Skip to content
LovableLovable

Staff / Principal Software Engineer, Infrastructure Security

Leads infrastructure security strategy and implementation across cloud, identity, runtime, and software supply chains. The role requires 8+ years of infrastructure or cloud security experience, staff/principal-level leadership, and hands-on expertise with major cloud and security platforms.

About the job

Responsibilities

  • Set the technical direction for cloud, identity, and build/runtime security.
  • Design and ship guardrails for workload identity, least-privilege IAM, network segmentation, secrets management, and production access.
  • Harden the software supply chain end to end, from developer laptops to production deployments.
  • Partner with Platform, SRE, and the Apps Platform team to make secure paths easy to use.
  • Mentor engineers across the company and raise the security bar by default.

Requirements

  • 8+ years of experience in infrastructure or cloud security, including at least 3 years at staff or principal level.
  • Deep expertise in GCP, AWS, and Cloudflare security primitives, including IAM, networking, KMS, workload identity, and edge security.
  • Hands-on experience with Kubernetes, Terraform, Wiz, GitHub Actions, and modern CI/CD.
  • Knowledge of supply-chain security, including SLSA, Sigstore, and SBOMs.
  • Comfort writing Go, Python, or Rust to ship security guardrails as code.
  • Track record of measurably reducing blast radius involving secrets, lateral movement, and production access.

Nice to Have

  • Experience securing multi-tenant platforms.
  • Experience securing LLM- or agent-driven infrastructure.

Technology Stack

  • Frontend: React, TypeScript
  • Backend: Golang, Rust
  • Cloud: Cloudflare, GCP, AWS, multiple LLM providers
  • DevOps and tooling: GitHub Actions, Grafana, OTEL, Terraform
  • Data: ClickHouse, Firestore, Spanner, BigQuery

Skills

GCP, AWS, Cloudflare, IAM, Kms, Kubernetes, Terraform, Wiz, GitHub Actions, Slsa, Sigstore, Sboms, Go, Python, Rust

Lovable

Lovable

Stockholm, Sweden

Staff / Principal Software Engineer, Detection and Response
No salary listedOn-site8+ YOESecurity Engineering

Leads detection engineering and incident response across corporate, production, and AI-agent environments. The role requires 8+ years of relevant experience, strong detections-as-code expertise, cloud and telemetry knowledge, and proven leadership of high-severity security incidents.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Vanta

Vanta

Remote

Lead Product GRC Subject Matter Expert
$230k+/yrRemote10+ YOESecurity Engineering

Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Lovable

Lovable

Stockholm, Sweden

Security Engineer, Corporate
No salary listedOn-site5+ YOESecurity Engineering

Owns corporate security across identities, endpoints, SaaS, email, and workplace AI tools. The role requires 5+ years of corporate, enterprise, or endpoint security experience, strong IAM and MDM expertise, coding ability, and practical risk-based security judgment.