Назад
Company hidden
1 час назад

Security Manager

120 000 - 200 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Manager (Cybersecurity): Owning Opal Security's internal security program across security operations, compliance, vendor risk, incident response, and IT security with an accent on SOC 2 readiness, identity and access controls, and third-party risk. Focus on leading incident investigations, coordinating vulnerability remediation, managing MSP and security vendors, and building repeatable security processes in a fast-moving startup.

Location: San Francisco, United States; 3+ days per week in the downtown office

Salary: $120,000–$200,000 per year plus bonus

Company

hirify.global develops an AI-native access platform for real-time visibility, policy-as-code, and identity control across employees, service accounts, and AI agents.

What you will do

  • Own the internal security program across people, systems, devices, vendors, and office environments.
  • Manage endpoint protection, SSO, MFA, access reviews, logging, monitoring, alerting, and least-privilege practices.
  • Lead security incident response, including triage, investigation, remediation, communications, and follow-up.
  • Drive SOC 2 compliance, control ownership, evidence collection, audit readiness, and auditor coordination.
  • Manage vendor security reviews, third-party risk, the security vendor relationship, and vulnerability remediation coordination.
  • Oversee IT operations through the MSP, including secure onboarding and offboarding, device management, office networking, and infrastructure.

Requirements

  • 5+ years of experience in security operations, GRC, IT security, or a similar security-focused role.
  • Experience owning or materially driving a company security program.
  • Strong familiarity with SOC 2 and experience with incident response, endpoint security, access reviews, logging, monitoring, and remediation tracking.
  • Strong understanding of SSO, MFA, least privilege, access reviews, and joiner/mover/leaver processes.
  • Experience managing security vendors, consultants, auditors, or other external partners, including IT operations through an MSP.
  • Ability to operate independently, prioritize risk, communicate clearly, and drive cross-functional follow-through in a startup environment.

Nice to have

  • Experience with FedRAMP, ISO 27001, or similar security frameworks.
  • Experience at a security, identity, or access management company.
  • Experience running or coordinating bug bounty or vulnerability disclosure programs.
  • Security certifications such as Security+, CISSP, or CISM.
  • Experience building or maturing an early-stage security program.

Culture & Benefits

  • Hands-on, security-first work in a fast-moving startup environment.
  • In-person collaboration with engineering, operations, leadership, and external partners.
  • Responsibility for practical security improvements without slowing business operations.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →