Oh My JobFind Jobs
Company
  • About Us
  • Blog
  • Contact
Tools
  • Paycheck Calculator
Legal
  • Terms of Service
  • Privacy Policy
  • California Privacy Rights
For Employers
Post a Job

Security Manager

Opal Security
Opal Security
San Francisco
Jul 29, 2026
120K – $200K • Offers Bonus
FullTime

Job Description

Opal Security is hiring a Security Manager to own the company's internal security program, including security operations, compliance, vendor risk, incident response, and security tooling. This is a hands-on role for someone who can operate independently, secure a fast-moving startup without creating friction, and partner effectively with engineering, operations, and leadership. The position requires 3+ days per week in our downtown San Francisco office.

About the Role

You will build and mature Opal's internal security program across people, systems, devices, vendors, and office environments. This role spans security operations, GRC (governance, risk, and compliance), vendor management, and IT oversight—but is not primarily focused on application security or product security, which will remain partnered with engineering. You'll manage our security vendor relationship, coordinate with an external managed IT service provider, and work cross-functionally to keep the company secure while maintaining compliance and scaling responsibly.

Responsibilities

Security Operations

  • Own Opal's internal security program including endpoint protection, SSO, MFA, access reviews, logging, monitoring, and alerting
  • Lead security incident response: triage, investigation, remediation, communication, and follow-up
  • Conduct internal access reviews and strengthen least-privilege practices across company systems
  • Manage physical and digital access controls for office and internal tools

Compliance & Risk (GRC)

  • Drive SOC 2 compliance work including control ownership, evidence collection, audit readiness, and auditor coordination
  • Maintain security policies, procedures, exceptions, control documentation, and audit evidence
  • Track security risks and drive remediation based on business impact
  • Translate security and compliance requirements into repeatable operating processes

Vendor Security & Vulnerability Management

  • Own vendor security reviews as part of procurement, and manage ongoing third-party risk assessment cycles
  • Manage Opal's security vendor: set priorities, review deliverables, escalate issues, and ensure accountability
  • Operate the bug bounty and vulnerability disclosure program including intake, triage, SLA tracking, and reporting
  • Coordinate vulnerability remediation across security vendors, engineering, legal, and business stakeholders

IT Oversight via Managed Service Provider

  • Manage the MSP relationship and ensure IT execution supports security and compliance needs
  • Coordinate secure employee onboarding and offboarding across accounts, hardware, access, and device posture
  • Hold the MSP accountable for device management, helpdesk, network support, and office infrastructure
  • Oversee office network and A/V decisions, including UniFi networking with VLAN segmentation
  • Evaluate MSP scope as Opal grows

Requirements

  • 5+ years of experience in security operations, GRC, IT security, or related security-focused roles
  • Experience owning or materially driving a company security program
  • Strong familiarity with SOC 2 compliance; FedRAMP, ISO 27001, or similar frameworks are a plus
  • Demonstrated experience with incident response, endpoint security, access reviews, logging and monitoring, and remediation tracking
  • Strong understanding of identity and access concepts: SSO, MFA, least privilege, access reviews, and joiner/mover/leaver processes
  • Experience managing security vendors, consultants, auditors, or other external partners
  • Comfort managing IT operations through an MSP or similar external provider
  • Strong written and verbal communication skills
  • Ability to operate independently, prioritize risk, and drive cross-functional follow-through in a startup environment

Nice to Have

  • Experience at a security, identity, or access management company
  • Experience running or coordinating bug bounty or vulnerability disclosure programs
  • Experience supporting federal-readiness, public-sector customers, or FedRAMP preparation
  • Security certifications such as Security+, CISSP, CISM, or equivalent
  • Experience building or maturing a security program from early stage

Benefits

Opal Security has raised $59M from leading investors including Greylock and Battery Ventures, and was named to Notable Capital's Rising in Cyber 2026 list by 150 leading CISOs. You'll work alongside experienced security and engineering leaders, including our CEO (formerly CEO of Cyberhaven, CMO at Nutanix), CPO (from Veza and Citrix), and CTO (from Meta).

Apply now
Share: