Security & Compliance Lead

Opal

San Francisco (CA)

On-site

USD 150,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Opal Security in San Francisco is seeking a Security Manager to own our internal security program, including operations, risk, and vendor oversight. This hands-on role collaborates with engineering, operations, and leadership to keep our startup secure while moving fast.

You will supervise IT operations via our MSP, oversee SOC 2 readiness, incident response, bug bounty coordination, and remediation tracking, with 3+ days in the office in downtown San Francisco.

Qualifications

  • 5+ years of experience in security operations, GRC, IT security, or similar security-focused role.
  • Experience owning or driving a company security program.
  • Familiarity with SOC 2; FedRAMP, ISO 27001, or similar frameworks a plus.
  • Experience with incident response, endpoint security, access reviews, logging/monitoring, and remediation tracking.
  • Strong understanding of identity and access concepts: SSO, MFA, least privilege, access reviews, joiner/mover/leaver processes.
  • Experience managing security vendors, consultants, auditors, or other external partners.
  • Comfort managing IT operations through an MSP or similar external provider.
  • Strong written and verbal communication skills.
  • Ability to operate independently, prioritize risk, and drive cross-functional follow-through in a startup environment.

Responsibilities

  • Own Opal's internal security program across people, systems, devices, vendors, and office environments.
  • Manage security tooling for endpoint protection, SSO, MFA, access reviews, logging, monitoring, and alerting.
  • Lead security incident response, including triage, investigation, remediation, communications, and follow-up.
  • Run internal access reviews and improve least-privilege practices across company systems.
  • Manage physical and digital access controls for the office and internal tools.
  • Drive SOC 2 compliance work, including control ownership, evidence collection, audit readiness, and auditor coordination.
  • Maintain security policies, procedures, exceptions, control documentation, and audit evidence.
  • Track security risks and drive practical remediation based on business impact.

Skills

Security operations
GRC program ownership
SOC 2 familiarity
Incident response
Identity & access
Vendor management
MSP IT operations
Communication skills
Startup risk governance

Job description

About Opal Security:

The best security and engineering teams use Opal Security, the AI-native access platform, for real-time visibility, policy-as-code, and control over every identity, from employees to service accounts to AI agents. Companies like Databricks, Notion, CoreWeave, and Superhuman rely on Opal. Based in San Francisco, we've raised $59M from Greylock, Battery Ventures, and SVCI, and were named to Notable Capital's Rising in Cyber 2026 list by 150 leading CISOs. Our leadership brings deep security pedigree: CEO Howard Ting (previously CEO of Cyberhaven, CMO at Nutanix), CPO Sameer Mehta (Veza, Citrix), and CTO Alex Pien (Meta), among others who've built category-defining products.

The Role

We're hiring a Security Manager to own Opal's internal security program. This person will be responsible for our security operations, compliance posture, vendor risk, incident response, and security tooling.

This is a hands-on, security-first role for someone who can operate independently, work well with external partners, and keep a fast-moving startup secure without slowing it down. You'll manage our security vendor and partner closely with engineering, operations, and leadership. You'll also oversee IT operations through our managed service provider (MSP), making sure onboarding/offboarding, devices, access, and office infrastructure meet our security and compliance needs.

This is not primarily an AppSec role. Product security and AppSec will remain closely partnered with Engineering, though this person will help coordinate security intake, bug bounty operations, vulnerability management, and remediation tracking.

We are building Opal together, in person. This role is 3+ days in office in downtown San Francisco.

