Staff / Principal Software Engineer, Security
Build end-to-end security features and systems for an AI-powered software creation platform, including scanners, compliance tooling, static analysis, and AI-assisted vulnerability remediation. Requires 10+ years of engineering experience, strong React/TypeScript and Golang skills, and on-site work in Stockholm.
About the job
Responsibilities
- Build security features and systems for an AI-powered software creation platform.
- Develop security product features end-to-end, including audit flows, security scanner interfaces, compliance tooling, and static analysis.
- Integrate AI/LLM capabilities into security workflows to detect, explain, and remediate vulnerabilities.
- Ship across the full stack, owning work from the first commit through production.
- Advocate for secure coding practices and conduct security-focused code reviews.
- Influence technical direction and product strategy with a security-first mindset.
Requirements
- 10+ years of engineering experience shipping production-grade products at high velocity, with experience operating at senior engineering levels.
- Deep experience with React and TypeScript on the frontend and Golang on the backend.
- Experience with product security features or code security and static analysis, such as SAST, linters, or vulnerability scanners.
- Strong understanding of systems design, performance tradeoffs, and scalable architecture.
- Strong product sense and ability to make complex functionality simple and actionable.
- Familiarity with AI/LLM-powered tooling or dense algorithmic or systems work.
- Ability to navigate ambiguity and drive clarity at an organisational level.
- Based in Stockholm or willing to relocate.
- Willingness to work on-site five days per week.
Tech Stack
- Frontend: React, TypeScript
- Backend: Golang, Rust
- Cloud: Cloudflare, Google Cloud, AWS
- DevOps and tooling: GitHub Actions, Grafana, OpenTelemetry, Terraform
- Data: ClickHouse, Firestore, Spanner, BigQuery
- Multiple LLM providers
Skills
React, TypeScript, Go, Rust, Cloudflare, GCP, AWS, GitHub Actions, Grafana, OpenTelemetry, Terraform, ClickHouse, Firestore, Spanner, BigQuery
Similar jobs
Security Engineering jobsLeads detection engineering and incident response across corporate, production, and AI-agent environments. The role requires 8+ years of relevant experience, strong detections-as-code expertise, cloud and telemetry knowledge, and proven leadership of high-severity security incidents.
Leads infrastructure security strategy and implementation across cloud, identity, runtime, and software supply chains. The role requires 8+ years of infrastructure or cloud security experience, staff/principal-level leadership, and hands-on expertise with major cloud and security platforms.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.