--- title: 'Security & Compliance Lead at Opal Security' canonical: 'https://feeny.ai/job/security-compliance-lead-opal-security-san-francisco-b414fmaeemcp' type: 'job' last_seen: '2026-09-06' --- # Security & Compliance Lead at Opal Security - **Company:** Opal Security - **Location:** San Francisco, CA - **Employment:** full-time - **Work type:** onsite - **Posted:** 2026-07-29 - **Last confirmed live:** 2026-09-06 - **Apply:** https://jobs.ashbyhq.com/opal/fb259171-4c9a-480e-b574-e9480bbe69cf ## Job description About Opal Security: The best security and engineering teams use Opal Security, the AI-native access platform, for real-time visibility, policy-as-code, and control over every identity, from employees to service accounts to AI agents. Companies like Databricks, Notion, CoreWeave, and Superhuman rely on Opal. Based in San Francisco, we've raised $59M from Greylock, Battery Ventures, and SVCI, and were named to Notable Capital's Rising in Cyber 2026 list by 150 leading CISOs. Our leadership brings deep security pedigree: CEO Howard Ting (previously CEO of Cyberhaven, CMO at Nutanix), CPO Sameer Mehta (Veza, Citrix), and CTO Alex Pien (Meta), among others who've built category-defining products. ## THE ROLE We're hiring a Security Manager to own Opal's internal security program. This person will be responsible for our security operations, compliance posture, vendor risk, incident response, and security tooling. This is a hands-on, security-first role for someone who can operate independently, work well with external partners, and keep a fast-moving startup secure without slowing it down. You'll manage our security vendor and partner closely with engineering, operations, and leadership. You'll also oversee IT operations through our managed service provider (MSP), making sure onboarding/offboarding, devices, access, and office infrastructure meet our security and compliance needs. This is not primarily an AppSec role. Product security and AppSec will remain closely partnered with Engineering, though this person will help coordinate security intake, bug bounty operations, vulnerability management, and remediation tracking. We are building Opal together, in person. This role is 3+ days in office in downtown San Francisco. ## WHAT YOU'LL OWN ## SECURITY OPERATIONS - Own Opal's internal security program across people, systems, devices, vendors, and office environments - Manage security tooling for endpoint protection, SSO, MFA, access reviews, logging, monitoring, and alerting - Lead security incident response, including triage, investigation, remediation, communications, and follow-up - Run internal access reviews and improve least-privilege practices across company systems - Manage physical and digital access controls for the office and internal tools ## COMPLIANCE & RISK - Drive SOC 2 compliance work, including control ownership, evidence collection, audit readiness, and auditor coordination - Maintain security policies, procedures, exceptions, control documentation, and audit evidence - Track security risks and drive practical remediation based on business impact - Help turn security and compliance requirements into repeatable operating processes ## VENDOR SECURITY & VULNERABILITY MANAGEMENT - Own vendor security reviews as part of Opal's procurement process - Manage ongoing third-party risk, including review cycles, evidence collection, and remediation follow-up - Manage Opal's security vendor: set priorities, review deliverables, escalate issues, and hold them accountable - Own bug bounty / vulnerability disclosure program operations, including intake, triage coordination, SLA tracking, and reporting - Coordinate vulnerability remediation across security vendors, engineering, legal, and business stakeholders ## IT OVERSIGHT VIA MSP - Manage Opal's IT MSP relationship and ensure IT execution supports security and compliance requirements - Coordinate secure onboarding/offboarding across accounts, hardware, access, and device posture - Hold the MSP accountable for device management, helpdesk, network support, and office infrastructure - Oversee office network and A/V decisions, including UniFi networking with VLAN segmentation - Evaluate whether MSP scope needs to change as Opal grows ## WHAT WE'RE LOOKING FOR - 5+ years of experience in security operations, GRC, IT security, or a similar security-focused role - Experience owning or materially driving a company security program - Strong familiarity with SOC 2; FedRAMP, ISO 27001, or similar frameworks are a plus - Experience with incident response, endpoint security, access reviews, logging/monitoring, and remediation tracking - Strong understanding of identity and access concepts: SSO, MFA, least privilege, access reviews, and joiner/mover/leaver processes - Experience managing security vendors, consultants, auditors, or other external partners - Comfort managing IT operations through an MSP or similar external provider - Strong written and verbal communication skills - Ability to operate independently, prioritize risk, and drive cross-functional follow-through in a startup environment ## NICE TO HAVE - Experience at a security, identity, or access management company - Experience running or coordinating bug bounty / vulnerability disclosure programs - Security certifications such as Security+, CISSP, CISM, or similar - Experience building or maturing a security program from an early stage ## About Opal Security ## Core Business - **Primary industry**: Cybersecurity – Identity Security / Access Governance - **Target customers**: B2B Enterprise (e.g., Databricks, Notion, Cloudflare, Scale AI, CoreWeave, SpaceXAI, Superhuman) - **Mission or purpose**: “To secure every identity and access path” [opal.dev/about](https://www.opal.dev/about) ## Products & Services - **Paladin**: AI agent that evaluates every access request, approves safe requests automatically, escalates only what needs a human, and revokes access when no longer needed. - **OpalScript**: Version-controlled, code-based approval workflows that scale across teams and environments; AI can generate the logic from natural