What You'll Own
Security Operations
  • Own Opal's internal security program across people, systems, devices, vendors, and office environments

  • Manage security tooling for endpoint protection, SSO, MFA, access reviews, logging, monitoring, and alerting

  • Lead security incident response, including triage, investigation, remediation, communications, and follow-up

  • Run internal access reviews and improve least-privilege practices across company systems

  • Manage physical and digital access controls for the office and internal tools

Compliance & Risk
  • Drive SOC 2 compliance work, including control ownership, evidence collection, audit readiness, and auditor coordination

  • Maintain security policies, procedures, exceptions, control documentation, and audit evidence

  • Track security risks and drive practical remediation based on business impact

  • Help turn security and compliance requirements into repeatable operating processes

Vendor Security & Vulnerability Management
  • Own vendor security reviews as part of Opal's procurement process

  • Manage ongoing third-party risk, including review cycles, evidence collection, and remediation follow-up

  • Manage Opal's security vendor: set priorities, review deliverables, escalated issues, and hold them accountable

  • Own bug bounty / vulnerability disclosure program operations, including intake, triage coordination, SLA tracking, and reporting

  • Coordinate vulnerability remediation across security vendors, engineering, legal, and business stakeholders

IT Oversight via MSP
  • Manage Opal's IT MSP relationship and ensure IT execution supports security and compliance requirements

  • Coordinate secure onboarding/offboarding across accounts, hardware, access, and device posture

  • Hold the MSP accountable for device management, helpdesk, network support, and office infrastructure

  • Oversee office network and A/V decisions, including UniFi networking with VLAN segmentation

  • Evaluate whether MSP scope needs to change as Opal grows

What We're Looking For
  • 5+ years of experience in security operations, GRC, IT security, or a similar security-focused role

  • Experience owning or materially driving a company security program

  • Strong familiarity with SOC 2; FedRAMP, ISO 27001, or similar frameworks are a plus

  • Experience with incident response, endpoint security, access reviews, logging/monitoring, and remediation tracking

  • Strong understanding of identity and access concepts: SSO, MFA, least privilege, access reviews, and joiner/mover/leaver processes

  • Experience managing security vendors, consultants, auditors, or other external partners

  • Comfort managing IT operations through an MSP or similar external provider

  • Strong written and verbal communication skills

  • Ability to operate independently, prioritize risk, and drive cross-functional follow-through in a startup environment

Nice to Have
  • Experience at a security, identity, or access management company

  • Experience running or coordinating bug bounty / vulnerability disclosure programs

  • Security certifications such as Security+, CISSP, CISM, or similar

  • Experience building or maturing a security program from an early stage

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security & Compliance Lead
Security & Compliance Lead

Opal Security • San Francisco (CA)

On-site
USD 120,000 - 200,000
Security & Compliance Lead — Build a Secure Startup Program
Security & Compliance Lead — Build a Secure Startup Program

Opal • San Francisco (CA)

On-site
USD 150,000 - 190,000
Security Operations Lead - SOC2, Vendor Risk, SF Office
Security Operations Lead - SOC2, Vendor Risk, SF Office

Opal Security • San Francisco (CA)

On-site
USD 120,000 - 200,000
Forward Deployed Engineer
Forward Deployed Engineer

Opal Security • San Francisco (CA)

On-site
USD 140,000 - 250,000
Competitive Salary
Early employee equity
Top-tier Medical, Vision, & Dental coverage
+7
Software Engineer
Software Engineer

Opal Security • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Competitive Salary
Early employee equity
Top-tier Medical, Vision, & Dental coverage
+7
Product Manager
Product Manager

Opal Security • San Francisco (CA)

On-site
USD 130,000 - 160,000
Recruiting and Workplace Experience Coordinator
Recruiting and Workplace Experience Coordinator

Opal • San Francisco (CA)

On-site
USD 65,000 - 85,000
Solutions Engineer
Solutions Engineer

Opal Security • San Francisco (CA)

On-site
USD 100,000 - 130,000
Software Engineer, Infrastructure
Software Engineer, Infrastructure

Opal Security • San Francisco (CA)

On-site
USD 140,000 - 215,000
Enterprise Security Engineer
Enterprise Security Engineer

Opendoor • Miami (FL)

On-site
USD 110,000 - 140,000