monday.com operates a cloud-based Work OS - a platform for managing projects, automating workflows, and coordinating teams - serving roughly 245,000 customers across verticals from marketing to government. The attack surface is substantial: millions of users, a unified platform spanning work management, CRM, dev, and service products, and a Nasdaq-traded business (since 2021) with over 3,000 employees and a global footprint. The company's infrastructure touches everything from automations and AI-powered features to integrations with third-party tools, making identity, access control, and data protection non-negotiable priorities.
For security professionals, the operational context is a high-traffic SaaS environment where the threat model includes credential stuffing, API abuse, misconfigurations in tenant isolation, and supply-chain risk from the platform's extensibility. The team works across domains like application security, cloud infrastructure hardening, threat detection, and secure software development lifecycle practices - all in the context of a product that customers rely on as a daily workflow backbone. Technical rigor matters here because the platform's value proposition depends on trust: customers across industries, including regulated sectors, handle sensitive data inside monday.com's ecosystem.
The company culture emphasizes transparency and rapid iteration, which on the engineering side translates to frequent deployments and a need for security tooling that keeps pace with continuous integration. Security roles likely involve building and maintaining controls across a multi-product architecture, collaborating closely with engineering teams, and scaling defenses to match a user base that spans small businesses and large enterprises alike.






