Skip to content

Lovable

Security Engineer, Corporate

Location
Stockholm, Stockholm County, SE
Arrangement
On-site
Employment type
Full-time
Posted
18 September 2026 (12 days ago)

Checked 12 days agoApplications go to the employer, never to RoleSprint

About this role

TL;DR You'll secure how Lovable works - the laptops, identities, SaaS apps, and AI tools 250+ Lovables use every day - without slowing anyone down.

WHY LOVABLE?

Lovable is the software creation platform that gives people the power to act on the problems closest to them. For decades, turning an idea into software required so much capital, technical fluency, and time that many ideas never came to life. Lovable is the counterargument: a platform for all people with ideas, ambition, and problems worth solving. From solopreneurs to small business owners to teams at companies like Adidas and Zendesk, people have built over 60 million projects on Lovable since its launch in November 2024. And we’re just getting started.

We’re building a generational company from Stockholm, with growing teams in London, Boston, New York, and San Francisco. Our team is small, talent-dense, and moving quickly, with a culture rooted in extreme ownership, high velocity, and low-ego collaboration. We look for people who care deeply, ship fast, and are eager to make a dent in the world.

Lovable is one of TIME’s 100 Most Influential Companies and has been recognized on the Forbes AI 50 and CNBC Disruptor 50, reflecting our momentum as one of Europe’s fastest-growing AI companies and one of the most ambitious places to build in this next era of software.

WHAT WE'RE LOOKING FOR

- 5+ years in corporate, enterprise, or endpoint security at a fast-growing tech company.

- Deep expertise in identity (Google Workspace/Okta/Entra, SSO, SCIM, conditional access), MDM (Jamf/Kandji/Intune), and SaaS security posture (SSPM).

- You can write code (Python, Bash, or Go) and treat policies as software - versioned, tested, deployed.

- Strong instincts for IT risks such as phishing, social engineering, and insider risk - including the new AI-flavored variants.

- Pragmatic about UX. You know when a control is real security and when it's just friction.

- Bonus: experience securing AI tools and agents in the workplace (Claude, ChatGPT, Cursor, et al).

- Bonus: experience managing hardware security keys

WHAT YOU'LL DO

- Own the security of Lovable's corporate environment: identity, endpoints, SaaS, email, and the AI tools we live in.

- Roll out and maintain controls that scale - passkeys, device trust, conditional access, DLP, SSPM.

- Run phishing, awareness, and tabletop programs that actually change behavior.

- Work on Detection & Response to make detection of insider and account-takeover risk first-class.

- Secure and optimise our diverse AI toolstack, including Lovable itself, working closely with the product team on feedback and iterations

- Help the Security and GRC teams make least-privilege the default and auditability free.

- Ensure the right data is surfaced to the right people, while implementing data classifications and reducing the risk of data loss

OUR STACK

- Devices: macOS, Linux, Kandji, Crowdstrike

- Networking: Tailscale, Cloudflare, Meter, Unifi

- IAM: Google Workspace, Okta, Entra

- Dev tools/data: Lovable, GitHub, BigQuery, various AI tools

- GRC: Vanta, Wiz

About your application

Please submit your application in English. It’s our company language, so you’ll be speaking lots of it if you join. We treat all candidates equally - if you’re interested, please apply through our careers portal.

Work location

  • Stockholm, Stockholm County, SE

Related jobs

Ready to make a decision?

This role is either worth your time or it isn’t.

Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.

Nothing is submitted automatically. You choose what happens next.

About this listing

Advertised by Lovable and published on Ashby, the applicant tracking system they use.

RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.

Published 18 September 2026, last checked 12 days ago. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.

More searches like this one

Browse all current openings

No credit card requiredStart free