Notion
Security Engineer, Detection and Response
Found: Yesterday
Who We Are
Notion is the collaborative AI workspace where teams and agents think together. We're building one place where your knowledge, projects, meetings, and AI tools live side by side, so work is faster, clearer, and less fragmented. Millions of individuals, small teams, and large companies run their work on Notion.
About The Role
We’re looking for a hands-on Detection Engineer to build and operate the systems and workflows we use to detect and respond to attacks across Notion’s cloud-native environment.
What You'll Achieve
- Design and maintain high-signal detections across cloud, identity, endpoints, and SaaS environments.
- Build and improve the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety.
- Develop tooling and automation that accelerate triage, enrichment, investigation, and detection authoring.
- Translate threat intelligence and adversary TTPs into durable detections, telemetry requirements, and response improvements.
- Participate in investigations, incident response, and postmortems that drive long-term security improvements.
- Define and track key metrics such as coverage, MTTD, and alert quality to guide investment decisions.
- Participate in a shared on-call rotation for incident response.
Skills You'll Need to Bring
- Have 6+ years of experience in detection engineering, security operations, incident response, or threat hunting.
- Have built and operated production detections with strong signal quality and sustainable tuning processes.
- Are fluent in one or more detection languages such as Sigma, KQL, SPL, YARA-L, EQL, or Panther.
- Have an offensive security mindset and have led purple team, blue team, or adversary emulation exercises.
- Have strong cloud security experience in AWS, GCP, or Azure.
- Are hands-on with SIEM, EDR, and SOAR platforms in large-scale environments.
- Communicate clearly through design docs, runbooks, and incident reports.
Nice to Have
- Experience applying LLMs or agent-style tooling to security workflows.
- Experience securing AI-enabled systems or endpoint tooling.
- Kubernetes or container detection experience.
- Background in threat intelligence, malware analysis, or digital forensics.
- Contributions to the detection engineering community through research, tooling, or talks.
Notion is committed to providing highly competitive cash compensation, equity, and benefits. The compensation offered for this role will be based on multiple factors such as location, the role's scope and complexity, and the candidate's experience and expertise, and may vary from the range provided below. The estimated base salary range for this role is €127,000–€142,000 per year.