Full-Time

Senior Product Designer

Product Design

Posted on 9/19/2025

Mondoo

Mondoo

51-200 employees

Unified security platform for IT exposure

No salary listed

Remote in USA

Remote

Category
UI/UX & Design (1)
Required Skills
JavaScript
UI/UX Design
Figma
Product Design
HTML/CSS
Requirements
  • 6-ish years of product design experience, ideally with time spent at early-stage or fast-moving startups.
  • A considered portfolio with zoomed-in detail and zoomed-out strategy.
  • Craft obsession: Strong command of design foundations like typography, space, color theory, as well as UX clarity, and micro-interaction care.
  • Strong inclination toward collaboration, comfort operating independently, and remotely.
  • The ability to tell stories, and push past the obvious.
  • Experience designing for technical audiences a plus (e.g. developers, security engineers, DevOps, etc.)
  • Figma mastery – It’s our tool of choice, the more proficient in designing and prototyping there, the better.
  • Speak the web — You should understand how to talk to developers about how to achieve your concepts through languages like HTML, CSS, and Javascript. Writing isn’t necessary, but reading is a must, if you can inspect and edit a webpage, even better.
Responsibilities
  • Champion our design principles in all of your work.
  • Lead design on core initiatives—from concept to craft—across the Mondoo platform.
  • Translate complex technical workflows into, explainable, human experiences.
  • Partner with product and engineering to incept new experiences, and refine existing ones throughout the product.
  • Help build and extend an invent new pieces of our burgeoning design system.
  • Elevate the design culture inside a small, focused team with high standards and high trust.
Desired Qualifications
  • Experience designing for technical audiences a plus (e.g. developers, security engineers, DevOps, etc.)

Mondoo helps organizations manage and reduce cyber exposure across their entire IT infrastructure by continuously discovering and inventorying assets such as on-premises servers, cloud services, SaaS apps, and employee endpoints. Its platform identifies, prioritizes, and remediates security vulnerabilities and misconfigurations through a data fabric that analyzes security data across environments, enabling clear risk insights. Security and compliance processes are automated and integrated into the development lifecycle from build to runtime, supporting DevSecOps workflows. Mondoo stands out by offering a unified framework for scanning across bare-metal servers, virtual machines, cloud environments, containers, and Kubernetes, with options ranging from a free open-source version to licensed commercial tiers. The goal is to help organizations reduce risk by providing continuous visibility, prioritized remediation, and automated compliance across all assets and environments.

Company Size

51-200

Company Stage

Early VC

Total Funding

$32.5M

Headquarters

San Francisco, California

Founded

2021

Simplify Jobs

Simplify's Take

What believers are saying

  • 7x revenue growth and 4.4x customer expansion beat targets by 62% in 2025.
  • Agentic Managed Service delivers 60% vulnerability reduction, sub-16-day MTTR.
  • Deutsche Telekom adoption enables MSSP channel partnerships for scaled growth.

What critics are saying

  • Tenable, Rapid7 enhance remediation integrations, eroding Mondoo differentiation within 12 months.
  • CrowdStrike, SentinelOne add agentic AI remediation, capturing Mondoo customers in 18 months.
  • $32.5M funding exhausts by mid-2027, forcing 40% staff cuts without new VC.

What makes Mondoo unique

  • Mondoo pioneers agentic vulnerability management automating detection to resolution.
  • Platform integrates Tenable, Rapid7, Qualys data for unified risk prioritization.
  • AI Skills Check scans agent skills across Claude Code, Cursor, Windsurf registries.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Growth & Insights and Company News

Headcount

6 month growth

-3%

1 year growth

4%

2 year growth

4%
Yahoo Finance
Mar 17th, 2026
Mondoo launches agentic managed vulnerability service with 60% reduction in vulnerabilities and sub-16-day MTTR

Mondoo has launched its Agentic Managed Vulnerability Service, combining security experts with its AI platform to deliver a 60% reduction in vulnerabilities and sub-16-day mean time to remediation. The San Francisco-based company also introduced an Automated Remediation Setup Service that deploys approved fixes through existing customer tools. The service addresses persistent challenges in vulnerability management, where organisations struggle to move beyond scanning and reporting. Mondoo research shows 91% of organisations lack confidence in their remediation ability, whilst 62% still rely on manual processes. The managed service pairs security professionals with Mondoo's AI platform, which collects data across cloud, on-premises, endpoints and software development lifecycles. The platform integrates with existing vulnerability tools including Tenable, Rapid7 and Qualys, providing a unified view of risk.

