TL;DR You'll build the detection and response capability that catches attackers before they matter - across Lovable's corporate, production, and AI-agent surfaces.
Why Lovable?
Lovable is the software creation platform that gives people the power to act on the problems closest to them. For decades, turning an idea into software required so much capital, technical fluency, and time that many ideas never came to life. Lovable is the counterargument: a platform for all people with ideas, ambition, and problems worth solving. From solopreneurs to small business owners to teams at companies like Adidas and Zendesk, people have built over 60 million projects on Lovable since its launch in November 2024. And we’re just getting started.
We’re building a generational company from Stockholm, with growing teams in London, Boston, New York, and San Francisco. Our team is small, talent-dense, and moving quickly, with a culture rooted in extreme ownership, high velocity, and low-ego collaboration. We look for people who care deeply, ship fast, and are eager to make a dent in the world.
Lovable is one of TIME’s 100 Most Influential Companies and has been recognized on the Forbes AI 50 and CNBC Disruptor 50, reflecting our momentum as one of Europe’s fastest-growing AI companies and one of the most ambitious places to build in this next era of software.
What we're looking for
8+ years in detection engineering, incident response, or threat hunting, with at least 3 at staff/principal level.
Strong engineering background - you build detections as code, not as saved searches in a SIEM.
Deep experience with cloud telemetry (GCP/AWS/Cloudflare), endpoint EDR, identity logs, and modern SIEM/data-lake stacks (Panther, Elastic, Snowflake/Clickhouse).
Battle-tested incident commander who has led real high-severity incidents from first alert to public post-mortem.
Adversary-minded: comfortable with MITRE ATT&CK, threat intel, purple-teaming, and red team collaboration.
Bonus: detection for LLM/agent abuse, prompt injection at scale, or insider risk in AI-augmented engineering orgs.
What you'll do
Build the detection engineering platform - pipelines, detections-as-code, automated triage, and response playbooks.
Design and own security incident response process with 24/7 coverage, with a small, high-leverage human and agent team.
Lead incidents end-to-end: detection, containment, eradication, post-mortem, and follow-through.
Hunt proactively across corporate, production, and AI-agent surfaces - and turn every finding into a durable detection.
Define what 'world-class D&R for an AI-native company' looks like, and build it.
Our tech stack
Frontend: React and Typescript.
Backend: Golang and Rust.
Cloud: Cloudflare, GCP, AWS, multiple LLM providers.
DevOps & Tooling: GitHub Actions, Grafana, OTEL, infra-as-code (Terraform).
Data: Clickhouse, Firestore, Spanner, BigQuery.
And we’re always exploring what’s next!
About your application
Please submit your application in English. It’s our company language, so you’ll be speaking lots of it if you join.
We treat all candidates equally - if you’re interested, please apply through our careers portal.