Skip to main content
frontier

Mend.io’s 7 Open Roles Demand Hands-On Open-Source Tool Experience

By John Hugo

The Seven Open Roles and Their Functional Focus

Mend.io is assembling teams across three business pillars (go-to-market, engineering, and general operations) as it scales what it calls the first AI-native application security platform. The hiring surge maps directly to product demands: securing open-source dependencies, custom code, and AI-generated components requires both technical depth and field coverage.

As of August 11, 2026, JobsRadar listed eight open positions at Mend.io, with seven added in the preceding 30 days and one posted in the prior 24 hours. The board refreshed at 05:07 UTC that day. First-party data from Zero G Talent’s live board confirms seven active listings, all added within the past seven days, with the most recent being the Financial Planning & Analysis Manager role based in Givatayim.

The engineering function carries the heaviest load. Two postings for Principal Software Engineer (Mend AI (AI Security)) reflect the company’s push into AI-generated code security, a domain it markets as central to its platform differentiation. One listing specifies Givatayim as the base location; the other restricts hiring to Poland, suggesting a distributed or offshore expansion of the AI security team. Both roles likely feed directly into Mend.io’s stated goal of extending risk visibility into AI-generated components, a capability the company advertises as unique.

Sales and business development account for four of the seven roles, concentrated in the United States and EMEA/APAC regions. The Account Executive, EMEA & APAC position and the Regional Sales Manager — AI Team role both sit in Givatayim, aligning with Mend.io’s Israeli headquarters. Two U.S.-based sales roles (Account Executive and Business Development Representative) are location-restricted, indicating a focus on domestic enterprise acquisition. The AI Team qualifier on the regional sales manager role signals that Mend.io is segmenting its GTM motion around AI-specific use cases, not just general AppSec.

The G&A bucket includes the Financial Planning & Analysis Manager, also based in Givatayim. This role supports the company’s scaling operations, likely tied to revenue growth from its enterprise platform model. Mend.io describes its platform as designed for global enterprises, combining intelligent automation with deep risk visibility — a positioning that demands both technical staffing and backend infrastructure.

Geographically, the distribution is tight: Givatayim appears in five roles, the United States in three, and Poland in one. No roles list remote-first or fully distributed arrangements, though the Givatayim-based positions are marked as hybrid. The location restrictions on U.S. roles suggest either compliance-driven hiring or a deliberate focus on specific regional markets.

The timing aligns with broader market movement. As enterprises grapple with software supply chain risk and AI-generated code proliferation, Mend.io’s hiring pattern reflects a targeted response — not a broad expansion. Each role maps to a functional gap in its AI-native AppSec narrative: engineering for product development, sales for market penetration, and operations for scale.

What Mend.io’s Screening Process Actually Evaluates

Glassdoor data as of August 2026 shows Mend.io’s hiring process averaging 22 days across 29 candidate interviews spanning all job titles. That timeline compresses into a sequence that mirrors the company’s product philosophy: speed without skipping fundamentals. Candidates report roughly four stages — an initial recruiter screen, a technical interview, a hiring-manager round, and a final loop that often includes a peer or cross-functional stakeholder. The interview volume (33 questions and 30 reviews posted anonymously) points to a process that leans heavily on scenario-based evaluation rather than abstract whiteboard puzzles.

The technical bar centers on Software Composition Analysis (SCA) and Static Application Security Testing (SAST). Builtin.com lists the Technical Support team as seeking engineers “eager to get immersed in the world of security and compliance associated with the use of open-source and closed-source software, specifically in the SCA and SAST fields.” That phrasing isn’t accidental. It signals that Mend.io screens for hands-on familiarity with vulnerability detection across dependency trees, not just theoretical knowledge of security frameworks. Candidates who reach later rounds can expect questions about real-world workflows: how to triage a critical CVE in a third-party library, how to configure policy gates in a CI/CD pipeline, or how to explain a false positive to a skeptical developer.

Cultural fit carries equal weight. A 2024 YouTube interview with an unnamed hiring manager reveals a process built around relationship-mapping. “The first thing I want to do is get to know all the people I’m going to be working with,” the manager said. “You want to be their friends because what you really are is you’re there to enable their success.” That framing recurs throughout the interview corpus. Screeners probe for evidence of cross-team collaboration — how a candidate has partnered with QA, how they’ve trained developers to recognize insecure patterns, how they’ve pushed fixes upstream rather than papering over them with tools. The manager’s three signature questions — “What keeps you up at night? What are the things you’re concerned about? What are the things that will make you successful?” — aren’t icebreakers. They’re diagnostics for a security culture that treats risk management as a shared responsibility.

