Job Title: Compliance and Security Lead
Job ID: 90236
Location: San Francisco, California
What you will be doing: Security Operations
- Own Opal’s internal security program across people, systems, devices, vendors, and office environments
- Manage security tooling for endpoint protection, SSO, MFA, access reviews, logging, monitoring, and alerting
- Lead security incident response, including triage, investigation, remediation, communications, and follow-up
- Run internal access reviews and improve least-privilege practices across company systems
- Manage physical and digital access controls for the office and internal tools
Compliance & Risk
- Drive SOC 2 compliance work, including control ownership, evidence collection, audit readiness, and auditor coordination
- Maintain security policies, procedures, exceptions, control documentation, and audit evidence
- Track security risks and drive practical remediation based on business impact
- Help turn security and compliance requirements into repeatable operating processes
Vendor Security & Vulnerability Management
- Own vendor security reviews as part of Opal’s procurement process
- Manage ongoing third-party risk, including review cycles, evidence collection, and remediation follow-up
- Manage Opal’s security vendor: set priorities, review deliverables, elevate issues, and hold them accountable
- Own bug bounty / vulnerability disclosure program operations, including intake, triage coordination, SLA tracking, and reporting
- Coordinate vulnerability remediation across security vendors, engineering, legal, and business stakeholders
IT Oversight via MSP
- Manage Opal’s IT MSP relationship and ensure IT execution supports security and compliance requirements
- Coordinate secure onboarding/offboarding across accounts, hardware, access, and device posture
- Hold the MSP accountable for device management, helpdesk, network support, and office infrastructure
- Oversee office network and A/V decisions, including UniFi networking with VLAN segmentation
- Evaluate whether MSP scope needs to change as Opal grows
What you must have:
- 5+ years of experience in security operations, GRC, IT security, or a similar security-focused role
- Experience owning or materially driving a company security program
- Strong familiarity with SOC 2; FedRAMP, ISO 27001, or similar frameworks are a plus
- Experience with incident response, endpoint security, access reviews, logging/monitoring, and remediation tracking
- Strong understanding of identity and access concepts: SSO, MFA, least privilege, access reviews, and joiner/mover/leaver processes
- Experience managing security vendors, consultants, auditors, or other external partners
- Comfort managing IT operations through an MSP or similar external providerStrong written and verbal communication skills
- Ability to operate independently, prioritize risk, and drive cross-functional follow-through in a startup environment
Salary/Rate Range: $150.00 -$200.00