# Application Security Engineer

**Company:** [Lovable](https://hotfix.jobs/companies/lovable)
**Location:** Stockholm, Sweden
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** Application Security, Secure Code Review, Threat Modeling, Sast/Dast, Supply Chain Security, Vulnerability Management, CI/CD, Secrets Management, Containerization, Cloudflare, GCP, AWS, Terraform, React, TypeScript
**Posted:** 2026-05-15

> The Application Security Engineer embeds security throughout the software development lifecycle through code reviews, threat modeling, security tooling, vulnerability response, and developer mentoring. The role requires 5+ years of application security experience and strong programming skills across cloud-native environments.

## Job Description

## Responsibilities
- Conduct secure code reviews, threat modeling, and architecture assessments to identify and mitigate vulnerabilities early.
- Collaborate with engineering teams to design and implement security features, provide actionable feedback, and embed security into product development.
- Lead security training, workshops, and one-on-one mentoring to upskill developers and foster a security-first culture.
- Integrate SAST/DAST and supply chain security tools into CI/CD pipelines for continuous, automated protection.
- Detect, triage, and respond to application vulnerabilities and incidents, driving remediation and continuous improvement.
- Monitor and address emerging risks in AI infrastructure, LLM pipelines, and third-party dependencies.

## Requirements
- 5+ years of experience in application security, including securing cloud-native environments at product-focused technology companies, high-growth startups, or leading AI labs.
- Strong programming and engineering skills.
- Deep expertise in application security, including secure code review, threat modeling, SAST/DAST, supply chain security, product patching, and vulnerability management.
- Experience securing engineering infrastructure, including CI/CD pipelines, secrets management, service-to-service authentication, containerized workloads, and public cloud platforms.
- Hands-on experience collaborating with developers to design and implement security features and best practices.
- Experience educating and mentoring engineers on secure coding, vulnerability remediation, and emerging threats.
- Systems mindset, with the ability to read and contribute to codebases, build security tooling, and integrate security into engineering workflows.

## Nice-to-haves
- Experience building internal security tools.
- Contributions to open-source security projects.

## Technical Environment
- Frontend: React, TypeScript
- Backend: Golang, Rust
- Cloud: Cloudflare, Google Cloud, AWS, Terraform
- DevOps and tooling: CI/CD pipelines, observability, infrastructure as code

## Similar jobs

- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Security Engineer, Corporate](https://hotfix.jobs/jobs/dcd1e85d-0333-46e1-82bd-188613dd7173) - Lovable - Stockholm, Sweden
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Lead Product GRC Subject Matter Expert](https://hotfix.jobs/jobs/57c937d5-05e3-4033-875a-890645c4aa6b) - Vanta - Remote - $230k – $270k/yr

**Apply:** https://hotfix.jobs/jobs/3b29cc9d-8a19-400b-a3cc-a584d58cc48c
**Canonical:** https://hotfix.jobs/jobs/3b29cc9d-8a19-400b-a3cc-a584d58cc48c