Lovable logo

Staff / Principal Software Engineer, Detection and Response

Lovable

Stockholm, Stockholm County, SwedenFull-timeNo compensation foundPosted 1w agoVerified open 5 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
Stockholm, Stockholm County, Sweden
Schedule
Full-time
Work Authorization
Not specified

Job overview

Lovable is hiring a Staff / Principal Software Engineer, Detection and Response. Lovable seeks a senior engineer to build detection and response capabilities that catch attackers across corporate, production, and AI‑agent surfaces. The role involves creating detections as code, leading high‑severity incidents, and defining world‑class security for an AI‑native company.

Key focus areas include Build detection engineering platform including pipelines, detections‑as‑code, automated triage, and response playbooks, Design and own security incident response process with 24/7 coverage, and Lead incidents end‑to‑end from detection through containment, eradication, and post‑mortem.

Important skills include Detection Engineering, Incident Management, Threat Hunting, Cloud Telemetry GCP, Cloud Telemetry AWS, and Cloud Telemetry Cloudflare. Preferred (not required): LLM Abuse Detection, Prompt Injection Detection, and Insider Risk Detection.

Skills & qualifications

RequiredNice to have

Skills

Detection EngineeringIncident ManagementThreat HuntingCloud Telemetry GCPCloud Telemetry AWSCloud Telemetry CloudflareEndpoint EDRIdentity LogsPanther SIEMElastic SIEMSnowflakeClickhouseMITRE ATT&CKThreat IntelPurple-TeamingRed Team CollaborationLLM Abuse DetectionPrompt Injection DetectionInsider Risk DetectionReactTypeScriptGoRustGitHub ActionsGrafanaOpenTelemetryTerraformFirestoreSpannerBigQueryDetections-as-CodeAutomated TriageResponse Playbooks

Qualifications

8+ Years Detection Engineering Experience3+ Years Staff/Principal Level ExperienceEnglish Language Proficiency

Full job description

TL;DR You'll build the detection and response capability that catches attackers before they matter - across Lovable's corporate, production, and AI-agent surfaces.

WHY LOVABLE?

Lovable is the software creation platform that gives people the power to act on the problems closest to them. For decades, turning an idea into software required so much capital, technical fluency, and time that many ideas never came to life. Lovable is the counterargument: a platform for all people with ideas, ambition, and problems worth solving. From solopreneurs to small business owners to teams at companies like Adidas and Zendesk, people have built over 60 million projects on Lovable since its launch in November 2024. And we’re just getting started.

We’re building a generational company from Stockholm, with growing teams in London, Boston, New York, and San Francisco. Our team is small, talent-dense, and moving quickly, with a culture rooted in extreme ownership, high velocity, and low-ego collaboration. We look for people who care deeply, ship fast, and are eager to make a dent in the world.

Lovable is one of TIME’s 100 Most Influential Companies and has been recognized on the Forbes AI 50 and CNBC Disruptor 50, reflecting our momentum as one of Europe’s fastest-growing AI companies and one of the most ambitious places to build in this next era of software.

WHAT WE'RE LOOKING FOR

  • 8+ years in detection engineering, incident response, or threat hunting, with at least 3 at staff/principal level.

  • Strong engineering background - you build detections as code, not as saved searches in a SIEM.

  • Deep experience with cloud telemetry (GCP/AWS/Cloudflare), endpoint EDR, identity logs, and modern SIEM/data-lake stacks (Panther, Elastic, Snowflake/Clickhouse).

  • Battle-tested incident commander who has led real high-severity incidents from first alert to public post-mortem.

  • Adversary-minded: comfortable with MITRE ATT&CK, threat intel, purple-teaming, and red team collaboration.

  • Bonus: detection for LLM/agent abuse, prompt injection at scale, or insider risk in AI-augmented engineering orgs.

WHAT YOU'LL DO

  • Build the detection engineering platform - pipelines, detections-as-code, automated triage, and response playbooks.

  • Design and own security incident response process with 24/7 coverage, with a small, high-leverage human and agent team.

  • Lead incidents end-to-end: detection, containment, eradication, post-mortem, and follow-through.

  • Hunt proactively across corporate, production, and AI-agent surfaces - and turn every finding into a durable detection.

  • Define what 'world-class D&R for an AI-native company' looks like, and build it.

OUR TECH STACK

  • Frontend: React and Typescript.

  • Backend: Golang and Rust.

  • Cloud: Cloudflare, GCP, AWS, multiple LLM providers.

  • DevOps & Tooling: GitHub Actions, Grafana, OTEL, infra-as-code (Terraform).

  • Data: Clickhouse, Firestore, Spanner, BigQuery.

And we’re always exploring what’s next!

ABOUT YOUR APPLICATION

Please submit your application in English. It’s our company language, so you’ll be speaking lots of it if you join. We treat all candidates equally - if you’re interested, please apply through our careers portal.

You've read the whole posting — now see how you match it.