The Manila Times
Mar 17th, 2026
Mondoo launches Agentic Managed Vulnerability Service to accelerate remediation and improve outcomes.

Mondoo launches Agentic Managed Vulnerability Service to accelerate remediation and improve outcomes. By GlobeNewswire March 17, 2026 World-class security experts, powered by Mondoo's proven AI platform, now deliver a 60% reduction in vulnerabilities and sub-16-day MTTR, so overwhelmed security teams don't have to do it alone SAN FRANCISCO, March 17, 2026 (GLOBE NEWSWIRE) - Mondoo, the pioneer in agentic vulnerability management, today announced the Mondoo Agentic Managed Vulnerability Service, a new expert-led offering that moves organizations from endless scanning and reporting to actual vulnerability remediation. Mondoo also introduced the Automated Remediation Setup Service, an optional add-on that establishes automated remediation workflows so approved fixes deploy instantly through customers' existing tooling. Most vulnerability management programs are stuck in an endless cycle of scanning and reporting. Even after prioritization, there are so many critical issues that it's increasingly difficult to know which to address first. This leads to critical vulnerabilities going unpatched, leaving organizations exposed or noncompliant. According to Mondoo's State of Vulnerability Remediation research, 91% of organizations lack confidence in their remediation ability, and 62% still rely on manual processes, contributing to industry-wide alert fatigue and growing security backlogs. "Most security teams aren't short on vulnerability data; they're short on the capacity to act on it," said Soo Choi-Andrews, CEO and Co-founder, Mondoo. "We built the Agentic Managed Vulnerability Service because we believe the industry needs to shift focus from reporting to outcomes. Our customers shouldn't need to hire more people just to keep up with the influx of vulnerabilities. With our world-class experts and proven AI platform, we deliver the results, 60% fewer vulnerabilities, mean-time-to-remediation under 16 days, and 10x faster than doing it manually, so our customers can focus on strategic work instead of chasing alerts." World-Class Experts Backed by a Proven AI Platform The Mondoo Agentic Managed Vulnerability Service pairs high-caliber security and IT operations professionals with Mondoo's AI-native platform to deliver fully optimized vulnerability management programs. Mondoo experts integrate with customer teams, taking full ownership of vulnerability monitoring, prioritization, remediation guidance, and reporting. The service is built on Mondoo's unified platform, which collects high-quality, high-fidelity data across the entire IT infrastructure, including cloud, on-premises, endpoints, SaaS, network devices, and the SDLC. In addition to Mondoo's native detections, the platform manages data from existing vulnerability tools such as Tenable, Rapid7, and Qualys, and ingests signals from CrowdStrike, SentinelOne, and Microsoft Defender, giving security teams a single, comprehensive view of their risk landscape. How It Works * Onboarding & Customization: Mondoo experts deploy the platform using the customer's preferred model, initiate continuous asset discovery, integrate with existing ITSM tools, and align scope and priorities to business objectives and risk tolerance. * Issue Prioritization: Experts triage vulnerability and compliance alerts to identify real risk based on local context, using Mondoo data queries to validate whether vulnerabilities actually pose a threat in the customer's specific environment. Zero-days, actively exploited CVEs, and government-flagged critical issues (CISA, BSI) are triaged with extra urgency through enriched threat intelligence. * Fix Suggestions: Mondoo creates actionable tickets in the customer's ITSM system (Jira, ServiceNow, GitHub Issues) with affected assets, prioritization rationale, remediation guidance, automation code (Ansible, PowerShell, Intune), and ready-to-approve pull requests. When no direct fix exists, Mondoo provides tailored mitigation advice. * Apply Fixes: Customers Retain 100% Control: The customer's security team reviews and approves all suggested fixes before implementation by copying code snippets, approving pull requests in their Git-based VCS, or clicking approve on ITSM tickets. Nothing is remediated without the customer's authorization. * Verification: Mondoo rescans after fixes are implemented to confirm remediation. Verified issues close automatically; recurring issues