Staff Principal Software Engineer Infrastructure Security

AI platform for creating, deploying, and managing full-stack software through natural-language interaction.

Series CRecently funded0 current maintainers0 active leadsTeam intelligence

Maintainer signals as of 9/25/2026

Stockholm, Sweden
About Lovable

Lovable lets people describe an idea in plain language and collaboratively build production-grade software. Its platform includes hosting, authentication, payments, integrations, security features, and deployment infrastructure.

View jobs by Lovable

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will set technical direction for cloud, identity, and build-runtime security; design workload identity, least-privilege IAM, network segmentation, secrets management, and production-access guardrails; harden the software supply chain; and mentor engineers on security practices.

Requirements

  • 8+ years of experience in infrastructure or cloud security
  • At least 3 years at staff or principal level
  • Deep expertise in GCP, AWS, and Cloudflare security primitives
  • Experience with IAM, network security, KMS, workload identity, and edge security
  • Hands-on experience with Kubernetes, Terraform, Wiz, GitHub Actions, and CI/CD
  • Knowledge of supply-chain security, including SLSA, Sigstore, and SBOMs
  • Ability to write Go, Python, or Rust
  • Track record of reducing security blast radius at a high-growth company
  • Bonus: experience securing multi-tenant platforms or LLM/agent-driven infrastructure
  • Application must be submitted in English

Responsibilities

  • Set technical direction for cloud, identity, and build/runtime security
  • Design and ship workload identity guardrails
  • Implement least-privilege IAM
  • Implement network segmentation
  • Manage secrets and production access
  • Harden the software supply chain from developer laptop to production deployment
  • Partner with Platform, SRE, and applications platform stakeholders
  • Mentor engineers across the organization
  • Raise the security standard by default