Head of DevOps and Security
Why Mend.io
We are redefining how modern organizations secure software from open source and custom code to AI-generated components. As the creators of the first AI Native AppSec Platform, we help global enterprises stay safe, fast, and compliant in an era of AI-driven development. Our platform combines intelligent automation, deep risk visibility, and developer-first experiences, shaping the future of application security.
We are also committed to building a collaborative, empowering workplace. If you are excited about this role but do not meet every requirement, we encourage you to apply. Your perspective could be exactly what we need!
We are looking for a Head of DevOps and Security to own the strategy and standards for the function that keeps our cloud infrastructure fast, reliable, and secure. You'll manage the DevOps team lead, giving direction on architecture, priorities, and technical bar while they run the team's day-to-day work. Alongside that, you'll be hands-on with security operations that today sit with SecOps, acting as our internal CISO-adjacent voice on cloud risk, compliance, and incident response. You'll be the person engineering leadership turns to when infrastructure and security decisions need to move fast without cutting corners
Responsibilities:
DevOps leadership and infrastructure
Manage the DevOps team lead: set direction, priorities, and the technical bar for the team, and support their growth as a manager
Own our cloud infrastructure and architecture (multi-cloud), including provisioning, scaling, and cost governance
Drive CI/CD, release processes, and deployment reliability so engineers can ship confidently
Own observability and incident response tooling, ensuring issues are caught early and resolved fast
Introduce and evaluate new cloud technologies and tools to improve delivery, scalability, and availability
Partner with R&D, product, and IT leadership to align infrastructure decisions with business needs
Own the R&D budget: plan and track spend, prioritize investment across infrastructure, tooling, and security, and report on it to leadership
Security operations and compliance
Operate and enhance security monitoring and incident response platforms (SIEM, SOAR)
Analyse system and application telemetry to detect, investigate, and respond to suspicious activity
Implement and maintain secure configurations across cloud environments and CI/CD pipelines
Review and prioritize findings from application and infrastructure security tools, and drive remediation with engineering
Own audit readiness and compliance efforts (SOC 2, ISO 27001, or similar frameworks)
Set and enforce security standards and policies across the organization, acting as the internal escalation point for security risk
Qualifications:
8+ years in DevOps, Site Reliability, or Platform Engineering, including experience managing a team lead or manager (not just individual contributors)
4+ years of hands-on experience in Security Operations or Security Engineering, ideally in a cloud-native SaaS environment
Deep expertise in at least one major cloud provider (AWS, Azure, or GCP), including networking, IAM, and cost management
Strong hands-on experience with Kubernetes, Terraform (or equivalent IaC), and modern CI/CD tooling
Working knowledge of security tooling (SIEM, EDR, IDS/IPS, vulnerability management) and compliance frameworks (SOC 2, ISO 27001, NIST)
Solid observability experience (metrics, logging, tracing) and a track record of owning incident response end to end
Strong people leader: coaches and grows managers, sets direction others can execute against, and represents DevOps and security credibly across the organization
Pragmatic and outcome-oriented, comfortable balancing technical depth with leadership responsibilities and defending trade-offs to non-technical stakeholders
Experience owning a budget: planning spend, prioritizing trade-offs, and reporting to leadership
Our Culture
At Mend.io, we are leading the way in securing AI-powered applications, and we believe the best innovations come from teams where everyone feels valued. We are committed to a workplace built on respect, trust, and growth, where learning and flexibility empower people to do their best work.