--- title: 'Principal Software Engineer - Mend AI (AI Security) at Mend.io' canonical: 'https://feeny.ai/job/principal-software-engineer-mend-ai-ai-security-mend-io-givatayim-w6fadjxb1hqe' type: 'job' last_seen: '2026-09-11' --- # Principal Software Engineer - Mend AI (AI Security) at Mend.io - **Company:** Mend.io - **Location:** Givatayim, Israel - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-07-20 - **Last confirmed live:** 2026-09-11 - **Apply:** https://jobs.ashbyhq.com/mend-io/e0b68d46-6caf-4427-a7bd-43828427856d ## Job description ## Why Mend.io We are redefining how modern organizations secure software from open source and custom code to AI-generated components. As the creators of the first AI Native AppSec Platform, we help global enterprises stay safe, fast, and compliant in an era of AI-driven development. Our platform combines intelligent automation, deep risk visibility, and developer-first experiences, shaping the future of application security. We are also committed to building a collaborative, empowering workplace. If you are excited about this role but do not meet every requirement, we encourage you to apply. Your perspective could be exactly what we need! [Mend.io](http://Mend.io) is building the next generation of application security for AI-powered software, and Mend AI is the team leading that bet. Our product detects and secures AI/ML components inside applications - addressing emerging risks like prompt injection, data leakage, and adversarial attacks - in a domain where the standards are still being written. We're looking for a Principal Software Engineer to take end-to-end ownership: from research and design through production, on systems that combine classical algorithms with AI/LLM-based capabilities. This is an AI-native role in both senses - you'll build security for AI systems, and you'll work AI-first yourself, using coding agents across the development lifecycle and knowing how to get consistently high-quality results from them. You'll work as a senior individual contributor with real influence over architecture and product direction, collaborating directly with security researchers, data scientists, and product managers across our Poland and Israel teams (1-hour time difference - genuine daily collaboration, not satellite work). ## What You'll Do - Own solutions end to end - from studying the domain and generating your own ideas, through research and design, to coding, shipping, and supporting them in production. - Drive independent research in a new domain where problems are not fully defined, balancing innovation with practical, cost-effective engineering - Build and evolve backend & frontend, extending traditional microservices with AI/LLM-based capabilities - Use AI agents throughout development - research, design, coding, and testing - to raise both speed and quality - Work closely with security researchers, data scientists, and product managers to turn ideas into shipped product ## What We're Looking For - 10+ years of backend software engineering experience, including 3+ years in a hands-on technical leadership role (Principal / Tech Lead / Architect) - A product mindset: you connect technical decisions to business impact - A team player with excellent communication skills, who’s not afraid to touch every aspect of modern software product development (e.g. quality, documentation, customer-facing technical discussions) - Proven experience designing and building systems from scratch in a product environment - including reliable, concurrent, thread-safe services - Strong hands-on skills in a modern backend language (Go or Python preferred) and the ability to pick up new languages and technologies quickly - Real, hands-on experience using AI coding agents across the development lifecycle - you know their strengths, their failure modes, and how to guide them to high-quality results - Solid grounding in cloud environments and modern development practices (AWS, GCP, or Azure) ## Nice to Have - Familiarity with AI security challenges (prompt injection, model leakage, adversarial attacks) - Experience integrating AI/LLM capabilities into real-world production systems - beyond out-of-the-box API calls (tuning, customization, evaluation) - Experience with ML workflows (training, deployment, inference) or tools such as LangChain, Hugging Face, or provider SDKs - Background in application security, cloud security, or DevSecOps Why [Mend.io](http://Mend.io) [Mend.io](http://Mend.io) is an established leader in application security - an AI-native AppSec platform trusted by enterprises worldwide. Mend AI operates like a startup inside that stability: a small, senior team with a greenfield mandate, direct access to decision-makers, and a product in one of the fastest-moving spaces in security. Our Poland team is a core engineering site, not an outsourcing arm - architecture happens where the engineers are. [Mend.io](http://Mend.io) is an equal opportunity employer. All aspects of employment are based solely on merit and professional competence, and we're committed to a diverse, inclusive workplace where everyone can do their best work. Our Culture At [Mend.io](https://www.mend.io), we are leading the way in securing AI-powered applications, and we believe the best innovations come from teams where everyone feels valued. We are committed to a workplace built on respect, trust, and growth, where learning and flexibility empower people to do their best work. ## About Mend.io ## Company Overview - **One-liner**: Mend.io provides a unified application security (AppSec) and AI security platform that helps enterprises secure code, dependencies, and AI models from development through runtime. - **Entity Type**: Private (Series D, $75M raised in 2021) - **Headquarters**: Boston, Massachusetts, United States (with major R&D hub in Tel Aviv, Israel) - **Founded**: 2011 (originally as WhiteSource, later rebranded to Mend.io) - **Founders**: Rami Sass and Azi Cohen ## Core Business - **Primary industries**: Application Security, AI Security, Software Supply Chain Security, Developer Tools - **Target customers**: Enterprise B2B – security teams, DevOps, and developers at large organizations - **Mission**: “Make application security frictionless for developers and scalable for security teams without compromise” – security should empower, not block. ## Products & Services - **Mend AppSec** (SCA, SAST, DAST, Container Security, License Compliance): A full-stack code security platform covering open source risk (reachability-driven SCA), custom code analysis (high-accuracy SAST), runtime API security, container scanning, and license governance. Includes automated SBOM generation and malicious package protection. - **Mend AI** (AI Security Posture Management – AI-SPM): Secures the AI lifecycle with Shadow AI discovery, AI-BOM generation, automated red teaming (CI/CD-integrated adversarial simulations across 8 attack vectors), system prompt hardening, runtime guardrails (behavioral enforcement between users and models), and compliance reporting aligned to EU AI Act. - **Mend Renovate** (Automated Dependency Updates): The world’s most trusted open-source dependency update tool (originally open source). Auto-creates safe, governed pull requests for 90+ ecosystems, with Merge Confidence scoring, grouping, and centralized policy management to reduce both technical and security debt. ## Market Standing - **Valuation**: Not publicly disclosed (last round – Series D of $75M in April 2021, led by Pitango VC) - **Key Metrics**: - **Annual Revenue** (Private): ~$28.2M (2025 estimate per LinkedIn) - **Total Funding**: $121.15M across 5 rounds (Seed 2011, Seed 2013, Series B 2017, Series C 2018, Series D 2021) - **Notable Investors/Partners**: 83North, Pitango VC, Susquehanna Growth Equity - **Growth Signals**: - Expanded from pure SCA to a unified AppSec + AI security platform - Acquired Renovate (2019) and Atom Security (2023) to strengthen capabilities - Active job postings up 100% month-over-month (12 current open roles as of mid-2025) - 33,918 LinkedIn followers (5% YoY growth) - Recognized as a leader in application security testing by analysts (Gartner, Forrester) ## Competitive Advantages - **Unified code + AI security**: Only platform that connects software supply chain security with AI security (model inventory, red teaming, runtime guardrails) in a single governed workflow. - **Independent and vendor-agnostic**: Not tied to any specific cloud or model provider – “Three of five AI security vendors are now inside big platforms. We’re not beholden to any model provider.” - **Pioneering SCA**: One of the first companies to make open source risk visible at enterprise scale, with a widely adopted open-source tool (Renovate) used by thousands of organizations. - **Developer-first approach**: Security that integrates seamlessly into IDEs, CI/CD, and PR workflows – reducing friction and accelerating remediation (e.g., 75% reduction in time spent on open source audits). ## Strategic Focus - **Securing the full AI lifecycle**: From AI model discovery and prompt hardening to runtime behavioral controls and compliance (EU AI Act, Cyber Resilience Act, NIST). - **Compliance as a byproduct**: Continuous inventory, testing, and remediation that produce audit-ready SBOM/AI-BOM documentation without manual overhead. - **Scaling Renovate adoption**: Pushing Renovate as the standard for automated dependency updates in enterprises, now bundled with Mend’s security scanning. - **Headcount rationalization**: After an 8.8% workforce reduction, focused investment in AI security, engineering, and go-to-market roles. ## Why Work Here - **Culture**: “Security should empower, not block” – a developer-empathy culture that values low-friction, high-impact security. Global and diverse team across 12 countries. - **Work style**: Hybrid/remote-friendly (offices in Boston, Tel Aviv, Germany, Poland, Croatia, India). Engineering culture emphasizes autonomy, open-source contributions, and modern tooling. - **Engineering focus**: Deep technical challenges in AI security, static analysis, reachability, and large-scale dependency graphs. Active job postings for senior backend, Java, principal software engineer, and agentic code analysis roles. - **Perks**: Not formally disclosed, but competitive compensation (e.g., Senior Channel Manager ~$137K/year, Fullstack Engineer ~$350K ILS/month) and a strong commitment to learning and innovation. - **Growth trajectory**: Rapidly expanding into the hottest segment (AI security) while maintaining a strong base in AppSec; early-stage enough for significant impact. ## Sources 1. [mend.io/about-us](https://www.mend.io/about-us/) 2. [mend.io/why-mend](https://www.mend.io/why-mend/) 3. [linkedin.com/company/mend-io](https://www.linkedin.com/company/mend-io) 4. [mend.io/careers](https://www.mend.io/careers/) ## Other roles at Mend.io - [Channel Manager, EMEA & APAC](https://feeny.ai/job/channel-manager-emea-apac-mend-io-givatayim-293s4dr5d2hb) — Givatayim, Israel - [Office Manager & Employee Experience Partner](https://feeny.ai/job/office-manager-employee-experience-partner-mend-io-givatayim-d0kd121gn5v3) — Givatayim, Israel - [Technical Support Engineer](https://feeny.ai/job/technical-support-engineer-mend-io-poland-fbdztprg1rva) — Poland - [Head of DevOps](https://feeny.ai/job/head-of-devops-mend-io-givatayim-494e2g6b67kh) — Givatayim, Israel - [Regional Sales Manager - AI Team](https://feeny.ai/job/regional-sales-manager-ai-team-mend-io-united-states-d9n8xy0p44tf) — United States - [Financial Planning & Analysis Manager](https://feeny.ai/job/financial-planning-analysis-manager-mend-io-givatayim-75rd4b47y1va) — Givatayim, Israel - [Account Executive, EMEA & APAC](https://feeny.ai/job/account-executive-emea-apac-mend-io-givatayim-r00hjz6m31ga) — Givatayim, Israel - [Account Executive](https://feeny.ai/job/account-executive-mend-io-united-states-zxfmh7y5g272) — United States - [Business Development Representative](https://feeny.ai/job/business-development-representative-mend-io-united-states-g68sv9c65tcz) — United States - [Principal Software Engineer - Mend AI (AI Security)](https://feeny.ai/job/principal-software-engineer-mend-ai-ai-security-mend-io-poland-hphm03162dq0) — Poland