Notion Logo

Notion

Security Engineer, Detection and Response

Posted An Hour Ago
Be an Early Applicant
Hybrid
New York, NY
230K-260K Annually
Senior level
Hybrid
New York, NY
230K-260K Annually
Senior level
Build and operate high-signal detections across cloud, identity, endpoints, and SaaS. Improve detection platforms, automation, and triage tooling (including LLM-based workflows). Translate threat TTPs into telemetry and detections, participate in incident response/on-call, track metrics like MTTD and alert quality, and drive detection engineering improvements across the org.
The summary above was generated by AI
Who We Are

Notion is the collaborative AI workspace where teams and agents think together. We're building one place where your knowledge, projects, meetings, and AI tools live side by side, so work feels faster, clearer, and less fragmented. Millions of individuals, small teams, and large companies run their work on Notion.

Notinos (our employees) are customer zero in bringing this future of work to life. We care about craft, humanity, and building things that last — not just shipping the next feature, but setting a standard for how modern teams (with humans and agents working together) think and execute.

About The Role

Millions of people rely on Notion to do their most important work, and protecting that trust is foundational to everything we build.

We’re looking for a hands-on Detection Engineer to build and operate the systems and workflows we use to detect and respond to attacks across Notion’s cloud-native environment. You’ll ship high-signal detections, improve the platform that powers them, participate in incident response, and help shape how detection and response engineering scales at Notion.

You’ll work closely with Engineering, Corporate Security, and Infrastructure, with broad latitude to identify gaps, prioritize investments, and build what’s needed next.

We view detection and response as a software engineering discipline: detections are code, platforms are products, and measurement matters

What You'll Achieve
  • Design and maintain high-signal detections across cloud, identity, endpoints, and SaaS environments.

  • Build and improve the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety.

  • Develop tooling and automation that accelerate triage, enrichment, investigation, and detection authoring, including LLM-based workflows where useful.

  • Translate threat intelligence and adversary TTPs into durable detections, telemetry requirements, and response improvements.

  • Participate in investigations, incident response, and postmortems that drive long-term security improvements.

  • Define and track key metrics such as coverage, MTTD, and alert quality to guide investment decisions.

  • Participate in a shared on-call rotation for incident response.

Skills You'll Need to Bring
  • Have 6+ years of experience in detection engineering, security operations, incident response, or threat hunting.

  • Have built and operated production detections with strong signal quality and sustainable tuning processes.

  • Are fluent in one or more detection languages such as Sigma, KQL, SPL, YARA-L, EQL, or Panther.

  • Have an offensive security mindset and have led purple team, blue team, or adversary emulation exercises that improved detections and telemetry.

  • Have strong cloud security experience in AWS, GCP, or Azure, including identity-focused attack detection.

  • Are hands-on with SIEM, EDR, and SOAR platforms in large-scale environments.

  • Communicate clearly through design docs, runbooks, and incident reports, and can drive projects independently.

Nice to Have
  • Experience applying LLMs or agent-style tooling to security workflows.

  • Experience securing AI-enabled systems or endpoint tooling.

  • Kubernetes or container detection experience.

  • Background in threat intelligence, malware analysis, or digital forensics.

  • Contributions to the detection engineering community through research, tooling, or talks.

  • Experience at a high-growth startup or AI company

Notion is committed to providing highly competitive cash compensation, equity, and benefits. The compensation offered for this role will be based on multiple factors such as location, the role’s scope and complexity, and the candidate’s experience and expertise, and may vary from the range provided below. For roles based in San Francisco or New York City, the estimated base salary range for this role is $230,000 - $260,000 per year.

 

By clicking “Submit Application”, I understand and agree that Notion and its affiliates and subsidiaries will collect and process my information in accordance with Notion’s Global Recruiting Privacy Policy and NYLL 144.

 

#LI-Onsite

A Note on AI

You don’t need deep AI expertise for every role, but we do expect every Notino to be intellectually curious, drawn to tinkering and discovery, and excited to use AI as a real collaborator in their work. For some roles, AI fluency is a core requirement — when that’s the case, we’ll make it explicit in the qualifications. People who thrive here don’t treat AI as a novelty. They use it to think better, move faster, and build more creatively.

Equal Opportunity & Accommodations

We hire talented and passionate people from a variety of backgrounds because we want our teams to reflect the wide diversity of our customers. If you’re excited about a role but your experience doesn’t align perfectly with every bullet point listed, we still encourage you to apply.

Notion is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Notion considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Notion is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, please let your recruiter know.

Similar Jobs at Notion

Yesterday
Hybrid
220K-260K Annually
Mid level
220K-260K Annually
Mid level
Artificial Intelligence • Productivity • Software
Build and maintain corporate security controls across identity, endpoints, and SaaS. Harden IAM (Okta, Google Workspace), run endpoint security for a macOS-first fleet, secure AI tool usage, reduce SaaS risk with SSPM and automation, and write Python/Terraform to automate access reviews, onboarding/offboarding, and audit evidence. Partner with Detection & Response and support SOC 2/ISO 27001 compliance and corporate incident response.
Top Skills: Ai AgentsChromeosEdrGoogle WorkspaceIso 27001Large Language ModelsmacOSMdmModel Context Protocol (Mcp)OauthOktaPhishing-Resistant MfaPythonSaaSScimScm (Audit/Telemetry)Soc 2SsoSspmTerraformWindows
Yesterday
Hybrid
175K-225K Annually
Mid level
175K-225K Annually
Mid level
Artificial Intelligence • Productivity • Software
As a Solutions Consultant at Notion, you will help customers optimize their use of the platform through tailored solutions, project management, and change management strategies to ensure successful implementation and adoption of Notion.
Top Skills: Api IntegrationsData Migration ToolsSaas Platforms
Yesterday
Hybrid
136K-155K Annually
Mid level
136K-155K Annually
Mid level
Artificial Intelligence • Productivity • Software
The AI Conversation Designer will create and maintain AI customer support experiences, focusing on chatbot dialogue, QA processes, and integrations, using analytics and best practices.
Top Skills: AdaDecagonGenerative AiPythonSierraSQL

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account