Mend.io’s product messaging reinforces this emphasis. The company describes itself as the creator of “the first AI Native AppSec Platform,” built to secure “both AI-generated and user-generated code inside modern applications.” That positioning shapes its screening criteria. Candidates aren’t just evaluated on their ability to operate existing tools — they’re assessed on whether they can articulate how security shifts when code origins become ambiguous. One hiring-manager video asks candidates to walk through a pipeline where SAST flags a vulnerability in code that may have been AI-generated, then explain how they’d determine ownership and remediation priority. The question isn’t hypothetical. It reflects the product reality: Mend AppSec unifies SAST, SCA, and container scanning in a single workflow, and the company expects its hires to think in those integrated terms from day one.

The process also screens for incrementalism. An employee interview on YouTube captures the ethos: “It’s really easy to see like, oh, there’s a thousand things I can do and let’s start doing them all. But that’s a recipe for disaster. You really need to build incrementally.” Screeners listen for candidates who can describe a phased rollout (starting with visibility, then prioritization, then automated enforcement) rather than those who pitch a full-stack transformation on day one. The phrase “you can’t boil the ocean on day one” surfaces repeatedly in candidate debriefs as an informal litmus test.

What doesn’t appear in the screening process is generic cybersecurity credential-checking. Glassdoor reviews as of August 2026 contain no mentions of CISSP, CISM, or CEH as gating criteria. Instead, candidates describe being asked to walk through actual code scans, explain SBOM interpretation, or debug a failing policy gate. The emphasis is on applied knowledge — the kind that surfaces when someone has sat in a developer’s chair and felt the friction of a security tool that blocks a merge request without offering a clear path forward.

Mend.io’s live job board as of the latest update lists six active roles across engineering, sales, and security operations, plus one newly posted Financial Planning & Analysis Manager position. The geographic spread (Givatayim, United States, EMEA & APAC) suggests the screening bar is consistent across regions, even as the company scales its enterprise AppSec platform globally. Candidates who pass the screen tend to share a common thread: they speak the language of risk management rather than compliance checkboxes, and they can trace a vulnerability from detection to developer resolution without hand-waving.

Why Open-Source Security Expertise Is Non-Negotiable

Mend.io’s entire product strategy orbits around a single, undeniable fact: open-source components make up 90% of modern applications. That concentration of third-party code is where Mend SCA lives and breathes, which is why hands-on experience with open-source risk tools isn’t a nice-to-have on a resume—it’s the baseline filter for passing the screen.

Mend SCA doesn’t just point at vulnerabilities. It generates a precise inventory of every open-source library and dependency in a codebase, maps reachability across direct and transitive dependencies, scores severity with CVSS 4.0, and layers in EPSS exploitability data to separate real threats from noise. The tool also produces SBOMs in SPDX and CycloneDX formats, ingests third-party SBOMs, and feeds vulnerability intelligence into AI code assistants for rapid remediation. Candidates who have never worked with SCA tooling, SBOM generation, or dependency-tree analysis will hit a wall early in Mend’s technical screens because the product’s value proposition collapses without that depth.

The platform’s reach amplifies the requirement. Mend SCA supports more than 200 programming languages and frameworks across major ecosystems, which means security teams must be fluent in how open-source risk manifests differently in Python, JavaScript, Java, Go, and others. A candidate who knows npm audit but has never touched pip-audit, or who can run a Docker scan but hasn’t analyzed container layers for embedded open-source vulnerabilities, will struggle to credibly discuss the platform’s day-to-day operation. The same applies to license compliance workflows: Mend SCA issues real-time alerts with automatic remediation when license types violate company policy, and can block violations before they enter the codebase. Screeners probe for experience with those policy engines because false positives there erode developer trust faster than any other failure mode.

Supply chain security tightens the screw further. Mend SCA flags malicious packages—typosquats, dependency-confusion attacks, and packages containing data-exfiltration or backdoor code—which means candidates must understand how attackers weaponize package names and registry behavior. Those who have only consumed pre-built reports, rather than configured or tuned detection rules, rarely advance past the first technical round.

