SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Lovable is a software creation platform that democratizes software development, enabling people with ideas to build without requiring extensive capital or technical expertise. Since launching in November 2024, over 60 million projects have been created on the platform by solopreneurs, small business owners, and teams at companies like Adidas and Zendesk. The company is recognized as one of TIME's 100 Most Influential Companies and appears on Forbes AI 50 and CNBC Disruptor 50.
You will lead the detection and response capability that identifies and stops attackers before they can cause damage across Lovable's corporate infrastructure, production systems, and AI-agent surfaces. This is a Staff/Principal-level role reporting to security leadership, with ownership of the entire detection engineering platform and incident response program.
Key responsibilities include: building the detection engineering platform with pipelines, detections-as-code, automated triage, and response playbooks; designing and owning the 24/7 security incident response process with a small, high-leverage team of humans and AI agents; leading incidents end-to-end from detection through post-mortem and remediation; proactively hunting across corporate, production, and AI-agent surfaces and converting findings into durable detections; and defining what world-class detection and response looks like for an AI-native company.
Required qualifications: 8+ years in detection engineering, incident response, or threat hunting with at least 3 years at staff/principal level; strong engineering background building detections as code rather than saved searches; deep experience with cloud telemetry (GCP/AWS/Cloudflare), endpoint EDR, identity logs, and modern SIEM/data-lake stacks (Panther, Elastic, Snowflake/Clickhouse); proven incident command experience leading high-severity incidents from alert to post-mortem; adversary-minded approach with comfort in MITRE ATT&CK, threat intelligence, purple-teaming, and red team collaboration. Bonus experience includes detection for LLM/agent abuse, prompt injection at scale, or insider risk in AI-augmented engineering organizations.
The tech stack includes React and TypeScript frontend, Golang and Rust backend, Cloudflare/GCP/AWS cloud infrastructure, GitHub Actions and Terraform for DevOps, and Clickhouse, Firestore, Spanner, and BigQuery for data.