Why this role exists
Oplane reviews every pull request against a customer’s architectural threat model and returns real findings with fixes. Scanners find patterns. Oplane understands the system. But that only pays off when an engineer can see a finding, understand it, and act on it without a security expert sitting next to them. That moment usually happens where they already are: in GitHub, GitLab and the other tools they live in, as much as in Oplane’s own interface. The product can be right and still fail if the person reading it cannot tell what matters, what to fix, and why.
Today the frontend is built and carried by founders and a small team alongside everything else. It works and customers use it daily, but it needs someone senior who owns it as their craft rather than as a side of the backend.
What you’ll own
The React and TypeScript product that engineers, security leads and compliance people actually look at, and the experience Oplane gives inside GitHub, GitLab and the other tools where most of them already work. How a threat model reads, how a finding is understood, and how someone goes from seeing a risk to fixing it.
What the job actually is
- Own the frontend
- React and TypeScript, built well and living close to the API that feeds it. You are the person who cares that the thing is fast, clear, and does not lie to the user about what the analysis found.
- Make hard security information legible
- Our users range from developers to AppSec to security leadership to compliance, and they do not read a finding the same way. Turning dense architectural risk into something a busy engineer trusts and acts on is the core design and engineering problem of this role.
- Meet developers where they already are
- A majority of our users never really leave GitHub, GitLab and the other UIs they work in, so making Oplane land well there, in the pull request, the checks, the review flow, matters as much as our own web app. The worst outcome is one more dashboard people forget to open, so you make sure the finding and its fix show up in the flow they are already in.
- Set the bar for the frontend as we grow
- Component structure, patterns, and the standards the next engineers inherit. You are early enough that what you build becomes how the frontend is built here.
- Build the agentic way, because we mean it
- This is a deeply agent-native codebase: our docs are written for coding agents to read, an agent reviews our pull requests, and we build for a world where agents write most of the code. You will plan, build and review with agents every day. We grow through agents rather than headcount, and if that reads as a threat to your craft rather than a multiplier of it, this is the wrong team.
Who this is for
- Around 8 years building production frontends, with real depth in React and TypeScript.
- Experience building for surfaces you do not fully control, like GitHub or GitLab apps, PR checks and comments, or embedded UIs, is a strong plus.
- You have owned the quality of an interface people used every day, and you can show it. Point us at something you built.
- You care about how a product reads, not only whether it renders. You do not need to be a designer, you do need judgment about clarity.
- You already use coding agents seriously in your own work. If you have not tried, this is the wrong team.
- Comfortable working close to a technical and security-heavy domain, and curious about it rather than put off by it.
- Startup or scale-up background.
- Working language is English.
How we work
Small team, ten of us today, real autonomy, and nothing between deciding something and doing it. We are honest about what is hard, including in this ad. We grow through agents rather than headcount, so the job is always to build the system that does the work rather than do the work by hand forever. Nobody here asks permission first. If you see it, do it, and tell us afterwards.
Our mission is to fix software for good. Security expertise should be software rather than a person you book time with, and that is a big enough problem to spend a career on.
What you get
- A product with paying enterprise customers using the interface daily, so your work reaches real users immediately. Teams like Miro, Tandem Health, Remotive Labs and Lightbringer already run Oplane, and we are SOC 2 certified.
- Real ownership of the frontend, working directly with the founders.
- Backed by Seed Capital and Icebreaker.vc, with angel investors from Neo4j and Google, including Emil Eifrem. $5.2M seed.
- Based at our Malmö office, on-site five days a week. This is an in-person engineering team by design, not a distributed one.