Staff / Principal Software Engineer, Detection and Response
On-siteStockholm, Stockholm, Sweden
Stockholm, Stockholm, SwedenOn-siteFull TimeSenior LevelSmall
Full TimeSenior LevelSmall
Job Summary
Build the detection engineering platform with pipelines, detections-as-code, automated triage, and response playbooks. Design and own the security incident response process featuring 24/7 coverage, leading incidents end-to-end from detection through post-mortem. Hunt proactively across corporate, production, and AI-agent surfaces to turn findings into durable detections. Define world-class detection and response capabilities for an AI-native company.
Required Qualifications
- 8+ years in detection engineering, incident response, or threat hunting
- at least 3 at staff/principal level
- Strong engineering background - you build detections as code, not as saved searches in a SIEM
- Deep experience with cloud telemetry (GCP/AWS/Cloudflare)
- Deep experience with endpoint EDR
- Deep experience with identity logs
- Deep experience with modern SIEM/data-lake stacks (Panther, Elastic, Snowflake/Clickhouse)
- Battle-tested incident commander who has led real high-severity incidents from first alert to public post-mortem
- Adversary-minded: comfortable with MITRE ATT&CK
- Adversary-minded: comfortable with threat intel
- Adversary-minded: comfortable with purple-teaming
- Adversary-minded: comfortable with red team collaboration
- Must be able to speak English
Desired Qualifications
- Bonus: detection for LLM/agent abuse
- Bonus: detection for prompt injection at scale
- Bonus: detection for insider risk in AI-augmented engineering orgs
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.