As the Security & Compliance Lead, you will own Opal Security’s internal security program, managing everything from security operations and SOC 2 compliance to vendor risk and incident response. You’ll partner with engineering and leadership to maintain a robust security posture, ensuring this fast-moving startup remains secure without compromising its engineering velocity.
Security & Compliance Lead at Opal Security
Working alongside an elite leadership team from Meta and Nutanix, you will drive SOC 2 compliance, manage security operations, and oversee vendor risk for an AI-native access platform trusted by giants like Databricks and Notion. This is a rare opportunity to build and scale a world-class security foundation at a high-growth startup that is actively defining the future of identity governance and automated access control.
Want to apply for this role?
Jack finds you jobs at companies like Opal Security. Talk to Jack to get considered for roles that fit what you're great at.
Location
San Francisco, United States
Compensation
$120k-$200k + Bonus
Company
Opal Security
Role overview
The best security and engineering teams use Opal to manage access for everyone and everything in the modern enterprise — from employees and contractors to service accounts and AI agents. Recognizing that access moves rapidly, touches everything, and changes constantly, our AI-proofed authorization control plane is built for how identity works (and what identity security needs) today and tomorrow: scale, speed, and intelligence. We are based in San Francisco, trusted by leading hypergrowth startups and the Fortune 500 alike, and backed by Greylock, Battery Ventures, Silicon Valley CISO Investments (SVCI), and other top experts from around the world.
What you will do
- Directly manage Opal Security’s internal security operations, including endpoint protection, SSO/MFA, and incident response, while overseeing IT infrastructure through a managed service provider.
- Lead the SOC 2 compliance lifecycle, from control ownership and evidence collection to audit readiness, while translating complex requirements into scalable and repeatable operating processes.
- Oversee third-party risk management and vulnerability disclosure programs, coordinating remediation efforts across engineering, legal, and business stakeholders to maintain a secure and trustworthy vendor ecosystem.
Who this is a fit for
- Brings 5+ years of experience in security operations, GRC, or IT security, with a proven track record of materially driving or owning a company’s internal security program.
- Demonstrates deep familiarity with SOC 2 frameworks and core identity concepts like least-privilege, access reviews, and JML processes within a fast-paced, high-growth startup environment.
- Possesses the ability to manage external partners, auditors, and MSPs effectively, coupled with strong written communication skills and a bias for independent, risk-based execution and follow-through.
Why this role is remarkable
- Join a high-growth category leader named to Notable Capital’s Rising in Cyber 2026 list, backed by $59M from top-tier investors like Greylock and Battery Ventures.
- Work alongside an elite leadership team with pedigrees from Nutanix, Meta, and Veza, building the future of identity governance for enterprise clients like Databricks and Notion.
- Own the internal security roadmap with significant autonomy, moving beyond just compliance to build a proactive, security-first culture at a company that is itself a major cybersecurity innovator.
How Jack & Jill work together
Jack gets to know what you're great at and what you want next, then searches 15 million jobs daily and helps you discover roles at companies like this.
Meet Jack
What happens next?
Jack’s an AI agent for job searching and career coaching. He works for you.
Jill is the AI recruiter working for the company. She recruits from Jack’s network.
If your profile’s a match and Opal Security wants to meet, Jill will make the intro. In the meantime, Jack will send you excellent alternatives.