Staff / Principal Software Engineer, Detection and Response

Lovable

Town of Stockholm (NY)

On-site

USD 180,000 - 320,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Lovable is building a detection and response capability that catches attackers before they matter—across corporate, production, and AI-agent surfaces. You’ll lead the creation of detections as code, automated triage, and 24/7 incident response oversight.

As a staff/principal leader, you will hunt across cloud telemetry (GCP/AWS/Cloudflare), EDR, identity logs, and modern data stacks, guiding real-time response and post-mortems.

Qualifications

  • 8+ years in detection engineering, incident response, or threat hunting, with at least 3 at staff/principal level.
  • Strong engineering background - you build detections as code, not as saved searches in a SIEM.
  • Deep experience with cloud telemetry (GCP/AWS/Cloudflare), endpoint EDR, identity logs, and modern SIEM/data-lake stacks (Panther, Elastic, Snowflake/Clickhouse).
  • Battle-tested incident commander who has led real high-severity incidents from first alert to public post-mortem.
  • Adversary-minded: comfortable with MITRE ATT&CK, threat intel, purple-teaming, and red team collaboration.
  • Bonus: detection for LLM/agent abuse, prompt injection at scale, or insider risk in AI-augmented engineering orgs.

Responsibilities

  • Build the detection engineering platform - pipelines, detections-as-code, automated triage, and response playbooks.
  • Design and own security incident response process with 24/7 coverage, with a small, high-leverage human and agent team.
  • Lead incidents end-to-end: detection, containment, eradication, post-mortem, and follow-through.
  • Hunt proactively across corporate, production, and AI-agent surfaces - and turn every finding into a durable detection.
  • Define what 'world-class D&R for an AI-native company' looks like, and build it.

Skills

Detection engineering
Incident response
Threat hunting
Cloud telemetry
EDR
MITRE ATT&CK
Threat intel
Purple-teaming
Red team
Team leadership

Tools

Panther
Elastic
Snowflake
ClickHouse

Job description

TL;DR You'll build the detection and response capability that catches attackers before they matter - across Lovable's corporate, production, and AI-agent surfaces.

Why Lovable?

Lovable is the software creation platform that gives people the power to act on the problems closest to them. For decades, turning an idea into software required so much capital, technical fluency, and time that many ideas never came to life. Lovable is the counterargument: a platform for all people with ideas, ambition, and problems worth solving. From solopreneurs to small business owners to teams at companies like Adidas and Zendesk, people have built over 60 million projects on Lovable since its launch in November 2024. And we’re just getting started.

We’re building a generational company from Stockholm, with growing teams in London, Boston, New York, and San Francisco. Our team is small, talent-dense, and moving quickly, with a culture rooted in extreme ownership, high velocity, and low-ego collaboration. We look for people who care deeply, ship fast, and are eager to make a dent in the world.

Lovable is one of TIME’s 100 Most Influential Companies and has been recognized on the Forbes AI 50 and CNBC Disruptor 50, reflecting our momentum as one of Europe’s fastest-growing AI companies and one of the most ambitious places to build in this next era of software.

What we're looking for
  • 8+ years in detection engineering, incident response, or threat hunting, with at least 3 at staff/principal level.
  • Strong engineering background - you build detections as code, not as saved searches in a SIEM.
  • Deep experience with cloud telemetry (GCP/AWS/Cloudflare), endpoint EDR, identity logs, and modern SIEM/data-lake stacks (Panther, Elastic, Snowflake/Clickhouse).
  • Battle-tested incident commander who has led real high-severity incidents from first alert to public post-mortem.
  • Adversary-minded: comfortable with MITRE ATT&CK, threat intel, purple-teaming, and red team collaboration.
  • Bonus: detection for LLM/agent abuse, prompt injection at scale, or insider risk in AI-augmented engineering orgs.
What you'll do
  • Build the detection engineering platform - pipelines, detections-as-code, automated triage, and response playbooks.
  • Design and own security incident response process with 24/7 coverage, with a small, high-leverage human and agent team.
  • Lead incidents end-to-end: detection, containment, eradication, post-mortem, and follow-through.
  • Hunt proactively across corporate, production, and AI-agent surfaces - and turn every finding into a durable detection.
  • Define what 'world-class D&R for an AI-native company' looks like, and build it.
Our tech stack
  • Frontend: React and Typescript.
  • Backend: Golang and Rust.
  • Cloud: Cloudflare, GCP, AWS, multiple LLM providers.
  • DevOps & Tooling: GitHub Actions, Grafana, OTEL, infra-as-code (Terraform).
  • Data: Clickhouse, Firestore, Spanner, BigQuery.

And we’re always exploring what’s next!

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Detection & Response Platform Engineer
Staff Detection & Response Platform Engineer

Lovable • Town of Stockholm (NY)

On-site
USD 180,000 - 320,000
Detection and Response Engineer
Detection and Response Engineer

Modal Labs • New York (NY)

On-site
USD 140,000 - 190,000
Detection and Response Engineer
Detection and Response Engineer

Modal • New York (NY)

On-site
USD 140,000 - 210,000
Staff / Principal Software Engineer, Infrastructure Security
Staff / Principal Software Engineer, Infrastructure Security

Lovable • Town of Stockholm (NY)

On-site
USD 180,000 - 240,000
Artificial Intelligence Engineer
Artificial Intelligence Engineer

detections-ai • California (MO)

On-site
USD 150,000 - 190,000
Trust & Safety Analyst Engineer
Trust & Safety Analyst Engineer

Lovable • Town of Stockholm (NY)

On-site
USD 140,000 - 190,000
Detection Engineer, Security Operations & Telemetry
Detection Engineer, Security Operations & Telemetry

Saronic • Austin (TX)

On-site
Confidential
Area Lead
Area Lead

Lovable • Town of Stockholm (NY)

On-site
USD 260,000 - 360,000
Trust & Safety Engineer
Trust & Safety Engineer

Lovable • Town of Stockholm (NY)

On-site
USD 180,000 - 250,000
Security Engineer, Detection and Response
Security Engineer, Detection and Response

OpenAI • United States

On-site
USD 293,000 - 385,000