Why this role exists
Oplane tells enterprise security teams what is wrong with their code. A product that makes that claim cannot itself be flaky, and it cannot silently start missing findings after a change nobody tested the right way. As we ship faster and lean harder on agents to write code, the test system is what keeps us honest, and this role exists to own it fully.
You are that owner, and you are building the function. There is a real test suite and a heavy CI battery already, run by the engineering team alongside everything else, and this role is the first to own test strategy end to end. You take what exists, make it a system you can fully trust, and build out the coverage as the product keeps shipping.
What you’ll own
Everything to do with proving the product does what we say it does, automatically and repeatedly. The test strategy, the automation, and the standard that makes a green build actually mean something.
What the job actually is
- Own test strategy and automation
- We are mostly a Python and TypeScript codebase with a CI battery that already gates every push. You decide what to test, at what level, where the real risk is, and how the whole thing stays fast enough that people trust it instead of routing around it.
- Test the parts that are genuinely hard to test
- Our core behavior is LLM-driven analysis of real, messy pull requests against an architectural threat model, and correctness is not a simple assertion. A large part of the job is eval-style testing: building the harnesses and judgments that prove the product still finds what it should and does not start hallucinating what it should not, run by run and model by model. We already do some of this. You make it rigorous.
- Make quality a system, not a person
- This is a deeply agent-native codebase: much of the code is written with coding agents, and an agent reviews our pull requests. We grow through agents rather than headcount, and that only stays safe if the test system is strong enough to catch what a fast-moving team and its agents get wrong. You build that safety net, keep it trustworthy, and use those same agents to build it.
- Own it end to end, into CI
- Tests that do not run automatically on every change are decoration. You work with the team so the suite runs in CI, stays fast enough to be respected, and fails loudly and clearly when it should.
- Set the bar for how we ship
- What “done” means, when a change is safe to release, and how we keep flakiness from eroding trust in the whole system. You are early enough that this becomes the norm.
Who this is for
- Around 8 years in test automation, and you have built a real automated test system, not just added cases to one someone else designed.
- You are a strong engineer, not a manual tester who scripts occasionally. You write good code and you have opinions about test design.
- You have tested something genuinely hard to pin down, where the correct output was not a fixed value, and you can explain how you approached it.
- You are comfortable with CI and making tests run automatically and fast as part of how the team ships. We are mostly a Python codebase, so being at home there matters.
- You use coding agents seriously in your own work and understand why a team moving this way needs strong tests underneath it.
- Startup or scale-up background, and comfortable owning a function alone.
- Working language is English.
How we work
Small team, ten of us today, real autonomy, and nothing between deciding something and doing it. We are honest about what is hard, including in this ad. We grow through agents rather than headcount, so the job is always to build the system that does the work rather than do the work by hand forever. Nobody here asks permission first. If you see it, do it, and tell us afterwards.
Our mission is to fix software for good. Security expertise should be software rather than a person you book time with, and that is a big enough problem to spend a career on.
What you get
- A product with paying enterprise customers, where the quality you protect is the thing they are paying for. Teams like Miro, Tandem Health, Remotive Labs and Lightbringer already run Oplane, and we are SOC 2 certified.
- Full ownership of test automation, building the function from nothing.
- Backed by Seed Capital and Icebreaker.vc, with angel investors from Neo4j and Google, including Emil Eifrem. $5.2M seed.
- Based at our Malmö office, on-site five days a week. This is an in-person engineering team by design, not a distributed one.