Opal logo

Security & Compliance Lead

Opal

San Francisco, CA · HybridFull-time$120–200K/yrPosted 1mo agoStill listed 2w ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$120–200K/yr
Location
San Francisco, CAHybrid
Schedule
Full-time
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

Opal is hiring a Security & Compliance Lead. Opal is seeking a Security & Compliance Lead to own and advance its internal security program, overseeing security operations, compliance, vendor risk, incident response, and tooling while collaborating with engineering, leadership, and external partners in a fast‑moving startup environment.

Key focus areas include Own internal security program across people, systems, devices, vendors, and office environments, Manage security tooling for endpoint protection, SSO, MFA, access reviews, logging, monitoring, and alerting, and Lead security incident response including triage, investigation, remediation, communications, and follow‑up.

Successful candidates bring 5+ Years Security Operations, GRC, IT Security, Or Similar Experience. Important skills include Security Operations, GRC, IT Security, SOC 2, Incident Management, and Endpoint Security. Preferred (not required): FedRAMP, ISO 27001, Bug Bounty Program Operations, and Vulnerability Disclosure Program Operations.

Skills & qualifications

RequiredNice to have

Skills

Security OperationsGRCIT SecuritySOC 2Incident ManagementEndpoint SecurityAccess ReviewsLogging/MonitoringRemediation TrackingSSOMFALeast PrivilegeJoiner/Mover/Leaver ProcessesManaging Security VendorsManaging ConsultantsManaging AuditorsManaging External PartnersManaging IT Operations Through MSPCommunicationOperating IndependentlyPrioritize RiskCross-Functional Follow-ThroughFedRAMPISO 27001Bug Bounty Program OperationsVulnerability Disclosure Program OperationsFederal-Readiness SupportPublic-Sector Customer SupportBuilding Security Program From Early StageCompany Security Program ManagementIdentity and Access ConceptsSecurity Vendor ManagementIT Operations Management Through MSPOperate IndependentlySecurity Program MaturationCompliance Posture ManagementVendor Risk ManagementSecurity Tooling ManagementExternal Partner CollaborationEngineering CollaborationOperations CollaborationLeadership CollaborationIT Operations OversightSecurity Intake CoordinationBug Bounty OperationsVulnerability ManagementEndpoint ProtectionLoggingMonitoringAlertingLeast-Privilege PracticesPhysical Access ControlsDigital Access ControlsControl OwnershipEvidence CollectionAudit ReadinessAuditor CoordinationSecurity Policy MaintenanceProcedure MaintenanceControl DocumentationSecurity Risk TrackingPractical RemediationVendor Security ReviewsThird-Party Risk ManagementSLA TrackingMSP Relationship ManagementSecure Onboarding/OffboardingDevice ManagementHelpdesk OversightNetwork Support OversightOffice Infrastructure OversightUniFi NetworkingVLAN Segmentation

Qualifications

5+ Years Experience in Security Operations, GRC, IT Security, or SimilarExperience Owning or Materially Driving a Company Security ProgramExperience With Incident ResponseExperience With Endpoint SecurityExperience With Access ReviewsExperience With Logging/MonitoringExperience With Remediation TrackingExperience Managing Security Vendors, Consultants, Auditors, or Other External PartnersExperience Managing IT Operations Through an MSP or Similar External ProviderExperience at a Security, Identity, or Access Management CompanyExperience Running or Coordinating Bug Bounty / Vulnerability Disclosure ProgramsSecurity+ Certification

Full job description

About Opal Security:

The best security and engineering teams use Opal Security, the AI-native access platform, for real-time visibility, policy-as-code, and control over every identity, from employees to service accounts to AI agents. Companies like Databricks, Notion, CoreWeave, and Superhuman rely on Opal. Based in San Francisco, we've raised $59M from Greylock, Battery Ventures, and SVCI, and were named to Notable Capital's Rising in Cyber 2026 list by 150 leading CISOs. Our leadership brings deep security pedigree: CEO Howard Ting (previously CEO of Cyberhaven, CMO at Nutanix), CPO Sameer Mehta (Veza, Citrix), and CTO Alex Pien (Meta), among others who've built category-defining products.

The Role We're hiring a Security Manager to own Opal's internal security program. This person will be responsible for our security operations, compliance posture, vendor risk, incident response, and security tooling.

This is a hands-on, security-first role for someone who can operate independently, work well with external partners, and keep a fast-moving startup secure without slowing it down. You'll manage our security vendor and partner closely with engineering, operations, and leadership. You'll also oversee IT operations through our managed service provider (MSP), making sure onboarding/offboarding, devices, access, and office infrastructure meet our security and compliance needs.

This is not primarily an AppSec role. Product security and AppSec will remain closely partnered with Engineering, though this person will help coordinate security intake, bug bounty operations, vulnerability management, and remediation tracking.

We are building Opal together, in person. This role is 3+ days in office in downtown San Francisco.

What You'll Own

Security Operations

  • Own Opal's internal security program across people, systems, devices, vendors, and office environments

  • Manage security tooling for endpoint protection, SSO, MFA, access reviews, logging, monitoring, and alerting

  • Lead security incident response, including triage, investigation, remediation, communications, and follow-up

  • Run internal access reviews and improve least-privilege practices across company systems

  • Manage physical and digital access controls for the office and internal tools

Compliance & Risk

  • Drive SOC 2 compliance work, including control ownership, evidence collection, audit readiness, and auditor coordination

  • Maintain security policies, procedures, exceptions, control documentation, and audit evidence

  • Track security risks and drive practical remediation based on business impact

  • Help turn security and compliance requirements into repeatable operating processes

Vendor Security & Vulnerability Management

  • Own vendor security reviews as part of Opal's procurement process

  • Manage ongoing third-party risk, including review cycles, evidence collection, and remediation follow-up

  • Manage Opal's security vendor: set priorities, review deliverables, escalate issues, and hold them accountable

  • Own bug bounty / vulnerability disclosure program operations, including intake, triage coordination, SLA tracking, and reporting

  • Coordinate vulnerability remediation across security vendors, engineering, legal, and business stakeholders

IT Oversight via MSP

  • Manage Opal's IT MSP relationship and ensure IT execution supports security and compliance requirements

  • Coordinate secure onboarding/offboarding across accounts, hardware, access, and device posture

  • Hold the MSP accountable for device management, helpdesk, network support, and office infrastructure

  • Oversee office network and A/V decisions, including UniFi networking with VLAN segmentation

  • Evaluate whether MSP scope needs to change as Opal grows

What We're Looking For

  • 5+ years of experience in security operations, GRC, IT security, or a similar security-focused role

  • Experience owning or materially driving a company security program

  • Strong familiarity with SOC 2; FedRAMP, ISO 27001, or similar frameworks are a plus

  • Experience with incident response, endpoint security, access reviews, logging/monitoring, and remediation tracking

  • Strong understanding of identity and access concepts: SSO, MFA, least privilege, access reviews, and joiner/mover/leaver processes

  • Experience managing security vendors, consultants, auditors, or other external partners

  • Comfort managing IT operations through an MSP or similar external provider

  • Strong written and verbal communication skills

  • Ability to operate independently, prioritize risk, and drive cross-functional follow-through in a startup environment

Nice to Have

  • Experience at a security, identity, or access management company

  • Experience running or coordinating bug bounty / vulnerability disclosure programs

  • Security certifications such as Security+, CISSP, CISM, or similar

  • Experience building or maturing a security program from an early stage

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.