Skip to content
All jobs

This job comes from Notion careers page, not from an Interstack member. You apply on their site, so Interstack can't track your application or tell you when it has been seen.

N

Security Engineer, Detection and Response

Notion · San Francisco, California

Full time Security Posted 1 week ago

Skills this job asks for

Notion AI agents

About the role

WHO WE ARE Notion is the collaborative AI workspace where teams and agents think together https://www.youtube.com/watch?v=vkpYpWfEK5s. We're building one place where your knowledge, projects, meetings, and AI tools live side by side, so work is faster, clearer, and less fragmented. Millions of individuals, small teams, and large companies run their work on Notion. Notinos (our employees) are customer zero in bringing this future of work to life. We care about craft, building things that last, and the belief that great work is still fundamentally human. Our goal isn’t to ship the next feature. Each and every team of Notinos is working to set the standard for how humans work together in the AI era. From building a business’s system of record to making and managing AI agents to automating away the busy work, we care deeply about giving our customers more time for their life’s work. ABOUT THE ROLE Millions of people rely on Notion to do their most important work, and protecting that trust is foundational to everything we build. We’re looking for a hands-on Detection Engineer to build and operate the systems and workflows we use to detect and respond to attacks across Notion’s cloud-native environment. You’ll ship high-signal detections, improve the platform that powers them, participate in incident response, and help shape how detection and response engineering scales at Notion. You’ll work closely with Engineering, Corporate Security, and Infrastructure, with broad latitude to identify gaps, prioritize investments, and build what’s needed next. We view detection and response as a software engineering discipline: detections are code, platforms are products, and measurement matters WHAT YOU'LL ACHIEVE - Build and tune high-signal detections across cloud, identity, endpoint, and SaaS environments, with review and mentorship from senior teammates as you ramp up. - Contribute to the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety. - Build tooling and automation that speed up triage, enrichment, investigation, and detection authoring, including LLM-based workflows where useful. - Turn threat intelligence and adversary TTPs into detections, telemetry requirements, and response improvements. - Take part in investigations, incident response, and postmortems, and help turn what we learn into lasting fixes. - Help define and track metrics such as coverage, MTTD, and alert quality. - Join a shared on-call rotation for incident response. SKILLS YOU'LL NEED TO BRING - We're hiring across a range of experience levels. If you have some of these skills but not all, we'd still like to hear from you. - 3+ years of experience in detection engineering, security operations, incident response, threat hunting, or a closely related security or software engineering role. - Have written or tuned detections that run in production, and care about signal quality and cutting noise. - Working knowledge of at least one detection or q...

A summary from the original listing. Read the full details on their site.

Apply on Notion's site

Opens in a new tab.

Similar jobs