Geographically, the hiring pressure is real. Zero G Talent’s live board shows Mend adding roles in Givatayim and the United States within the past seven days, including Principal Software Engineer focused on AI Security and Head of DevOps and Security. Those positions sit at the intersection of open-source risk and emerging attack surfaces—AI frameworks, infrastructure-as-code, and container layers—all areas where generic cybersecurity credentials fall short.

The screening logic follows the product logic. If an applicant can’t speak to how reachability analysis changes remediation priorities, or why EPSS scoring matters more than raw CVE counts, they haven’t operated in the environment Mend is asking them to secure. That’s not gatekeeping for its own sake—it’s matching the tool’s complexity to the people who can wield it effectively.

The Shift from Reactive to Proactive AppSec in Hiring Criteria

Mend.io's hiring criteria have moved decisively away from the traditional AppSec model of scanning code and flagging vulnerabilities after the fact. The company's public messaging makes clear that it expects candidates to understand and implement security programs that operate continuously across the entire development lifecycle — not just at discrete checkpoints.

The shift is evident in how Mend.io describes its own platform. Rather than positioning itself as a tool that catches issues post-deployment, the company emphasizes real-time feedback at the moment of code generation in the IDE, followed by deep analysis at commit. This dual-scan flow means candidates must demonstrate familiarity with shifting security left — integrating checks into developer workflows rather than treating security as a separate phase.

Mend.io's emphasis on business context and exploitability signals in prioritization reflects a broader expectation that candidates can move beyond technical severity scores to assess actual business risk. The company's Contextual Project Classification feature identifies business-critical functions and sensitive data directly from code, suggesting that successful candidates need to understand how to translate technical findings into prioritized remediation based on real-world impact.

The platform's integration with AI coding agents illustrates another dimension of this proactive approach. When an agent generates code or proposes a dependency, Mend.io can check for vulnerabilities and return actionable guidance before changes are accepted. Candidates who can speak to implementing similar guardrails in agentic development environments — or who have experience designing security controls for non-deterministic AI components — align with this hiring focus.

Runtime protection represents another area where reactive approaches fall short. Static analysis and pre-deployment scans don't stop runtime exploitation, and AI agents introduce vulnerabilities that change with every prompt or model update. Mend.io's behavioral controls between users and applications in production suggest that candidates with experience in runtime application self-protection (RASP) or production monitoring will be better positioned to pass screening.

The company's customer outcomes reinforce this emphasis. Vonage reported an 80% reduction in vulnerability remediation time after adopting Mend.io, and open source audits that previously took a week now complete in 15 minutes. These improvements come not from faster scanning alone, but from embedding security into developer workflows so that remediation happens during development rather than after deployment.

Mend.io's screening process appears designed to identify candidates who can architect these kinds of programs — people who understand how to reduce noise through better prioritization, how to integrate security into CI/CD without creating bottlenecks, and how to govern risk across AI-generated code, open source dependencies, and production agents simultaneously. The company's job listings, including roles like Principal Software Engineer focused on AI Security and Head of DevOps and Security, signal that it is actively building teams around this proactive model.

One tension remains: while Mend.io's messaging emphasizes proactive, integrated security, its customer-facing materials still highlight traditional scanning capabilities like SAST and SCA. Candidates who can bridge both worlds — demonstrating deep technical knowledge of scanning tools while articulating how those tools fit into a broader, continuously operating security program — will likely clear screening most effectively.

Contrast with Industry Hiring Trends in Application Security

Mend.io's current hiring push lands against a market that is, by almost every measure, still scrambling to fill seats. The U.S. alone carries more than 470,000 unfilled cybersecurity positions, and globally the gap has swollen to 4.8 million open roles — a 19% increase from the prior year. Yet the broader AppSec labor market is not simply expanding uniformly; it is polarizing around two very different hiring philosophies. One rewards developer-aligned, shift-left generalists. The other (smaller in headcount but growing in influence) demands deep, specialized supply-chain and open-source risk expertise. Mend.io is betting squarely on the latter.

That bet looks deliberate when measured against the numbers. Of the 5,197 application security job postings analyzed across 796 companies between October 2025 and May 2026, 49.6% required senior-level experience or above, and only 1.9% were open to entry-level candidates. The field is aging up even as it grows. What is more telling is the language those postings use: 72% lean on shift-left framing, and 61.2% describe an "Enabler" philosophy — positioning security as something that empowers developers rather than gates them. Remediation, by contrast, barely appears; only 3.3% of enriched descriptions use narrow remediation terms like "fix rate" or "triage backlog."

