Enter a job title or keyword

Security & Compliance Lead

Opal Security


Job Location:

San Francisco, CA - USA

Yearly Salary: USD 120000 - 200000
Posted: 22 August 2026 (Yesterday)
Application Deadline: 19 November 2026
Vacancies: 1 Vacancy

Department:

Engineering

Job Summary

About Opal Security:

The best security and engineering teams use Opal Security the AI-native access platform for real-time visibility policy-as-code and control over every identity from employees to service accounts to AI agents. Companies like Databricks Notion CoreWeave and Superhuman rely on Opal. Based in San Francisco weve raised $59M from Greylock Battery Ventures and SVCI and were named to Notable Capitals Rising in Cyber 2026 list by 150 leading CISOs. Our leadership brings deep security pedigree: CEO Howard Ting (previously CEO of Cyberhaven CMO at Nutanix) CPO Sameer Mehta (Veza Citrix) and CTO Alex Pien (Meta) among others whove built category-defining products.

The Role

Were hiring a Security Manager to own Opals internal security program. This person will be responsible for our security operations compliance posture vendor risk incident response and security tooling.

This is a hands-on security-first role for someone who can operate independently work well with external partners and keep a fast-moving startup secure without slowing it down. Youll manage our security vendor and partner closely with engineering operations and leadership. Youll also oversee IT operations through our managed service provider (MSP) making sure onboarding/offboarding devices access and office infrastructure meet our security and compliance needs.

This is not primarily an AppSec role. Product security and AppSec will remain closely partnered with Engineering though this person will help coordinate security intake bug bounty operations vulnerability management and remediation tracking.

We are building Opal together in person. This role is 3 days in office in downtown San Francisco.

What Youll Own

Security Operations
  • Own Opals internal security program across people systems devices vendors and office environments

  • Manage security tooling for endpoint protection SSO MFA access reviews logging monitoring and alerting

  • Lead security incident response including triage investigation remediation communications and follow-up

  • Run internal access reviews and improve least-privilege practices across company systems

  • Manage physical and digital access controls for the office and internal tools

Compliance & Risk
  • Drive SOC 2 compliance work including control ownership evidence collection audit readiness and auditor coordination

  • Maintain security policies procedures exceptions control documentation and audit evidence

  • Track security risks and drive practical remediation based on business impact

  • Help turn security and compliance requirements into repeatable operating processes

Vendor Security & Vulnerability Management
  • Own vendor security reviews as part of Opals procurement process

  • Manage ongoing third-party risk including review cycles evidence collection and remediation follow-up

  • Manage Opals security vendor: set priorities review deliverables escalate issues and hold them accountable

  • Own bug bounty / vulnerability disclosure program operations including intake triage coordination SLA tracking and reporting

  • Coordinate vulnerability remediation across security vendors engineering legal and business stakeholders

IT Oversight via MSP
  • Manage Opals IT MSP relationship and ensure IT execution supports security and compliance requirements

  • Coordinate secure onboarding/offboarding across accounts hardware access and device posture

  • Hold the MSP accountable for device management helpdesk network support and office infrastructure

  • Oversee office network and A/V decisions including UniFi networking with VLAN segmentation

  • Evaluate whether MSP scope needs to change as Opal grows

What Were Looking For
  • 5 years of experience in security operations GRC IT security or a similar security-focused role

  • Experience owning or materially driving a company security program

  • Strong familiarity with SOC 2; FedRAMP ISO 27001 or similar frameworks are a plus

  • Experience with incident response endpoint security access reviews logging/monitoring and remediation tracking

  • Strong understanding of identity and access concepts: SSO MFA least privilege access reviews and joiner/mover/leaver processes

  • Experience managing security vendors consultants auditors or other external partners

  • Comfort managing IT operations through an MSP or similar external provider

  • Strong written and verbal communication skills

  • Ability to operate independently prioritize risk and drive cross-functional follow-through in a startup environment

Nice to Have
  • Experience at a security identity or access management company

  • Experience running or coordinating bug bounty / vulnerability disclosure programs

  • Security certifications such as Security CISSP CISM or similar

  • Experience building or maturing a security program from an early stage


About Company

Company Logo

Opal is the identity security platform for modern enterprises. With Opal, companies can implement least privilege, automate access reviews, and accelerate access requests.

View Profile View Profile