seeks a Compliance and Security Lead in San Francisco to own and advance security and compliance programs for a fast-growing environment.

The role encompasses SOC 2 readiness, vendor security management, MSP IT oversight, and incident response leadership, driving least-privilege and access governance across the company.

Qualifications

  • 5+ years of experience in security operations, GRC, IT security, or a similar security-focused role.
  • Experience owning or driving a company security program.
  • Strong familiarity with SOC 2; FedRAMP, ISO 27001, or similar frameworks are a plus.
  • Experience with incident response, endpoint security, access reviews, logging/monitoring, and remediation tracking.
  • Strong understanding of identity and access concepts: SSO, MFA, least privilege, access reviews, and joiner/mover/leaver processes.
  • Experience managing security vendors, consultants, auditors, or other external partners.
  • Comfort managing IT operations through an MSP or similar external provider; strong written and verbal communication skills.
  • Ability to operate independently, prioritize risk, and drive cross-functional follow-through in a startup environment.

Responsibilities

  • Own and manage the internal security program across people, systems, devices, vendors, and office environments.
  • Oversee security tooling for endpoint protection, SSO, MFA, access reviews, logging, monitoring, and alerting.
  • Lead security incident response, including triage, investigation, remediation, communications, and follow-up.
  • Run internal access reviews and improve least-privilege practices across company systems.
  • Manage physical and digital access controls for the office and internal tools.
  • Drive SOC 2 compliance work, including control ownership, evidence collection, audit readiness, and auditor coordination.
  • Maintain security policies, procedures, exceptions, control documentation, and audit evidence.
  • Track security risks and drive practical remediation based on business impact.
  • Help turn security and compliance requirements into repeatable operating processes.
  • Own vendor security reviews as part of Opal’s procurement process.
  • Manage ongoing third-party risk, including review cycles, evidence collection, and remediation follow-up.
  • Manage Opal’s security vendor: set priorities, review deliverables, elevate issues, and hold them accountable.
  • Own bug bounty / vulnerability disclosure program operations, including intake, triage coordination, SLA tracking, and reporting.
  • Coordinate vulnerability remediation across security vendors, engineering, legal, and business stakeholders.
  • Manage Opal’s IT MSP relationship and ensure IT execution supports security and compliance requirements.
  • Coordinate secure onboarding/offboarding across accounts, hardware, access, and device posture.
  • Hold the MSP accountable for device management, helpdesk, network support, and office infrastructure.
  • Oversee office network and A/V decisions, including UniFi networking with VLAN segmentation.
  • Evaluate whether MSP scope needs to change as Opal grows.

Skills

Security operations
Security program ownership
SOC 2 familiarity
Incident response
Identity and access management
Vendor management
MSP/outsourcing IT operations
Strong communication
Startup adaptability

Job description

Job Title: Compliance and Security Lead

Job ID: 90236

Location: San Francisco, California

What you will be doing: Security Operations
  • Own Opal’s internal security program across people, systems, devices, vendors, and office environments
  • Manage security tooling for endpoint protection, SSO, MFA, access reviews, logging, monitoring, and alerting
  • Lead security incident response, including triage, investigation, remediation, communications, and follow-up
  • Run internal access reviews and improve least-privilege practices across company systems
  • Manage physical and digital access controls for the office and internal tools
Compliance & Risk
  • Drive SOC 2 compliance work, including control ownership, evidence collection, audit readiness, and auditor coordination
  • Maintain security policies, procedures, exceptions, control documentation, and audit evidence
  • Track security risks and drive practical remediation based on business impact
  • Help turn security and compliance requirements into repeatable operating processes
Vendor Security & Vulnerability Management
  • Own vendor security reviews as part of Opal’s procurement process
  • Manage ongoing third-party risk, including review cycles, evidence collection, and remediation follow-up
  • Manage Opal’s security vendor: set priorities, review deliverables, elevate issues, and hold them accountable
  • Own bug bounty / vulnerability disclosure program operations, including intake, triage coordination, SLA tracking, and reporting
  • Coordinate vulnerability remediation across security vendors, engineering, legal, and business stakeholders
IT Oversight via MSP
  • Manage Opal’s IT MSP relationship and ensure IT execution supports security and compliance requirements
  • Coordinate secure onboarding/offboarding across accounts, hardware, access, and device posture
  • Hold the MSP accountable for device management, helpdesk, network support, and office infrastructure
  • Oversee office network and A/V decisions, including UniFi networking with VLAN segmentation
  • Evaluate whether MSP scope needs to change as Opal grows
What you must have:
  • 5+ years of experience in security operations, GRC, IT security, or a similar security-focused role
  • Experience owning or materially driving a company security program
  • Strong familiarity with SOC 2; FedRAMP, ISO 27001, or similar frameworks are a plus
  • Experience with incident response, endpoint security, access reviews, logging/monitoring, and remediation tracking
  • Strong understanding of identity and access concepts: SSO, MFA, least privilege, access reviews, and joiner/mover/leaver processes
  • Experience managing security vendors, consultants, auditors, or other external partners
  • Comfort managing IT operations through an MSP or similar external providerStrong written and verbal communication skills
  • Ability to operate independently, prioritize risk, and drive cross-functional follow-through in a startup environment

Salary/Rate Range: $150.00 -$200.00

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security & Compliance Lead
Security & Compliance Lead

Opal Security • San Francisco (CA)

On-site
USD 120,000 - 200,000
Security Operations Lead - SOC2, Vendor Risk, SF Office
Security Operations Lead - SOC2, Vendor Risk, SF Office

Opal Security • San Francisco (CA)

On-site
USD 120,000 - 200,000
Enterprise Account Executive - Bay Area
Enterprise Account Executive - Bay Area

Opal Security • San Francisco (CA)

On-site
USD 260,000 - 300,000
Competitive Salary
Early employee equity
Top-tier Medical Vision Dental
+7
Software Engineer, Infrastructure
Software Engineer, Infrastructure

Opal Security • San Francisco (CA)

On-site
USD 140,000 - 215,000
Security Compliance Analyst
Security Compliance Analyst

Managed IT & Security Provider • Alexandria (VA)

On-site
USD 75,000 - 100,000
401(k)
401(k) matching
Bonus based on performance
+3
Technical Customer Success Manager
Technical Customer Success Manager

opal • San Francisco (CA)

On-site
USD 120,000 - 180,000
Staff Security Analyst - GRC
Staff Security Analyst - GRC

Jobgether • United States

Hybrid
USD 150,000 - 164,000
Remote work within the United States
Hybrid option with designated offices
Lead, Cybersecurity Architecture & Operations
Lead, Cybersecurity Architecture & Operations

Culligan International • Rosemont (IL)

Hybrid
USD 140,000 - 180,000
Security Compliance Analyst
Security Compliance Analyst

Sur • United States

On-site
USD 22,000 - 33,000
Senior Manager, IT Security Operations
Senior Manager, IT Security Operations

Jobtailor • Washington

On-site
USD 140,000 - 180,000