22 days ago
Stockholm, SwedenStaff+
Responsibilities
- Set the technical direction for cloud, identity, build, and runtime security.
- Design and ship guardrails for workload identity, least-privilege IAM, network segmentation, secrets management, and production access.
- Harden the software supply chain from developer laptops through production deployment.
- Partner with Platform, SRE, and Lovable Apps Platform teams to make secure workflows easy to adopt.
- Mentor engineers and raise the company-wide security bar through secure-by-default practices.
Requirements
- 8+ years of experience in infrastructure or cloud security, including at least 3 years at staff or principal level.
- Deep expertise in GCP, AWS, and Cloudflare security primitives, including IAM, networking, KMS, workload identity, and edge security.
- Hands-on experience with Kubernetes, Terraform, Wiz, GitHub Actions, and modern CI/CD, plus supply-chain security practices such as SLSA, sigstore, and SBOMs.
- Ability to write Go, Python, or Rust to implement security guardrails as code.
- Demonstrated success reducing blast radius involving secrets, lateral movement, and production access at a high-growth company.
- Experience securing multi-tenant platforms or LLM/agent-driven infrastructure is preferred.
Tech Stack
AWSClickHouseCloudflareGitHub ActionsGoGoogle BigQueryGoogle Cloud PlatformGrafanaKubernetesPythonReactRustTerraformTypeScript