Opal

Security Manager

Opal$120K — $145K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in security operations, GRC, IT security, or similar roles
  • Proven experience leading a company security program
  • Familiarity with SOC 2 and other frameworks like FedRAMP or ISO 27001
  • Incident response and endpoint security expertise
  • Understanding of identity and access management concepts like SSO and MFA
  • Experience managing external security vendors and partners
  • Ability to oversee IT operations through a managed service provider (MSP)
  • Effective written and verbal communication skills
  • Comfort working independently in a startup environment.

Responsibilities

  • Own the internal security program for people, systems, and vendors
  • Manage security tooling, including endpoint protection and access reviews
  • Lead incident response efforts including investigation and remediation
  • Run access reviews to enforce least-privilege practices
  • Drive SOC 2 compliance efforts, including audit coordination
  • Manage vendor security reviews within procurement processes
  • Oversee IT execution via the MSP to meet security and compliance needs
  • Coordinate secure onboarding/offboarding processes
  • Evaluate and adjust MSP scope as the company grows.

Benefits

  • Flexible work environment with 3+ days in-office
  • Opportunity to build a security program from the ground up
  • Close collaboration with engineering and leadership
  • Exposure to diverse security challenges in a fast-paced startup
  • Direct influence over security policies and vendor relationships.
Full Job Description
The Role

We're hiring a Security Manager to own Opal's internal security program. This person will be responsible for our security operations, compliance posture, vendor risk, incident response, and security tooling.

This is a hands-on, security-first role for someone who can operate independently, work well with external partners, and keep a fast-moving startup secure without slowing it down. You'll manage our security vendor and partner closely with engineering, operations, and leadership. You'll also oversee IT operations through our managed service provider (MSP), making sure onboarding/offboarding, devices, access, and office infrastructure meet our security and compliance needs.

This is not primarily an AppSec role. Product security and AppSec will remain closely partnered with Engineering, though this person will help coordinate security intake, bug bounty operations, vulnerability management, and remediation tracking.

We are building Opal together, in person. This role is 3+ days in office in downtown San Francisco.

What You'll Own

Security Operations
  • Own Opal's internal security program across people, systems, devices, vendors, and office environments
  • Manage security tooling for endpoint protection, SSO, MFA, access reviews, logging, monitoring, and alerting
  • Lead security incident response, including triage, investigation, remediation, communications, and follow-up
  • Run internal access reviews and improve least-privilege practices across company systems
  • Manage physical and digital access controls for the office and internal tools
Compliance & Risk
  • Drive SOC 2 compliance work, including control ownership, evidence collection, audit readiness, and auditor coordination
  • Maintain security policies, procedures, exceptions, control documentation, and audit evidence
  • Track security risks and drive practical remediation based on business impact
  • Help turn security and compliance requirements into repeatable operating processes
Vendor Security & Vulnerability Management
  • Own vendor security reviews as part of Opal's procurement process
  • Manage ongoing third-party risk, including review cycles, evidence collection, and remediation follow-up
  • Manage Opal's security vendor: set priorities, review deliverables, escalate issues, and hold them accountable
  • Own bug bounty / vulnerability disclosure program operations, including intake, triage coordination, SLA tracking, and reporting
  • Coordinate vulnerability remediation across security vendors, engineering, legal, and business stakeholders
IT Oversight via MSP
  • Manage Opal's IT MSP relationship and ensure IT execution supports security and compliance requirements
  • Coordinate secure onboarding/offboarding across accounts, hardware, access, and device posture
  • Hold the MSP accountable for device management, helpdesk, network support, and office infrastructure
  • Oversee office network and A/V decisions, including UniFi networking with VLAN segmentation
  • Evaluate whether MSP scope needs to change as Opal grows
What We're Looking For
  • 5+ years of experience in security operations, GRC, IT security, or a similar security-focused role
  • Experience owning or materially driving a company security program
  • Strong familiarity with SOC 2; FedRAMP, ISO 27001, or similar frameworks are a plus
  • Experience with incident response, endpoint security, access reviews, logging/monitoring, and remediation tracking
  • Strong understanding of identity and access concepts: SSO, MFA, least privilege, access reviews, and joiner/mover/leaver processes
  • Experience managing security vendors, consultants, auditors, or other external partners
  • Comfort managing IT operations through an MSP or similar external provider
  • Strong written and verbal communication skills
  • Ability to operate independently, prioritize risk, and drive cross-functional follow-through in a startup environment
Nice to Have
  • Experience at a security, identity, or access management company
  • Experience running or coordinating bug bounty / vulnerability disclosure programs
  • Experience supporting federal-readiness, public-sector customers, or FedRAMP preparation
  • Security certifications such as Security+, CISSP, CISM, or similar
  • Experience building or maturing a security program from an early stage

About Opal

Opal is a software company that provides a cloud-based collaboration platform for marketing teams. The platform allows teams to manage their marketing campaigns, content, and assets in one place, and provides tools for collaboration, workflow management, and analytics. Opal was founded in 2010 and is headquartered in Seattle, Washington. The company serves customers in a variety of industries, including healthcare, technology, and consumer goods.
Learn more about Opal
Size
200 employees
Industry
Founded
2011

Similar Jobs

More Jobs at Opal

More Information Technology Jobs

Find similar Security Manager jobs: