Back to search
EngineeringOn-site

Staff / Principal Software Engineer, Detection and Response

Lovable · On-site

Apply
Last seen by MeritLog September 9, 2026Source: AshbySource version: ashby-public-job-posting-v1

MeritLog read this listing from Lovable's Ashby job board and last checked it on September 9, 2026.

Source: the employer's Ashby job board. Open the original listing for current details.

Job details

Work model
On-site
Salary
Not listed by source
Location
Stockholm

Hiring context

How this role compares at Lovable

Lovable has 83 live roles in MeritLog’s catalog across 11 job families, and 33 of them are in engineering. 0 of those listings publish a pay range, a disclosure rate of 0%.

Lovable concentrates this hiring in:

Counted across the job boards MeritLog tracks, at the time this page was served. Pay comparisons use only listings that publish a complete range in the same currency and period.

What the role asks for

What you'd do

  • Build the detection engineering platform - pipelines, detections-as-code, automated triage, and response playbooks.
  • Design and own security incident response process with 24/7 coverage, with a small, high-leverage human and agent team.
  • Lead incidents end-to-end: detection, containment, eradication, post-mortem, and follow-through.
  • Hunt proactively across corporate, production, and AI-agent surfaces - and turn every finding into a durable detection.
  • Define what 'world-class D&R for an AI-native company' looks like, and build it.
  • Frontend: React and Typescript.
  • Backend: Golang and Rust.
  • Cloud: Cloudflare, GCP, AWS, multiple LLM providers.
  • DevOps & Tooling: GitHub Actions, Grafana, OTEL, infra-as-code (Terraform).
  • Data: Clickhouse, Firestore, Spanner, BigQuery.

Parsed by MeritLog from the employer’s own posting. The full description follows below.

Job description

TL;DR You'll build the detection and response capability that catches attackers before they matter - across Lovable's corporate, production, and AI-agent surfaces. WHY LOVABLE? Lovable is the software creation platform that gives people the power to act on the problems closest to them. For decades, turning an idea into software required so much capital, technical fluency, and time that many ideas never came to life. Lovable is the counterargument: a platform for all people with ideas, ambition, and problems worth solving. From solopreneurs to small business owners to teams at companies like Adidas and Zendesk, people have built over 60 million projects on Lovable since its launch in November 2024. And we’re just getting started. We’re building a generational company from Stockholm, with growing teams in London, Boston, New York, and San Francisco. Our team is small, talent-dense, and moving quickly, with a culture rooted in extreme ownership, high velocity, and low-ego collaboration. We look for people who care deeply, ship fast, and are eager to make a dent in the world. Lovable is one of TIME’s 100 Most Influential Companies and has been recognized on the Forbes AI 50 and CNBC Disruptor 50, reflecting our momentum as one of Europe’s fastest-growing AI companies and one of the most ambitious places to build in this next era of software. WHAT WE'RE LOOKING FOR - 8+ years in detection engineering, incident response, or threat hunting, with at least 3 at staff/principal level. - Strong engineering background - you build detections as code, not as saved searches in a SIEM. - Deep experience with cloud telemetry (GCP/AWS/Cloudflare), endpoint EDR, identity logs, and modern SIEM/data-lake stacks (Panther, Elastic, Snowflake/Clickhouse). - Battle-tested incident commander who has led real high-severity incidents from first alert to public post-mortem. - Adversary-minded: comfortable with MITRE ATT&CK, threat intel, purple-teaming, and red team collaboration. - Bonus: detection for LLM/agent abuse, prompt injection at scale, or insider risk in AI-augmented engineering orgs. WHAT YOU'LL DO - Build the detection engineering platform - pipelines, detections-as-code, automated triage, and response playbooks. - Design and own security incident response process with 24/7 coverage, with a small, high-leverage human and agent team. - Lead incidents end-to-end: detection, containment, eradication, post-mortem, and follow-through. - Hunt proactively across corporate, production, and AI-agent surfaces - and turn every finding into a durable detection. - Define what 'world-class D&R for an AI-native company' looks like, and build it. OUR TECH STACK - Frontend: React and Typescript. - Backend: Golang and Rust. - Cloud: Cloudflare, GCP, AWS, multiple LLM providers. - DevOps & Tooling: GitHub Actions, Grafana, OTEL, infra-as-code (Terraform). - Data: Clickhouse, Firestore, Spanner, BigQuery. And we’re always exploring what’s next! ABOUT YOUR APPLICATION Please submit your application in English. It’s our company language, so you’ll be speaking lots of it if you join. We treat all candidates equally - if you’re interested, please apply through our careers portal.

Privacy choices

Analytics and advertising stay off unless you allow them. Private data stays out.

Read the privacy notice