Mend.io's job listings read differently. They do not dress up remediation as enablement. They do not obscure risk management behind developer-empowerment rhetoric. Instead, they foreground open-source risk, SBOM interpretation, and proactive AppSec program design — the operational details that the market's dominant hiring language tends to abstract away. Where most enterprise companies post roughly two AppSec roles per 1,000 engineers and mid-market firms post eight, Mend's seven simultaneous openings suggest a concentrated, product-led expansion rather than a broad platform rollout. IT & Services still dominates AppSec hiring at 42.9% of all postings, but software companies with embedded security products (the category Mend occupies) are pulling from a narrower, more technical talent pool.

The salary signal reinforces the distinction. AI-mentioning roles command a 10.9% premium ($155,936 average versus $140,648 for traditional AppSec positions), and 28.8% of those AI-tagged listings reference agentic security concepts. Mend's Principal Software Engineer - Mend AI (AI Security) listing sits precisely at that intersection: it is not just another AI-augmented security role, it is a role built around AI as a security surface. The company is not following the market's AI-for-salary-bump trend; it is defining what AI security hiring looks like from the inside out.

Budget constraints now rank as the top barrier to hiring, overtaking talent availability, and 55% of organizations report understaffed security teams. Against that backdrop, companies that reduce coordination load (through automation, process redesign, or both) change the staffing math. That is the logic behind open-source-centric challengers like Snyk and GitLab, which embed scanners inside commit workflows to win developer mindshare and lower switching costs. Mend's approach mirrors that strategy in hiring: rather than competing for the same generalist AppSec talent that every enterprise is chasing, it is cultivating specialists who can build and operate the tools that make the rest of the market's coordination problem disappear.

One tension worth noting: the market is moving toward fewer entry-level opportunities (only 1.9% of postings are open to newcomers) while Mend's openings skew heavily toward senior and principal levels, which aligns with the trend but narrows the funnel even further.

Candidate Signals That Pass the Screen: Real-World Examples

Mend.io's hiring surge centers on roles that demand hands-on experience with software composition analysis (SCA), software bill of materials (SBOM), and proactive vulnerability remediation — not theoretical security knowledge. The seven open positions span engineering, sales, and security operations, with recent additions including Principal Software Engineer - Mend AI (AI Security) and Head of DevOps and Security, both based in Givatayim, alongside Account Executive roles covering EMEA, APAC, and the United States. These roles reflect a company scaling its enterprise application security platform, and the candidate profiles that clear Mend's screening process tend to mirror that product focus directly.

Successful applicants typically demonstrate deep experience with open-source risk management tools, particularly SCA platforms that map dependencies to licenses and enforce allow/deny policies in development workflows. Mend's own documentation emphasizes that its SCA tool maps every dependency to its license, scores risk, and integrates policy enforcement directly into the dev workflow. Candidates who have worked with tools that produce similar outcomes (whether commercial or open-source) tend to surface in later interview stages. This includes experience with SBOM generation, dependency tracking across CI/CD pipelines, and license compliance automation, all of which align with Mend's stated product capabilities as of mid-2024.

Public customer success stories reinforce what the company values in practice. WTW reported an 80% reduction in vulnerability remediation time after adopting Mend, citing faster developer feedback loops as the primary driver. Vonage highlighted how Mend enabled alignment between competing security and development priorities. Candidates who can articulate similar impact — reducing mean time to remediation (MTTR), accelerating developer response to vulnerability alerts, or integrating security feedback into existing development workflows — tend to progress past initial screens. This isn't about knowing security theory; it's about having shipped security tooling that developers actually use.

Certifications alone don't pass the screen, but targeted credentials paired with relevant project work do. Candidates with hands-on experience in supply chain security frameworks, container security scanning, or SAST/DAST integration tend to stand out, especially when they can point to specific implementations. The recent emphasis on AI-generated components in Mend's hiring language suggests that experience with AI security tooling or ML model risk assessment is becoming a differentiator for engineering and AI-focused roles.

What consistently fails the screen is generic cybersecurity experience without application security depth. Candidates who list broad infosec certifications but cannot discuss dependency management, license risk scoring, or policy-as-code enforcement tend to be filtered out early. Likewise, experience limited to legacy vendor tools — particularly those focused on network or endpoint security rather than software supply chains — does not align with Mend's current hiring priorities. The company's shift toward an all-in-one pricing model covering SCA, SAST, container security, and AI security as of 2024 signals that candidates must demonstrate breadth across these domains, not just depth in one.

