Jobs · Information Technology · California

Security Manager

Opal Security · San Francisco, CA · 4 wk ago
On-siteInformation Technology$120k–$200k/yrFull-time

About the role

The Security Manager will own Opal Security's internal security program, covering security operations, compliance, vendor risk, incident response, and security tooling. This role requires hands-on experience and the ability to operate independently while keeping a fast-moving startup secure.

Responsibilities

  • Own Opal's internal security program across people, systems, devices, vendors, and office environments
  • Manage security tooling for endpoint protection, SSO, MFA, access reviews, logging, monitoring, and alerting
  • Lead security incident response, including triage, investigation, remediation, communications, and follow-up
  • Manage internal access reviews and improve least-privilege practices across company systems
  • Oversee physical and digital access controls for the office and internal tools
  • Drive SOC 2 compliance work, including control ownership, evidence collection, audit readiness, and auditor coordination
  • Maintain security policies, procedures, exceptions, control documentation, and audit evidence
  • Track security risks and drive practical remediation based on business impact
  • Turn security and compliance requirements into repeatable operating processes
  • Own vendor security reviews as part of Opal's procurement process
  • Manage ongoing third-party risk, including review cycles, evidence collection, and remediation follow-up
  • Own bug bounty / vulnerability disclosure program operations, including intake, triage coordination, SLA tracking, and reporting
  • Coordinate vulnerability remediation across security vendors, engineering, legal, and business stakeholders
  • Manage Opal's IT MSP relationship and ensure IT execution supports security and compliance requirements
  • Coordinate secure onboarding/offboarding across accounts, hardware, access, and device posture
  • Hold the MSP accountable for device management, helpdesk, network support, and office infrastructure
  • Evaluate whether MSP scope needs to change as Opal grows

Requirements

  • 5+ years of experience in security operations, GRC, IT security, or a similar security-focused role
  • Strong familiarity with SOC 2; FedRAMP, ISO 27001, or similar frameworks are a plus
  • Experience with incident response, endpoint security, access reviews, logging/monitoring, and remediation tracking
  • A strong understanding of identity and access concepts: SSO, MFA, least privilege, access reviews, and joiner/mover/leaver processes
  • Experience managing security vendors, consultants, auditors, or other external partners
  • Comfort managing IT operations through an MSP or similar external provider
  • Strong written and verbal communication skills
  • Ability to operate independently, prioritize risk, and drive cross-functional follow-through in a startup environment

Similar jobs

Security Manager

FirstService ResidentialBal Harbour, FL· Today
Information Technology$23/hrapply on careers.fsresidential.com

Security Manager

FirstService ResidentialNorth Miami Beach, FL· Today
Management$23/hrapply on careers.fsresidential.com

Security Manager

Saint Francis HospitalEvanston, IL· 2 days ago
Management$77k–$111k/yrapply on careers-primehealthcare.icims.com

Security Manager

Cleveland Museum of ArtCleveland, OH· 2 days ago
Information Technology$60k/yrapply on recruiting.ultipro.com

Security Manager

Marksman SecurityDallas, TX· 3 days ago
Information Technology$80k/yrapply on grnh.se

Security Manager

Palmetto Citizens Federal Credit UnionColumbia, SC· Yesterday
Information Technologyapply on careers-palmettocitizens.icims.com