reopen if drift is detected. * Tracking & Reporting: Mondoo delivers ongoing reporting on issues resolved, open tickets, MTTR trends, patch and EOL status, integration health, certificate expirations, asset coverage, and compliance - with weekly standups, monthly executive reports, and quarterly business reviews. Advertisement New: Automated Remediation Setup Service Mondoo also introduced the Automated Remediation Setup Service, an optional deployment and configuration engagement that establishes automated remediation workflows for organizations in need of additional support. Mondoo experts integrate the platform with customers' existing deployment tooling (Microsoft Intune, Ansible, Puppet, Chef, SCCM), ensuring that fixes are automatically executed and verified once an analyst approves the remediation ticket. For organizations without existing deployment automation, Mondoo experts set up Ansible as an open-source remediation engine at no additional licensing cost. The analyst-driven workflow keeps security teams in full control: Mondoo identifies the issue and creates an enriched ticket, the analyst reviews and approves it, the fix deploys automatically through existing tooling, and Mondoo verifies the result, eliminating manual remediation toil while maintaining complete visibility and approval authority. MSSP And Channel Ready Mondoo Agentic Managed Vulnerability Service can be resold by Mondoo channel partners and is also MSSP-ready. Managed security service providers can partner with Mondoo to build and deliver their own branded managed vulnerability offerings, extending integrated, pervasive security protection to their client base. Deutsche Telekom, co-owner of T-Mobile and one of the world's largest telecommunications providers, already leverages Mondoo to secure its hybrid infrastructure, demonstrating the platform's ability to operate at enterprise scale in complex, multi-tenant environments. "The speed and accuracy of Mondoo's platform, combined with its deep insights into IT architecture, enables customers to quickly remediate issues and significantly reduce CVEs and policy violations," said Thomas Tschersich, CEO of Telekom Security & CSO of Deutsche Telekom AG. By partnering with Mondoo, MSSPs can expand their service portfolios with a differentiated, outcomes-driven vulnerability management offering backed by Mondoo's proven AI platform and guaranteed remediation results - delivering measurable value to their clients without building the capability from scratch. The Mondoo Agentic Managed Vulnerability Service and the Automated Remediation Setup Service are now available. For more information, visit www.mondoo.com or find Mondoo at RSA Conference, Booth 4425 in the North Expo Hall. About Mondoo Mondoo's Agentic Managed Vulnerability Service, a combination of local expert security professionals and a proven AI-native platform, delivers the outcomes security professionals need, helping them transition out of the endless cycle of scanning and reporting and into actual remediation. Trusted by more than 300 customers worldwide, including Fortune 50 companies, Mondoo prioritizes risks by business impact and exploitability, collects structured, context-aware data from the entire IT infrastructure, and provides actionable remediation guidance, including automation code and ready-to-approve pull requests, that eliminates vulnerabilities rather than just categorizing them. Mondoo's customers have reduced vulnerabilities by 60%, achieved mean-time-to-remediation under 16 days, and accelerated remediation 10x faster than manual approaches. With seamless ITSM integrations, transparent security pipelines, and guaranteed outcomes, Mondoo bridges the gap between security and engineering to fix what matters most to the business. Media Contact Will Clark Marketbridge for Mondoo

WN.com
Mar 17th, 2026
Mondoo launches agentic managed vulnerability service to accelerate remediation and improve outcomes.

Mondoo launches agentic managed vulnerability service to accelerate remediation and improve outcomes.

Mondoo
Oct 3rd, 2025
Mondoo Raises $17.5 Million to Pioneer Agentic Vulnerability Management

Context-aware AI agents unify vulnerability prioritization, remediation and orchestration across enterprise IT infrastructure, security and platform engineering teams

GeekTech
Oct 1st, 2025
Mondoo Raises $17.5 Million for Vulnerability Management Platform

Mondoo has raised more than $32 million in total, with the latest funding round led by HV Capital.

INACTIVE