← All open roles

Senior Backend Engineer

Malmö · On-site · Full-time

Own the backend services and APIs that turn a customer’s code into a threat model and carry it through to a fix.

Why this role exists

Oplane is an always-on security expert for AI-first engineering teams. Our biggest focus today is PR Analysis: every pull request reviewed against the customer’s architectural threat model before it merges, with findings and code-level fixes attached rather than a report handed over. Scanners find patterns. Oplane understands the system. That is where we are now, not where we stop, and we ship new capabilities constantly.

You are a senior hire on that backend. There is a working system with paying enterprise customers on it, so you are not starting from a blank repo, but large parts of it are still the first version that got us here and need someone senior to make them hold at scale.

What you’ll own

The backend services and APIs that turn a customer’s code into a threat model and carry it through to a fix. Design, correctness, and the parts of reliability that live in the application layer.

What the job actually is

Design and build the core backend
Python services, clean APIs, and the system design behind turning a customer’s code into a threat model and driving the fix. The analysis itself is AI-driven, so a lot of the interesting design is in orchestrating models reliably, not just moving data around. You own real system design here, not tickets handed to you fully specified.
Build the APIs the product lives or dies by
Oplane only works when it is embedded in a customer’s repos, CI, pull request flow and coding agents. Part of that surface is how external coding agents talk to Oplane and run threat modeling directly. It has to be clean, stable, and hard to break, because other people’s pipelines and agents depend on it.
Make it hold at enterprise scale
Companies with thousands of engineers, large codebases, concurrent analysis, and a lot of sensitive input passing through. You care about throughput, correct handling of customer code and secrets, and failure modes that do not silently drop a finding.
Build the agentic way, because we mean it
This is the most agent-native codebase you are likely to have worked in. Our docs are written for coding agents to read, an agent reviews our pull requests, and we are building for a world where agents write most of the code. You will plan with an agent, build with one, and review with one, every day. We grow through agents rather than headcount, and if that reads as a threat to your craft rather than a multiplier of it, this is the wrong team.
Work close to security
The whole product is about security architecture, and the team lives it, from prompt injection to secure-by-design, as a daily concern rather than an annual audit. You do not have to arrive as a security expert, but security experience is a real plus, and you should want to get good at it, because it is the domain the code is about.

Who this is for

  • Around 10 years building backend systems in production. Depth in APIs, data, and system design matters more than any single language, and Python is a plus rather than a requirement.
  • You think in architecture. You can hold a whole system in your head, see where it will break, own the design calls other people build on, and reason about a service end to end from data model to failure behavior.
  • You can read what an AI agent produces and judge it. A lot of the code here is agent-written, and we need the architectural judgment to catch what it gets subtly wrong and steer it, rather than rubber-stamp it.
  • You already use coding agents seriously in your own work and have opinions about where they help and where they do not. If you have not tried, this is the wrong team.
  • Security experience is a strong plus. AppSec, secure design, working on a security product, or having been the person who reviewed everyone else’s threat model.
  • Startup or scale-up background.
  • Working language is English.

How we work

Small team, ten of us today, real autonomy, and nothing between deciding something and doing it. We are honest about what is hard, including in this ad. We grow through agents rather than headcount, so the job is always to build the system that does the work rather than do the work by hand forever. Nobody here asks permission first. If you see it, do it, and tell us afterwards.

Our mission is to fix software for good. Security expertise should be software rather than a person you book time with, and that is a big enough problem to spend a career on.

What you get

  • A product with paying enterprise customers already running on the code you will own, so your work ships to real usage from week one. Teams like Miro, Tandem Health, Remotive Labs and Lightbringer already run Oplane, and we are SOC 2 certified.
  • Real ownership of the backend, working directly with the founders.
  • Backed by Seed Capital and Icebreaker.vc, with angel investors from Neo4j and Google, including Emil Eifrem. $5.2M seed.
  • Based at our Malmö office, on-site five days a week. This is an in-person engineering team by design, not a distributed one.

How to apply

Tell us about a system you designed and one decision in it you would make differently now. Point us at code if you can.

We value your privacy

We use cookies to make the site work better for you and to analyze traffic. You can accept all cookies, customize your settings, or reject non-essential cookies.