Logo for Mend.io

Security Operations Lead

Role overview

Qualifications

  • Strong experience in Security Operations, Cloud Security, Product Security, or a similar role.
  • Hands-on experience with cloud security technologies, vulnerability management, incident response, SIEM, WAF, CSPM, and IAM.
  • Experience working closely with Engineering and Product teams.
  • Familiarity with SOC 2, ISO 27001, and security compliance frameworks.

Responsibilities

  • Assess security risks across Mend’s product and cloud infrastructure and drive a prioritized improvement plan.
  • Own day-to-day cloud and infrastructure security operations, including SIEM/SOC monitoring, WAF, CSPM, access reviews, encryption, and secrets management.
  • Lead vulnerability management, including Mend’s HackerOne bug bounty program and remediation coordination with Engineering.
  • Lead security incident response and support disaster recovery planning and testing.

Key facts

Hard skills

Other skills

  • Analytical Skills
  • Communication
  • Collaboration

About the company

Mend.io logo

Mend.io

Computer Software / SaaS

Mend.io, formerly known as WhiteSource, has over a decade of experience helping global organizations build world-class AppSec programs that reduce risk and accelerate development -– using tools built into the technologies that software and security teams already love. Our automated technology protects organizations from supply chain and malicious package attacks, vulnerabilities in open source and custom code, and open-source license risks. With a proven track record of successfully meeting complex and large-scale application security needs, Mend.io is the go-to technology for the world’s most demanding development and security teams. The company has more than 1,000 customers, including 25 percent of the Fortune 100, and manages Renovate, the open source automated dependency update project. For more information visit Mend.io.

Company details

Company typeSME
IndustryComputer Software / SaaS
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Why Mend.io

We are redefining how modern organizations secure software from open source and custom code to AI-generated components. As the creators of the first AI Native AppSec Platform, we help global enterprises stay safe, fast, and compliant in an era of AI-driven development. Our platform combines intelligent automation, deep risk visibility, and developer-first experiences, shaping the future of application security.

We are also committed to building a collaborative, empowering workplace. If you are excited about this role but do not meet every requirement, we encourage you to apply. Your perspective could be exactly what we need!

Mend is looking for a hands-on Security Operations Lead to drive security operations across our cloud infrastructure, product, compliance, and customer-facing activities.

You will work closely with Engineering, Product, IT, Sales, Legal, and company leadership to identify risks, improve controls, respond to security issues, and strengthen Mend’s overall security posture.

Responsibilities

  • Assess security risks across Mend’s product and cloud infrastructure and drive a prioritized improvement plan.

  • Own day-to-day cloud and infrastructure security operations, including SIEM/SOC monitoring, WAF, CSPM, access reviews, encryption, and secrets management.

  • Lead vulnerability management, including Mend’s HackerOne bug bounty program and remediation coordination with Engineering.

  • Lead security incident response and support disaster recovery planning and testing.

  • Support customer-facing security activities, including questionnaires, RFPs, and technical security discussions during sales cycles.

  • Drive audit and certification activities, including SOC 2 and ISO 27001/27701/27017, and maintain compliance controls and evidence through Drata.

  • Manage third-party security assessments and support security and AI governance.

  • Serve as a key internal security advisor for teams across the company.

  • Own and improve security tooling, automation, and operational processes.

What We’re Looking For

  • Strong experience in Security Operations, Cloud Security, Product Security, or a similar role.

  • Hands-on experience with cloud security technologies, vulnerability management, incident response, SIEM, WAF, CSPM, and IAM.

  • Experience working closely with Engineering and Product teams.

  • Familiarity with SOC 2, ISO 27001, and security compliance frameworks.

  • Strong analytical, communication, and cross-functional collaboration skills.

  • A practical, hands-on approach with the ability to balance security risk and business needs.

Our Culture

At Mend.io, we are leading the way in securing AI-powered applications, and we believe the best innovations come from teams where everyone feels valued. We are committed to a workplace built on respect, trust, and growth, where learning and flexibility empower people to do their best work.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Operations Lead Related jobs

Other jobs at Mend.io

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.