Security Operations Lead

Mend.io REMOTE KRAKOW WARSAW 2026-09-30

  • 6+ years experience in Security Operations, Cloud Security, Product Security, or a similar role.
  • Hands-on experience with cloud security technologies, vulnerability management, incident response, SIEM, WAF, CSPM, and IAM.
  • Experience working closely with Engineering and Product teams.
  • Familiarity with SOC 2, ISO 27001, and security compliance frameworks.
  • Strong analytical, communication, and cross-functional collaboration skills.
  • A practical, hands-on approach with the ability to balance security risk and business needs.

Mend is looking for a hands-on Security Operations Lead to drive security operations across our cloud infrastructure, product, compliance, and customer-facing activities.

You will work closely with Engineering, Product, IT, Sales, Legal, and company leadership to identify risks, improve controls, respond to security issues, and strengthen Mend’s overall security posture.



Why Mend.io:
Mend.io is redefining how modern organizations secure software, from open source and custom code to AI generated components. As the creators of the first AI Native AppSec Platform, we help global enterprises stay safe, fast, and compliant in an era of AI driven development. Our platform combines intelligent automation, deep risk visibility, and developer-first experiences, shaping the future of application security.We are also committed to building an inclusive, empowering workplace. If you’re excited about this role but don’t meet every requirement, we encourage you to apply. Your perspective could be exactly what we need.



Our Benefits:

We offer two flexible engagement options: B2B contract or employment via Deel. Both come with a strong benefits package designed to support you professionally and personally.


Core Benefits:



  • Remote Work: Work from your home office in Poland.

  • Training Budget: Annual budget for professional development.

  • Stock Options: Share in our company’s success.

  • Recharge Days: 4 Annually (One company-wide Friday off each quarter).

  • Absence Paid Days: 36 days to utilize time off.

  • Company Equipment Purchase: We cover the cost of your new laptop and essential work tools, so you can set yourself up for success from day one.


Our Culture:
At Mend.io, we are building more than the future of application security - we are building a culture where diverse perspectives drive innovation. As we lead the way in securing AI powered applications, we believe the best solutions come from teams where everyone feels seen, heard, and empowered to thrive.We are committed to a workplace rooted in respect, trust, and growth. That means supporting your development through mentorship, learning, and meaningful challenges, while also valuing flexibility and balance.



,[Assess security risks across Mend’s product and cloud infrastructure and drive a prioritized improvement plan., Own day-to-day cloud and infrastructure security operations, including SIEM/SOC monitoring, WAF, CSPM, access reviews, encryption, and secrets management., Lead vulnerability management, including Mend’s HackerOne bug bounty program and remediation coordination with Engineering., Lead security incident response and support disaster recovery planning and testing., Support customer-facing security activities, including questionnaires, RFPs, and technical security discussions during sales cycles., Drive audit and certification activities, including SOC 2 and ISO 27001/27701/27017, and maintain compliance controls and evidence through Drata., Manage third-party security assessments and support security and AI governance., Serve as a key internal security advisor for teams across the company., Own and improve security tooling, automation, and operational processes.] Requirements: Security Engineering, SecOps, Public cloud, AWS, Azure, SIEM, IDS/IPS, EDR, SaaS, Kubernetes, SOC 2, ISO 27001, NIST Tools: Jira, Github, Confluence, GitHub. Additionally: Training budget, International projects.