Security Operations Lead
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
We are redefining how modern organizations secure software from open source and custom code to AI-generated components. As the creators of the first AI Native AppSec Platform, we help global enterprises stay safe, fast, and compliant in an era of AI-driven development. Our platform combines intelligent automation, deep risk visibility, and developer-first experiences, shaping the future of application security.
We are also committed to building a collaborative, empowering workplace. If you are excited about this role but do not meet every requirement, we encourage you to apply. Your perspective could be exactly what we need!
Mend is looking for a hands-on Security Operations Lead to drive security operations across our cloud infrastructure, product, compliance, and customer-facing activities.
You will work closely with Engineering, Product, IT, Sales, Legal, and company leadership to identify risks, improve controls, respond to security issues, and strengthen Mend’s overall security posture.
Responsibilities
Assess security risks across Mend’s product and cloud infrastructure and drive a prioritized improvement plan.
Own day-to-day cloud and infrastructure security operations, including SIEM/SOC monitoring, WAF, CSPM, access reviews, encryption, and secrets management.
Lead vulnerability management, including Mend’s HackerOne bug bounty program and remediation coordination with Engineering.
Lead security incident response and support disaster recovery planning and testing.
Support customer-facing security activities, including questionnaires, RFPs, and technical security discussions during sales cycles.
Drive audit and certification activities, including SOC 2 and ISO 27001/27701/27017, and maintain compliance controls and evidence through Drata.
Manage third-party security assessments and support security and AI governance.
Serve as a key internal security advisor for teams across the company.
Own and improve security tooling, automation, and operational processes.
What We’re Looking For
Strong experience in Security Operations, Cloud Security, Product Security, or a similar role.
Hands-on experience with cloud security technologies, vulnerability management, incident response, SIEM, WAF, CSPM, and IAM.
Experience working closely with Engineering and Product teams.
Familiarity with SOC 2, ISO 27001, and security compliance frameworks.
Strong analytical, communication, and cross-functional collaboration skills.
A practical, hands-on approach with the ability to balance security risk and business needs.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Mend.io
Explore Top Companies in this Space
SteerBridge
Government Contracting / Enterprise Software / Cybersecurity / Cloud Services
Northramp
IT Services / Government Technology / Enterprise Software / Cybersecurity
Very Good Security
Financial Services / Enterprise Software / Cybersecurity / Payment Processing
Innovatrics
AI / Cybersecurity / Enterprise Software / Identity Management
Mend.io
View Company ProfileMend.io is a premier, enterprise-grade application security platform engineered to orchestrate massive-scale software supply chain ecosystems and intelligent frictionless vulnerability workflows. Operating as a highly integrated AppSec hub, the company eliminates the operational friction of traditional siloed code scanning by seamlessly deploying advanced Software Composition Analysis (SCA) telemetry, rigorous Static Application Security Testing (SAST) architectures, and cohesive automated remediation frameworks. Moving beyond rigid legacy security vendors, Mend.io empowers global enterprises, elite DevOps teams, and high-growth organizations to dynamically synchronize their secure software development lifecycles (SDLC) with world-class protective execution. Under the hood, their sophisticated security infrastructure natively handles complex open-source dependency ingestion, instantaneous real-time exploit routing, and seamless developer environment integration, ensuring frictionless operational readiness and uncompromising code resilience. What sets Mend.io apart is its uncompromising dedication to frictionless security orchestration; by bridging the gap between cutting-edge vulnerability research and rigorous automated remediation, the platform empowers organizations to radically accelerate their deployment velocity, optimize application protection, and build an unassailable foundation for continuous commercial dominance in the modern cybersecurity landscape.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.






