Lovable logo
LovablePosted 1 week ago

Staff / Principal Software Engineer, Detection and Response

On-siteStockholm, Stockholm, Sweden

Full TimeSenior LevelSmall

Job Summary

Build the detection engineering platform with pipelines, detections-as-code, automated triage, and response playbooks. Design and own the security incident response process featuring 24/7 coverage, leading incidents end-to-end from detection through post-mortem. Hunt proactively across corporate, production, and AI-agent surfaces to turn findings into durable detections. Define world-class detection and response capabilities for an AI-native company.

Required Qualifications

  • 8+ years in detection engineering, incident response, or threat hunting
  • at least 3 at staff/principal level
  • Strong engineering background - you build detections as code, not as saved searches in a SIEM
  • Deep experience with cloud telemetry (GCP/AWS/Cloudflare)
  • Deep experience with endpoint EDR
  • Deep experience with identity logs
  • Deep experience with modern SIEM/data-lake stacks (Panther, Elastic, Snowflake/Clickhouse)
  • Battle-tested incident commander who has led real high-severity incidents from first alert to public post-mortem
  • Adversary-minded: comfortable with MITRE ATT&CK
  • Adversary-minded: comfortable with threat intel
  • Adversary-minded: comfortable with purple-teaming
  • Adversary-minded: comfortable with red team collaboration
  • Must be able to speak English

Desired Qualifications

  • Bonus: detection for LLM/agent abuse
  • Bonus: detection for prompt injection at scale
  • Bonus: detection for insider risk in AI-augmented engineering orgs

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce