{"schemaVersion":"jobsearcher.job.v1","id":"3f7014cd2d3f57a200766015","url":"https://jobsearcher.com/jobs/3f7014cd2d3f57a200766015","canonicalUrl":"https://jobsearcher.com/jobs/3f7014cd2d3f57a200766015","title":"Security Manager","description":"About Opal Security:\r\nThe best security and engineering teams use Opal Security, the AI-native access platform, for real-time visibility, policy-as-code, and control over every identity, from employees to service accounts to AI agents. Companies like Databricks, Notion, CoreWeave, and Superhuman rely on Opal. Based in San Francisco, we've raised $59M from Greylock, Battery Ventures, and SVCI, and were named to Notable Capital's Rising in Cyber 2026 list by 150 leading CISOs. Our leadership brings deep security pedigree: CEO Howard Ting (previously CEO of Cyberhaven, CMO at Nutanix), CPO Sameer Mehta (Veza, Citrix), and CTO Alex Pien (Meta), among others who've built category-defining products.\r\nThe Role We're hiring a Security Manager to own Opal's internal security program. This person will be responsible for our security operations, compliance posture, vendor risk, incident response, and security tooling.\r\nThis is a hands-on, security-first role for someone who can operate independently, work well with external partners, and keep a fast-moving startup secure without slowing it down. You'll manage our security vendor and partner closely with engineering, operations, and leadership. You'll also oversee IT operations through our managed service provider (MSP), making sure onboarding/offboarding, devices, access, and office infrastructure meet our security and compliance needs.\r\nThis is not primarily an AppSec role. Product security and AppSec will remain closely partnered with Engineering, though this person will help coordinate security intake, bug bounty operations, vulnerability management, and remediation tracking.\r\nWe are building Opal together, in person. This role is 3+ days in office in downtown San Francisco.\r\nWhat You'll Own Security Operations Own Opal's internal security program across people, systems, devices, vendors, and office environments\r\nManage security tooling for endpoint protection, SSO, MFA, access reviews, logging, monitoring, and alerting\r\nLead security incident response, including triage, investigation, remediation, communications, and follow-up\r\nRun internal access reviews and improve least-privilege practices across company systems\r\nManage physical and digital access controls for the office and internal tools\r\nCompliance & Risk Drive SOC 2 compliance work, including control ownership, evidence collection, audit readiness, and auditor coordination\r\nMaintain security policies, procedures, exceptions, control documentation, and audit evidence\r\nTrack security risks and drive practical remediation based on business impact\r\nHelp turn security and compliance requirements into repeatable operating processes\r\nVendor Security & Vulnerability Management Own vendor security reviews as part of Opal's procurement process\r\nManage ongoing third-party risk, including review cycles, evidence collection, and remediation follow-up\r\nManage Opal's security vendor: set priorities, review deliverables, escalated issues, and hold them accountable\r\nOwn bug bounty / vulnerability disclosure program operations, including intake, triage coordination, SLA tracking, and reporting\r\nCoordinate vulnerability remediation across security vendors, engineering, legal, and business stakeholders\r\nIT Oversight via MSP Manage Opal's IT MSP relationship and ensure IT execution supports security and compliance requirements\r\nCoordinate secure onboarding/offboarding across accounts, hardware, access, and device posture\r\nHold the MSP accountable for device management, helpdesk, network support, and office infrastructure\r\nOversee office network and A/V decisions, including UniFi networking with VLAN segmentation\r\nEvaluate whether MSP scope needs to change as Opal grows\r\nWhat We're Looking For 5+ years of experience in security operations, GRC, IT security, or a similar security-focused role\r\nExperience owning or materially driving a company security program\r\nStrong familiarity with SOC 2; FedRAMP, ISO 27001, or similar frameworks are a plus\r\nExperience with incident response, endpoint security, access reviews, logging/monitoring, and remediation tracking\r\nStrong understanding of identity and access concepts: SSO, MFA, least privilege, access reviews, and joiner/mover/leaver processes\r\nExperience managing security vendors, consultants, auditors, or other external partners\r\nComfort managing IT operations through an MSP or similar external provider\r\nStrong written and verbal communication skills\r\nAbility to operate independently, prioritize risk, and drive cross-functional follow-through in a startup environment\r\nNice to Have Experience at a security, identity, or access management company\r\nExperience running or coordinating bug bounty / vulnerability disclosure programs\r\nSecurity certifications such as Security+, CISSP, CISM, or similar\r\nExperience building or maturing a security program from an early stage\r\nJ-18808-Ljbffr","company":"Laptopbatteryus","rawCompany":"laptopbatteryus","city":"Millbrae","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-08-08T01:59:20.664Z","occupations":[{"code":"11-3013.01","title":"Security Managers","slug":"security-managers"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"33-1091.00","title":"First-Line