language. - **OpalQuery**: Query the entire stack in plain English to surface risk, over-provisioned access, separation-of-duties conflicts, and hidden privilege escalation paths. - **Just-In-Time Access**: Grant privileged access only when needed, auto-revoke when work is done. - **AI-Guided Access Reviews**: Explainable recommendations that surface the riskiest access, replacing rubber-stamp reviews. - **Access Intelligence**: Ask who has access to what, and why, in plain English. - **Security for AI Agents**: Define what AI agents can see, access, and execute before they touch your systems. - **Programmable Governance**: Build access logic into workflows and approvals as version-controlled, testable code. - **Platform integrations**: Connects to 250+ systems across cloud, identity, SaaS, databases, and AI platforms (e.g., Okta, AWS, GCP, Snowflake, GitHub, OpenAI, Anthropic, Databricks, ServiceNow, Salesforce). ## Market Standing - **Valuation/Market Cap**: Not disclosed - **Key Metric**: Total funding of $59M (latest $23M round announced June 2026); annual revenue not publicly available - **Notable Investors/Partners**: Greylock Partners, Battery Ventures, Box Group, SVCI, Cambium Capital. Advisors include former CTO of JPMorgan Chase, former CSO of Robinhood, CISO of Datadog, CEO of Abnormal Security, CTO of 1Password, CSO of Coinbase, and founder of LDAP. - **Growth Signals**: - Named to Notable Capital’s “Rising in Cyber 2026” list (30 most promising private cybersecurity startups). - More than 60% of the team has joined since the start of 2026, with hiring accelerating across engineering, product, and go-to-market. - Major customers: Databricks runs 86,000 just-in-time access requests through Opal; Mercari governs over 5,000 Okta entitlements via automated reviews. - Launched the industry’s first platform to see, encode, and enforce access governance for AI agents (Paladin) in March 2026. ## Competitive Advantages - **AI-native architecture** that understands CISO context with security engineer precision. - **Policy-as-code** (OpalScript) enables version-controlled, testable, and scalable access logic. - **Unified governance** across humans, non-human identities (service accounts, CI/CD pipelines), and AI agents—all in one access graph. - **Just-in-time by default** reduces standing access and attack surface. - **Self-hosted or on-prem deployment** option for tightly controlled environments. - **SOC 2 Type 2 certified**, independent penetration testing annually, TLS 1.2+ in transit, AWS KMS at rest, daily encrypted backups. - **250+ integrations** with major cloud, identity, SaaS, database, and AI platforms. ## Strategic Focus - Unify identity governance across all identity types, with a strong emphasis on securing AI agents as they proliferate in enterprise environments. - Scale the engineering and go-to-market teams (60%+ team growth in 2026). - Expand leadership: new Chief Product Officer (Sameer Mehta, ex-Veza), Chief Technology Officer (Alex Pien, ex-Meta), VP of Field Engineering (ex-Cisco), VP of Marketing (ex-Clumio), Head of Product & Solutions Marketing (ex-Salesforce). - Continue to build a self-improving system that ensures resilience and enables faster movement without increasing risk. ## Why Work Here - **Hybrid work model**: Offices in San Francisco (HQ) and New York; employees engage in a combination of remote and on-site work. - **Fast-growing startup** backed by top-tier VCs (Greylock, Battery Ventures) with significant momentum and market recognition. - **Mission-driven security work**: Opportunity to solve hard problems in identity security, especially at the intersection of AI and access control. - **Cutting-edge technology**: Work on AI-native policy engines, large-scale access graphs, and integrations with hundreds of platforms. - **Strong engineering culture** with leadership from experienced executives (ex-Meta, ex-Veza, ex-Cisco, ex-Palo Alto Networks). - **Open roles** (as of mid-2026): Software Engineer, Engineering Manager, Product Manager, Forward Deployed Engineer, Solutions Engineer, Enterprise Account Executive, Technical Customer Success Manager, Application Security Engineer, and more. ## Sources 1. [opal.dev](https://www.opal.dev/) 2. [opal.dev/about](https://www.opal.dev/about) 3. [builtin.com/company/opal-security](https://builtin.com/company/opal-security) 4. [linkedin.com/company/opalsecurity](https://www.linkedin.com/company/opalsecurity) 5. [opal.dev/media-press/opal-security-raises-23m-new-leadership](https://www.opal.dev/media-press/opal-security-raises-23m-new-leadership) ## Other roles at Opal Security - [GTM Engineer](https://feeny.ai/job/gtm-engineer-opal-security-san-francisco-39ywrh6eh725) — San Francisco, CA - [Business Development Representative](https://feeny.ai/job/business-development-representative-opal-security-san-francisco-9ps3v5c9j6c2) — San Francisco, CA - [Senior Field Marketing Manager](https://feeny.ai/job/senior-field-marketing-manager-opal-security-san-francisco-v228sq12atz3) — San Francisco, CA - [Enterprise Account Executive - Southeast](https://feeny.ai/job/enterprise-account-executive-southeast-opal-security-atlanta-fhzns023gzw1) — Atlanta, GA - [Enterprise Account Executive - Southern California](https://feeny.ai/job/enterprise-account-executive-southern-california-opal-security-los-angeles-8rke94henpjv) — Los Angeles, CA - [Enterprise Account Executive - Mid West](https://feeny.ai/job/enterprise-account-executive-mid-west-opal-security-austin-vycxprpkp42d) — Austin, TX - [Product Marketing & Content Associate](https://feeny.ai/job/product-marketing-content-associate-opal-security-san-francisco-4vbht8k73qg1) — San Francisco, CA - [Application Security Engineer](https://feeny.ai/job/application-security-engineer-opal-security-san-francisco-rcy76s1xh1ff) — San Francisco, CA - [Senior Manager Demand Generation](https://feeny.ai/job/senior-manager-demand-generation-opal-security-san-francisco-3a47zepv1b9c) — San Francisco, CA - [Software Engineer, Infrastructure](https://feeny.ai/job/software-engineer-infrastructure-opal-security-san-francisco-6mtmwh30b8t6) — San Francisco, CA