Staff / Principal Software Engineer, Detection and Response

Lovable
Stockholm
Workplace: OnsiteFull timeFunction: Software EngineeringExperience: 8+ yearsSkills: ["Extreme ownership","High-velocity","Low-ego collaboration","Adversary-minded","Incident leadership","Proactive problem solving"]

Build Lovable’s detection and response capability across corporate, production, and AI-agent surfaces. Design detections-as-code and automated triage/response playbooks, and lead end-to-end incidents from first alert through eradication and post-mortem. Proactively hunt using telemetry, EDR, identity logs, and modern SIEM/data-lake stacks, partnering on purple/red-team activities and MITRE ATT&CK-driven threat intelligence.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Lovable
Lovable
3 days ago

Staff / Principal Software Engineer, Detection and Response

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 2 hours agoStatus: Live

Job Summary

Build Lovable’s detection and response capability across corporate, production, and AI-agent surfaces. Design detections-as-code and automated triage/response playbooks, and lead end-to-end incidents from first alert through eradication and post-mortem. Proactively hunt using telemetry, EDR, identity logs, and modern SIEM/data-lake stacks, partnering on purple/red-team activities and MITRE ATT&CK-driven threat intelligence.
Location: Stockholm
Workplace: Onsite
Employment Type: Full time
Job Function: Software Engineering
Seniority: Sr. Manager level

Key Responsibilities

  • •Build the detection engineering platform, including pipelines, detections-as-code, automated triage, and response playbooks.
  • •Design and own the security incident response process with 24/7 coverage using a small, high-leverage human and agent team.
  • •Lead security incidents end-to-end: detection, containment, eradication, post-mortem, and follow-through.
  • •Hunt proactively across corporate, production, and AI-agent surfaces and convert findings into durable detections.
  • •Define and build what world-class detection and response for an AI-native company looks like.

Key Requirements

  • •8+ years in detection engineering, incident response, or threat hunting, including at least 3 years at staff/principal level.
  • •Strong engineering background building detections as code rather than in a SIEM UI.
  • •Deep experience with cloud telemetry (GCP/AWS/Cloudflare), endpoint EDR, identity logs, and modern SIEM/data-lake stacks (Panther, Elastic, Snowflake/Clickhouse).
  • •Battle-tested incident commander who has led real high-severity incidents from first alert through public post-mortem.
  • •Adversary-minded with experience using MITRE ATT&CK, threat intel, purple-teaming, and collaborating with red teams.
Experience:8+ yearsSecurityThreat huntingIncident responseDetection engineering
Skills:Extreme ownershipHigh-velocityLow-ego collaborationAdversary-mindedIncident leadershipProactive problem solving
Languages:English
Tech Stack:ReactTypescriptGolangRustCloudflareGCPAWSGitHub ActionsGrafanaOTELTerraformClickhouseFirestoreSpannerBigQueryMITRE ATT&CK

Company Brief

Lovable
Lovable builds a conversational AI platform that lets users create apps and websites by chatting with AI, automating full‑stack development and integrations to rapidly produce production-ready software.
Industry: Developer Tools
Company Size: Medium (51 to 250 employees)
Revenue: USD 100M to 250M
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series B
Headquarters: Stockholm, Sweden
Founded: 2023
WebsiteLinkedInGlassdoor