Supervisors of Security Workers","slug":"first-line-supervisors-of-security-workers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Manager","description":"About Opal Security:\r\nThe best security and engineering teams use Opal Security, the AI-native access platform, for real-time visibility, policy-as-code, and control over every identity, from employees to service accounts to AI agents. Companies like Databricks, Notion, CoreWeave, and Superhuman rely on Opal. Based in San Francisco, we've raised $59M from Greylock, Battery Ventures, and SVCI, and were named to Notable Capital's Rising in Cyber 2026 list by 150 leading CISOs. Our leadership brings deep security pedigree: CEO Howard Ting (previously CEO of Cyberhaven, CMO at Nutanix), CPO Sameer Mehta (Veza, Citrix), and CTO Alex Pien (Meta), among others who've built category-defining products.\r\nThe Role We're hiring a Security Manager to own Opal's internal security program. This person will be responsible for our security operations, compliance posture, vendor risk, incident response, and security tooling.\r\nThis is a hands-on, security-first role for someone who can operate independently, work well with external partners, and keep a fast-moving startup secure without slowing it down. You'll manage our security vendor and partner closely with engineering, operations, and leadership. You'll also oversee IT operations through our managed service provider (MSP), making sure onboarding/offboarding, devices, access, and office infrastructure meet our security and compliance needs.\r\nThis is not primarily an AppSec role. Product security and AppSec will remain closely partnered with Engineering, though this person will help coordinate security intake, bug bounty operations, vulnerability management, and remediation tracking.\r\nWe are building Opal together, in person. This role is 3+ days in office in downtown San Francisco.\r\nWhat You'll Own Security Operations Own Opal's internal security program across people, systems, devices, vendors, and office environments\r\nManage security tooling for endpoint protection, SSO, MFA, access reviews, logging, monitoring, and alerting\r\nLead security incident response, including triage, investigation, remediation, communications, and follow-up\r\nRun internal access reviews and improve least-privilege practices across company systems\r\nManage physical and digital access controls for the office and internal tools\r\nCompliance & Risk Drive SOC 2 compliance work, including control ownership, evidence collection, audit readiness, and auditor coordination\r\nMaintain security policies, procedures, exceptions, control documentation, and audit evidence\r\nTrack security risks and drive practical remediation based on business impact\r\nHelp turn security and compliance requirements into repeatable operating processes\r\nVendor Security & Vulnerability Management Own vendor security reviews as part of Opal's procurement process\r\nManage ongoing third-party risk, including review cycles, evidence collection, and remediation follow-up\r\nManage Opal's security vendor: set priorities, review deliverables, escalated issues, and hold them accountable\r\nOwn bug bounty / vulnerability disclosure program operations, including intake, triage coordination, SLA tracking, and reporting\r\nCoordinate vulnerability remediation across security vendors, engineering, legal, and business stakeholders\r\nIT Oversight via MSP Manage Opal's IT MSP relationship and ensure IT execution supports security and compliance requirements\r\nCoordinate secure onboarding/offboarding across accounts, hardware, access, and device posture\r\nHold the MSP accountable for device management, helpdesk, network support, and office infrastructure\r\nOversee office network and A/V decisions, including UniFi networking with VLAN segmentation\r\nEvaluate whether MSP scope needs to change as Opal grows\r\nWhat We're Looking For 5+ years of experience in security operations, GRC, IT security, or a similar security-focused role\r\nExperience owning or materially driving a company security program\r\nStrong familiarity with SOC 2; FedRAMP, ISO 27001, or similar frameworks are a plus\r\nExperience with incident response, endpoint security, access reviews, logging/monitoring, and remediation tracking\r\nStrong understanding of identity and access concepts: SSO, MFA, least privilege, access reviews, and joiner/mover/leaver processes\r\nExperience managing security vendors, consultants, auditors, or other external partners\r\nComfort managing IT operations through an MSP or similar external provider\r\nStrong written and verbal communication skills\r\nAbility to operate independently, prioritize risk, and drive cross-functional follow-through in a startup environment\r\nNice to Have Experience at a security, identity, or access management company\r\nExperience running or coordinating bug bounty / vulnerability disclosure programs\r\nSecurity certifications such as Security+, CISSP, CISM, or similar\r\nExperience building or maturing a security program from an early stage\r\nJ-18808-Ljbffr","datePosted":"2026-08-08T01:59:20.664Z","dateModified":"2026-08-08T01:59:20.664Z","hiringOrganization":{"@type":"Organization","name":"Laptopbatteryus","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Millbrae","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"3f7014cd2d3f57a200766015"},"url":"https://jobsearcher.com/jobs/3f7014cd2d3f57a200766015"}}