
Security Operations Lead
What you need
- Strong experience in Security/Cloud/Product Security
- Hands-on with SIEM, WAF, CSPM, IAM, vulnerability management
- Experience collaborating with Engineering and Product teams
- Familiarity with SOC 2, ISO 27001 compliance frameworks
- Practical hands-on approach balancing security and business
What you'll do
- Assess security risks across product and cloud infrastructure
- Own cloud security operations: SIEM, WAF, CSPM, secrets management
- Lead vulnerability management and HackerOne bug bounty program
- Lead incident response and disaster recovery planning
- Drive SOC 2/ISO compliance audits and maintain Drata evidence
Why Mend.io
We are redefining how modern organizations secure software from open source and custom code to AI-generated components. As the creators of the first AI Native AppSec Platform, we help global enterprises stay safe, fast, and compliant in an era of AI-driven development. Our platform combines intelligent automation, deep risk visibility, and developer-first experiences, shaping the future of application security.
We are also committed to building a collaborative, empowering workplace. If you are excited about this role but do not meet every requirement, we encourage you to apply. Your perspective could be exactly what we need!
Mend is looking for a hands-on Security Operations Lead to drive security operations across our cloud infrastructure, product, compliance, and customer-facing activities.
You will work closely with Engineering, Product, IT, Sales, Legal, and company leadership to identify risks, improve controls, respond to security issues, and strengthen Mend’s overall security posture.
Responsibilities
Assess security risks across Mend’s product and cloud infrastructure and drive a prioritized improvement plan.
Own day-to-day cloud and infrastructure security operations, including SIEM/SOC monitoring, WAF, CSPM, access reviews, encryption, and secrets management.
Lead vulnerability management, including Mend’s HackerOne bug bounty program and remediation coordination with Engineering.
Lead security incident response and support disaster recovery planning and testing.
Support customer-facing security activities, including questionnaires, RFPs, and technical security discussions during sales cycles.
Drive audit and certification activities, including SOC 2 and ISO 27001/27701/27017, and maintain compliance controls and evidence through Drata.
Manage third-party security assessments and support security and AI governance.
Serve as a key internal security advisor for teams across the company.
Own and improve security tooling, automation, and operational processes.
What We’re Looking For
Strong experience in Security Operations, Cloud Security, Product Security, or a similar role.
Hands-on experience with cloud security technologies, vulnerability management, incident response, SIEM, WAF, CSPM, and IAM.
Experience working closely with Engineering and Product teams.
Familiarity with SOC 2, ISO 27001, and security compliance frameworks.
Strong analytical, communication, and cross-functional collaboration skills.
A practical, hands-on approach with the ability to balance security risk and business needs.
Our Culture
At Mend.io, we are leading the way in securing AI-powered applications, and we believe the best innovations come from teams where everyone feels valued. We are committed to a workplace built on respect, trust, and growth, where learning and flexibility empower people to do their best work.
Optimize your resume for this job
Get a match score and the keywords you're missing
About Mend
𝐒𝐭𝐚𝐫𝐭 𝐦𝐚𝐧𝐚𝐠𝐢𝐧𝐠 𝐚𝐩𝐩𝐥𝐢𝐜𝐚𝐭𝐢𝐨𝐧 𝐫𝐢𝐬𝐤 🚀 Mend.io gives you all the tools you need to build a mature, proactive AppSec program that effectively manages application risk.
Similar Security roles


