Security Manager
About Opal SecurityThe best security and engineering teams use Opal Security, the AI-native access platform, for real-time visibility, policy-as-code, and control over every identity, from employees to service accounts to AI agents. Companies like Databricks, Notion, CoreWeave, and Superhuman rely on Opal. Based in San Francisco, we've raised $59M from Greylock, Battery Ventures, and SVCI, and were named to Notable Capital's Rising in Cyber 2026 list by 150 leading CISOs. Our leadership brings deep security pedigree: CEO Howard Ting (previously CEO of Cyberhaven, CMO at Nutanix), CPO Sameer Mehta (Veza, Citrix), and CTO Alex Pien (Meta), among others who've built category-defining products.The RoleWe're hiring a Security Manager to own Opal's internal security program. This person will be responsible for our security operations, compliance posture, vendor risk, incident response, and security tooling.This is a hands-on, security-first role for someone who can operate independently, work well with external partners, and keep a fast-moving startup secure without slowing it down. You'll manage our security vendor and partner closely with engineering, operations, and leadership. You'll also oversee IT operations through our managed service provider (MSP), making sure onboarding/offboarding, devices, access, and office infrastructure meet our security and compliance needs.This is not primarily an AppSec role. Product security and AppSec will remain closely partnered with Engineering, though this person will help coordinate security intake, bug bounty operations, vulnerability management, and remediation tracking.We are building Opal together, in person. This role is 3+ days in office in downtown San Francisco.What You'll OwnSecurity OperationsOwn Opal's internal security program across people, systems, devices, vendors, and office environmentsManage security tooling for endpoint protection, SSO, MFA, access reviews, logging, monitoring, and alertingLead security incident response, including triage, investigation, remediation, communications, and follow-upRun internal access reviews and improve least-privilege practices across company systemsManage physical and digital access controls for the office and internal toolsCompliance & RiskDrive SOC 2 compliance work, including control ownership, evidence collection, audit readiness, and auditor coordinationMaintain security policies, procedures, exceptions, control documentation, and audit evidenceTrack security risks and drive practical remediation based on business impactHelp turn security and compliance requirements into repeatable operating processesVendor Security & Vulnerability ManagementOwn vendor security reviews as part of Opal's procurement processManage ongoing third-party risk, including review cycles, evidence collection, and remediation follow-upManage Opal's security vendor: set priorities, review deliverables, escalate issues, and hold them accountableOwn bug bounty / vulnerability disclosure program operations, including intake, triage coordination, SLA tracking, and reportingCoordinate vulnerability remediation across security vendors, engineering, legal, and business stakeholdersIT Oversight via MSPManage Opal's IT MSP relationship and ensure IT execution supports security and compliance requirementsCoordinate secure onboarding/offboarding across accounts, hardware, access, and device postureHold the MSP accountable for device management, helpdesk, network support, and office infrastructureOversee office network and A/V decisions, including UniFi networking with VLAN segmentationEvaluate whether MSP scope needs to change as Opal growsWhat We're Looking For5+ years of experience in security operations, GRC, IT security, or a similar security-focused roleExperience owning or materially driving a company security programStrong familiarity with SOC 2; FedRAMP, ISO 27001, or similar frameworks are a plusExperience with incident response, endpoint security, access reviews, logging/monitoring, and remediation trackingStrong understanding of identity and access concepts: SSO, MFA, least privilege, access reviews, and joiner/mover/leaver processesExperience managing security vendors, consultants, auditors, or other external partnersComfort managing IT operations through an MSP or similar external providerStrong written and verbal communication skillsAbility to operate independently, prioritize risk, and drive cross-functional follow-through in a startup environmentNice to HaveExperience at a security, identity, or access management companyExperience running or coordinating bug bounty / vulnerability disclosure programsExperience supporting federal-readiness, public-sector customers, or FedRAMP preparationSecurity certifications such as Security+, CISSP, CISM, or similarExperience building or maturing a security program from an early stageCompensation Range: $120K - $200K