Staff / Principal Software Engineer, Detection and Response
LovableStockholmFull TimeEngineering
Remotely
reactawstypescriptrustgolanggcpterraformcloudflare
Job Description
📋 Description
- Build the detection engineering platform - pipelines, detections-as-code, automated triage, and
- Design and own security incident response process with 24/7 coverage, with a small, high-leverage
- Lead incidents end-to-end: detection, containment, eradication, post-mortem, and follow-through.
- Hunt proactively across corporate, production, and AI-agent surfaces - and turn every finding into
- Define what 'world-class D&R for an AI-native company' looks like, and build it.
🎯 Requirements
- 8+ years in detection engineering, incident response, or threat hunting, with at least 3 at
- Strong engineering background - you build detections as code, not as saved searches in a SIEM.
- Deep experience with cloud telemetry (GCP/AWS/Cloudflare), endpoint EDR, identity logs, and modern
- Battle-tested incident commander who has led real high-severity incidents from first alert to
- Adversary-minded: comfortable with MITRE ATT&CK, threat intel, purple-teaming, and red team
- Bonus: detection for LLM/agent abuse, prompt injection at scale, or insider risk in AI-augmented
Back to all jobs