6d ago

avatar

Lovable

Staff / Principal Software Engineer, Detection and Response

$160K - $240K

Stockholm, Stockholm County, Sweden

Senior (10+ years)

SaaS

Growing (201–500)

[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]

Questions about the Staff / Principal Software Engineer, Detection and Response role at Lovable

What core technical competencies define a 'principal' impact in D&R?

A principal-level impact in Detection and Response at Lovable is defined by shifting from reactive manual tasks to building automated, durable systems. You must possess deep expertise in "detections-as-code," replacing static SIEM queries with scalable, programmatic detection pipelines. A principal leader doesn't just manage incidents; they architect the entire response ecosystem, integrating AI-agent workflows, telemetry optimization, and proactive threat hunting across cloud and LLM-specific surfaces. Crucially, this role demands the ability to bridge the gap between high-level adversary modeling—using MITRE ATT&CK and purple-teaming—and robust engineering execution. Your impact is measured by your capacity to codify defense, reduce manual toil, and define the security posture for an AI-native infrastructure.

How do you balance automated detection with manual threat hunting priorities?

In this role, balancing automation with manual hunting is about creating a virtuous cycle. I prioritize building a robust detection-as-code platform, utilizing tools like Panther or Snowflake to automate high-fidelity alerts that reduce noise for our on-call team. Once the baseline is automated, I dedicate capacity to proactive threat hunting across our unique AI-agent and cloud surfaces. Every manual discovery is then engineered back into the pipeline as a durable detection, continuously shifting our defensive posture. By treating security infrastructure as a product, we ensure that manual effort is never redundant, but rather a catalyst for scaling our defenses against evolving adversary tactics.

How is the industry evolving to handle AI-agent specific security threats?

The industry is shifting from traditional perimeter defense toward "AI-native" security, focusing on observability and detection-as-code. As roles like Lovable’s Principal Software Engineer indicate, the evolution involves protecting non-deterministic AI surfaces from prompt injection, model abuse, and agentic manipulation. Organizations are moving beyond static SIEM searches, instead integrating specialized telemetry from LLM providers and infrastructure-as-code to build automated triage playbooks. Security is no longer just about guarding endpoints; it now requires proactive threat hunting across AI-agent workflows. By treating AI-augmented environments as unique attack surfaces, firms are developing durable, code-driven detections to mitigate risks before they escalate, effectively redefining "world-class" incident response for an era defined by autonomous software creation.

How does D&R at Lovable protect AI-agent surfaces versus corporate assets?

At Lovable, Detection and Response (D&R) employs a unified engineering-led approach to secure both environments, though the implementation nuances differ. For corporate assets, the team focuses on traditional telemetry from EDR, identity providers, and cloud logs to identify unauthorized access and insider threats. Conversely, securing AI-agent surfaces requires specialized, forward-looking strategies, such as detecting prompt injection, model abuse, and anomalous agent behavior. Across both domains, the team treats detections as code, building automated pipelines and response playbooks that transform proactive threat hunting into durable, scalable alerts. By leveraging tools like Cloudflare, GCP, and advanced data stacks, Lovable bridges the gap between infrastructure security and emerging AI-specific risks.

What is your vision for integrating agent-led triage into the incident workflow?

My vision for integrating agent-led triage is to transform security response from a reactive, manual burden into an automated, high-velocity feedback loop. At Lovable, where we handle complex AI-agent surfaces, agents should serve as the "first responder" layer. They will perform real-time correlation across telemetry—GCP, Cloudflare, and EDR logs—to qualify alerts, verify true positives, and execute initial containment protocols instantly. By embedding agents directly into our Detection-as-Code pipeline, we can move from simple filtering to autonomous, context-aware decision-making. This frees our human team to focus on high-level threat hunting and strategic architecture, ensuring that our response capabilities scale alongside the platform, maintaining world-class security without sacrificing the velocity that defines our culture.