Security Manager at Opal Security | San Francisco, California, United States | Rezi

Security Manager at Opal Security

Security Manager

Opal Security · San Francisco, California, United States

Today

Security Manager

Opal Security · San Francisco, California, United States

9 hours ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Opal Security is seeking a Security Manager to lead their internal security program, focusing on security operations, compliance, vendor risk, incident response, and security tooling. This hands-on role requires independent operation, collaboration with external partners, and securing a fast-moving startup without hindering its pace. The position involves managing the security vendor and closely partnering with engineering, operations, and leadership, while also overseeing IT operations through a managed service provider to ensure security and compliance needs are met.

Responsibilities

  • Own Opal's internal security program across people, systems, devices, vendors, and office environments
  • Manage security tooling for endpoint protection, SSO, MFA, access reviews, logging, monitoring, and alerting
  • Lead security incident response, including triage, investigation, remediation, communications, and follow-up
  • Run internal access reviews and improve least-privilege practices across company systems
  • Manage physical and digital access controls for the office and internal tools
  • Drive SOC 2 compliance work, including control ownership, evidence collection, audit readiness, and auditor coordination
  • Maintain security policies, procedures, exceptions, control documentation, and audit evidence
  • Track security risks and drive practical remediation based on business impact
  • Help turn security and compliance requirements into repeatable operating processes
  • Own vendor security reviews as part of Opal's procurement process
  • Manage ongoing third-party risk, including review cycles, evidence collection, and remediation follow-up
  • Manage Opal's security vendor: set priorities, review deliverables, escalate issues, and hold them accountable
  • Own bug bounty / vulnerability disclosure program operations, including intake, triage coordination, SLA tracking, and reporting
  • Coordinate vulnerability remediation across security vendors, engineering, legal, and business stakeholders
  • Manage Opal's IT MSP relationship and ensure IT execution supports security and compliance requirements
  • Coordinate secure onboarding/offboarding across accounts, hardware, access, and device posture
  • Hold the MSP accountable for device management, helpdesk, network support, and office infrastructure
  • Oversee office network and A/V decisions, including UniFi networking with VLAN segmentation
  • Evaluate whether MSP scope needs to change as Opal grows

Requirements

  • 5+ years of experience in security operations, GRC, IT security, or a similar security-focused role
  • Experience owning or materially driving a company security program
  • Strong familiarity with SOC 2
  • Experience with incident response, endpoint security, access reviews, logging/monitoring, and remediation tracking
  • Strong understanding of identity and access concepts: SSO, MFA, least privilege, access reviews, and joiner/mover/leaver processes
  • Experience managing security vendors, consultants, auditors, or other external partners
  • Comfort managing IT operations through an MSP or similar external provider
  • Strong written and verbal communication skills
  • Ability to operate independently, prioritize risk, and drive cross-functional follow-through in a startup environment

Skills

  • Security operations
  • GRC
  • IT security
  • SOC 2
  • Incident response
  • Endpoint security
  • Access reviews
  • Logging/monitoring
  • Remediation tracking
  • SSO
  • MFA
  • Least privilege
  • Joiner/mover/leaver processes
  • Vendor management
  • MSP management
  • Communication skills
  • Risk prioritization
  • Cross-functional collaboration
  • Bug bounty programs
  • Vulnerability disclosure programs
  • FedRAMP preparation
  • Security certifications (Security+, CISSP, CISM)
  • Security program maturation

Location

  • San Francisco

Work Type

  • In-office (3+ days)
  • Hybrid

Experience Level

  • 5+ years of experience

About the Company

  • Opal Security is an AI-native access platform used by security and engineering teams for real-time visibility, policy-as-code, and control over identities. Companies like Databricks, Notion, CoreWeave, and Superhuman rely on Opal. Based in San Francisco, the company has raised $59M from Greylock, Battery Ventures, and SVCI. Opal was named to Notable Capital's Rising in Cyber 2026 list. The leadership team has a strong security background, with the CEO previously being CEO of Cyberhaven and CMO at Nutanix, and the CPO having experience at Veza and Citrix.