Penetration Tester
Lovable
Penetration Tester at Lovable is a full time role based in Stockholm, Stockholm County, Sweden. It was published on 29 May 2026 and was open at last check.
| Role | Penetration Tester |
|---|---|
| Company | Lovable |
| Location | Stockholm, Stockholm County, Sweden |
| Employment type | Full Time |
| Published | 29 May 2026 |
| Status | Open at last check |
TL;DR: We're looking for a world-class Penetration Tester with a name in the field. You'll push Lovable's platform to its limits, hunt vulnerabilities across our AI pipelines and user-generated code, and make sure attackers never get there before you do.
Why Lovable?
Lovable lets anyone and everyone build software with any language. From solopreneurs to Fortune 100 teams, millions of people use Lovable to transform raw ideas into real products - fast. We are at the forefront of a foundational shift in software creation, which means you have an unprecedented opportunity to change the way the digital world works. Over 2 million people in 200+ countries already use Lovable to launch businesses, automate work, and bring their ideas to life. And we’re just getting started.
We’re a small, talent-dense team building a generation-defining company from Stockholm. We value extreme ownership, high velocity, and low-ego collaboration. We seek out people who care deeply, ship fast, and are eager to make a dent in the world.
What we’re looking for
- 12+ years of hands-on penetration testing experience across web, mobile, APIs, and cloud infrastructure.
- A track record the field knows about: CVEs to your name, hall-of-fame credits in major bug bounty programs, or a reputation that precedes you.
- Deep expertise in offensive security techniques: OWASP, MITRE ATT&CK, exploit development, privilege escalation, and lateral movement.
- Hands-on experience using AI as part of your hacking workflow — not just testing AI systems, but actively leveraging it as an offensive tool.
- Experience attacking AI-native products or LLM-integrated systems, including prompt injection, model abuse, and data exfiltration vectors.
- Strong understanding of cloud environments (GCP, AWS, Cloudflare) and the attack surfaces they introduce.
- Ability to translate complex findings into clear, prioritised reports that engineering teams can act on immediately.
- Low ego, high output. You collaborate as naturally as you compete against systems.
- Bonus: experience with red team operations, supply chain attacks, or mobile security (iOS/Android). Familiarity with SAST/DAST tooling.
What you’ll do
- Own offensive security end-to-end: plan and execute penetration tests across Lovable's web platform, mobile surface, APIs, cloud infrastructure, and AI pipelines.
- Break our AI before others do: probe LLM integrations for prompt injection, jailbreaks, data leakage, and novel attack vectors unique to AI-generated code running in live products.
- Stress-test user-generated code at scale: identify systemic vulnerabilities introduced when millions of users create and deploy real applications on Lovable.
- Turn findings into action: work directly with engineering to prioritise, remediate, and verify fixes, closing the loop between discovery and resolution.
- Raise the security bar org-wide: run internal red team exercises, contribute to threat modelling, and embed an attacker's mindset across the engineering culture.
- Help make Lovable the most secure AI product in the market.
Our Tech Stack
- Frontend: React and TypeScript
- Backend: Golang and Rust
- Cloud: Cloudflare, GCP, AWS, multiple LLM providers
- DevOps & Tooling: GitHub Actions, Grafana, OTEL, infra-as-code (Terraform)
- Data: Clickhouse, Firestore, Spanner, BigQuery
And we're always exploring what's next!
About your application
Please submit your application in English. It’s our company language, so you’ll be speaking lots of it if you join.
We treat all candidates equally - if you’re interested, please apply through our careers portal.
Create your free OnJob profile to apply — we'll take you to Lovable's application after sign-up. · Posted 29 May 2026.
Penetration Tester at Lovable — questions answered
What does the Penetration Tester role at Lovable pay?
Lovable does not publish a salary on this Penetration Tester listing, so OnJob shows no figure for it rather than an estimate. For what this role pays across the market, the OnJob salary guides aggregate the live listings that do disclose pay.
Where is the Penetration Tester role at Lovable based?
Lovable lists this Penetration Tester role in Stockholm, Stockholm County, Sweden, advertised as full time work at that location. Larger employers sometimes cover several sites under one city name, so confirm the exact office with Lovable before you apply.
Is the Penetration Tester role at Lovable still open?
The Penetration Tester posting at Lovable was open at OnJob's last check of the employer's careers page, having been published on 29 May 2026. OnJob re-checks source listings on each build and marks a role closed once it disappears, but listings can close without notice, so the employer's own page is the final word.
How do you apply for the Penetration Tester role at Lovable?
Apply to the Penetration Tester at Lovable role through OnJob with a free profile: OnJob scores your fit against the listing, shows the skills lowering that score, and submits an ATS-ready profile to Lovable's own application page. Creating a profile is free and needs no card.
Related jobs you can win
Hand-picked roles that match this listing on skills, category and location — each scored to your profile inside OnJob.
Explore more on OnJob
Hiring for a role like this?
Post a job on OnJob and reach AI-matched candidates.