Search...

Application Security Engineer

Lovable logo
Lovable

AI app builder that turns natural-language prompts into full-stack web applications.

Maintainer signals as of 8/14/2026

Stockholm, Sweden
About Lovable

Lovable (lovable.dev) is a Swedish AI software-builder platform: users describe an app in natural language and Lovable generates production full-stack code — one of the fastest-growing AI products.

View jobs by Lovable

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will champion application security throughout the development lifecycle. You will conduct secure code reviews, threat modeling, and architecture assessments; design and implement secure features with engineers; integrate automated security tools into CI/CD pipelines; and detect, triage, and remediate vulnerabilities and incidents. You will also deliver security training and mentoring, and address emerging risks in AI infrastructure, LLM pipelines, and third-party dependencies.

Requirements

  • 5+ years of application security experience securing cloud-native environments at product-focused technology companies, high-growth startups, or leading AI labs.
  • Strong programming and engineering skills.
  • Expertise in secure code review, threat modeling, SAST, DAST, supply chain security, product patching, and vulnerability management.
  • Experience securing CI/CD pipelines, secrets management, service-to-service authentication, containerized workloads, and public cloud platforms.
  • Experience collaborating with developers to design and implement security features and best practices.
  • Experience educating and mentoring engineers on secure coding, vulnerability remediation, and emerging threats.
  • Ability to read and contribute to codebases, build security tooling, and integrate security into engineering workflows.
  • Experience building internal security tools or contributing to open-source security projects is a bonus.

Responsibilities

  • Conduct secure code reviews, threat modeling, and architecture assessments to identify and mitigate vulnerabilities early.
  • Design and implement security features with engineering teams and embed security in product development.
  • Lead security training, workshops, and one-to-one mentoring for developers.
  • Integrate SAST, DAST, and supply chain security tools into CI/CD pipelines.
  • Detect, triage, and respond to application vulnerabilities and incidents.
  • Monitor and address emerging risks in AI infrastructure, LLM pipelines, and third-party dependencies.