At monday.com, we are reshaping the way teams work. Our AI Work Platform is an open platform that democratizes the power of software so organizations can easily build software applications and work management tools tailored to their exact needs. As a fast-growing, global SaaS company, trust and security are at the core of everything we do. We are looking for a visionary, hands-on leader to ensure our rapidly evolving platform remains secure, resilient, and trusted by millions of users worldwide.
About The RoleAs our Application Security Team Lead, you will lead a talented team of security engineers, working hand-in-hand with our Product and R&D organizations to embed security into every phase of the software development lifecycle (SDLC), while owning the planning and execution of our global AppSec program.
This is a high-impact managerial role that balances deep technical expertise with business influence. You will champion a "secure-by-design" culture, ensuring that our fast-paced deployment cycles never compromise on data protection and application resilience.
As our Application Security Team Lead, you will lead a talented team of security engineers, working hand-in-hand with our Product and R&D organizations to embed security into every phase of the software development lifecycle (SDLC), while owning the planning and execution of our global AppSec program.
This is a high-impact managerial role that balances deep technical expertise with business influence. You will champion a "secure-by-design" culture, ensuring that our fast-paced deployment cycles never compromise on data protection and application resilience.
Key Responsibilities
- Strategic Leadership & Culture
- Define the Vision: Craft and execute a comprehensive, scalable application security roadmap aligned with monday.com’s rapid growth and multi-product strategy.
- Cultivate a Security Mindset: Drive a culture of security ownership across R&D through training, champion programs, and collaborative threat modeling.
- Team Growth: Mentor, scale, and lead a high-performing team of AppSec engineers, fostering continuous learning and innovation.
- Technical & Operational Oversight
- Secure SDLC: Integrate automated security testing (SAST,SCA, Secrets) seamlessly into our CI/CD pipelines without slowing down engineering velocity.
- Threat Modeling & Review: Lead threat modeling sessions and architectural reviews for major platform shifts, new features, and infrastructure changes.
- Vulnerability Management: Oversee our bug bounty program, penetration testing engagements, and internal vulnerability disclosures, ensuring smart, risk-based prioritization and remediation.
- Collaboration & Compliance
- R&D Partnership: Act as a trusted advisor to product managers and engineering leads, balancing risk mitigation with business agility.
- Compliance & Trust: Partner with Governance, Risk, and Compliance (GRC) teams to ensure application alignment with international standards (e.g., SOC 2, ISO 27001, GDPR, HIPAA).
- Proven Leadership: 8+ years of experience in dedicated application security roles, with at least 3+ years successfully managing and scaling AppSec teams in a modern cloud/SaaS environment.
- Deep Technical Expertise: Strong background in securing cloud-native applications (AWS preferable) and deep knowledge of web application vulnerabilities (OWASP Top 10, CWE).
- Developer Fluent: Proficiency in modern programming languages used in our stack (e.g., Node.js, Ruby on Rails, React) and experience with containerized environments (Kubernetes, Docker).
- Automation Advocate: Proven track record of implementing and optimizing AppSec tooling directly into DevOps pipelines (GitHub, CI/CD tools).
- Outstanding Communication: Ability to translate complex cryptographic and security concepts into actionable business context for both developers and executive stakeholders.
Skills Required
- 8+ years of experience in dedicated application security roles
- 3+ years successfully managing and scaling AppSec teams
- Strong background in securing cloud-native applications
- Deep knowledge of web application vulnerabilities (OWASP Top 10, CWE)
- Proficiency in modern programming languages (Node.js, Ruby on Rails, React)
- Experience with containerized environments (Kubernetes, Docker)
- Proven track record of implementing AppSec tooling into DevOps pipelines
- Outstanding communication skills
monday.com Compensation & Benefits Highlights
-
Retirement Support — A 401(k) with a guaranteed 3% company contribution regardless of employee deferral, plus equity eligibility and an ESPP, strengthens long‑term financial security. This flat contribution adds predictable value alongside stock programs.
-
Parental & Family Support — Up to 13 weeks fully paid parental leave for all caregivers, adoption assistance, and an onsite mother’s room indicate robust family support. Access to fertility support is also described.
-
Wellbeing & Lifestyle Benefits — Day‑to‑day perks include free in‑office breakfast, a monthly meal stipend around $300, a commuter stipend around $130, snacks, and a monthly wellness stipend, alongside 12 EAP sessions. These allowances complement medical, dental, vision, life, and disability insurance.
monday.com Insights
What We Do
At monday.com, we help teams get more work done. We are the best AI work platform that empowers teams to automate, build, and scale their impact end-to-end with tools that actually execute the work for you. With over $1B in ARR, 250,000+ customers, and a global team, we’re serious about building a product people love to use and giving our employees the same ownership and flexibility to shape the way the world works.
Why Work With Us
At monday.com we believe in transparency, accountability, and impact. Together, those values have lent themselves to create a strong culture of professional and creative autonomy where every team member is encouraged to share ideas and help bring them to life!
Gallery
monday.com Teams
monday.com Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
monday.com embraces a flexible work environment with our hybrid model!