The strongest signals come from candidates who can connect their past work to Mend's core value proposition: fast feedback loops that reduce developer friction while improving security outcomes. Whether through open-source contributions to SCA-related projects, internal tool development around dependency management, or measurable improvements in remediation timelines, successful applicants tend to have shipped real security tooling that developers adopted willingly. That pattern (not a certification or a job title) is what clears the screen at Mend.io today.

What's NOT in the Screening Process: Debunking Myths

Mend.io's screening process filters for depth in open-source risk and proactive AppSec execution. That focus leaves little room for credentials that look good on paper but don't map to its product reality. The company's job board frames the mission explicitly: "redefining how modern organizations secure software from open source and custom code to AI-generated components" and calls itself "the creators of the first AI Native AppSec Platform." That positioning narrows what counts as relevant experience.

Generic cybersecurity certifications sit at the top of the pile candidates assume will open doors. ISC²'s April 2026 update to the CISSP experience waiver illustrates the broader shift in how the industry values credentials. The waiver list dropped from roughly 50 approved certifications to about 25, removing CEH, CISA, CRISC, and OSCP for applications submitted on or after April 1, 2026. Those credentials remain "excellent for pentesting careers," but they no longer trim a year off the CISSP requirement because they don't demonstrate knowledge "closely aligned to the CISSP domains." That logic mirrors Mend.io's own evaluation bias. The company's Glassdoor interview data shows a focus that "not on network security firewall intrusion detection," which aligns with the same principle: depth in software supply chain and open-source risk outweighs broad security theory.

CompTIA Security+, CySA+, and SecurityX survived the ISC² cut. ISACA's CISM also remained on the approved list, while CISA and CRISC did not. That distinction matters because it signals which certifications still carry weight in practical, hands-on security work. For early-career candidates, the surviving credentials double as both career-building tools and pathway shortcuts. But even those certifications won't pass Mend.io's screen on their own. The company's docs make the boundary explicit: candidate evaluation "excludes pure DevOps without security context." Someone who can deploy pipelines but cannot articulate risk in open-source dependencies or explain how to integrate security controls into CI/CD will not advance, regardless of how many acronyms they hold.

Legacy vendor experience follows the same pattern. Candidates steeped in traditional perimeter or infrastructure security tools often assume transferable skills apply. They don't. Mend.io's platform centers on software composition analysis, SBOM generation, and AI-native risk detection. Experience with legacy static analysis or network-focused appliances does not substitute for hands-on work with tools like Mend's own platform or comparable SCA solutions. The company's career page reinforces this: it seeks people who can "help global enterprises stay safe, fast, and compliant in an era of AI-driven development." That is a product-specific challenge, not a general security competency.

Non-security coding experience faces the same headwind. Developers who write clean code but have never engaged with dependency scanning, vulnerability triage, or proactive AppSec workflows will struggle to clear Mend.io's technical screens. The company's emphasis on "proactive security culture" means candidates must demonstrate that they've built or operated programs that prevent issues before they reach production, not just fixed them after discovery.

Certifications and credentials that do survive ISC²'s April 2026 update (Security+, CySA+, CISM, CCSP) remain useful but insufficient. A four-year degree still grants the same one-year CISSP waiver and was untouched by the change, but again, that credential alone doesn't signal the kind of open-source risk expertise Mend.io prioritizes.

The pattern is consistent: broad, theoretical, or legacy-aligned credentials get screened out early. What passes must show direct engagement with the problems Mend.io's customers actually face — supply chain attacks, AI-generated code risk, and the integration of security into developer workflows. That is the standard the company's current hiring surge reflects, and the boundary its screening process enforces.


Mend.io isn't just filling seats — it's stockpiling specialists who can operate inside the exact workflows its platform was built to automate. Every role maps to a seam in modern development where security either gets bolted on or built in. The company's bet is that the builders who can navigate those seams are the ones worth hiring, and the ones who can't will find the screen closing fast.


Working in frontier tech? Zero G Talent tracks the openings: see every open Mend role, browse frontier tech jobs, the companies hiring, and the people building the field.

Ready to Start Your Space Career?

Browse frontier jobs and find your next opportunity.

View frontier Jobs