Role in brief
Notion is seeking a Security Engineer to develop and manage systems for attack detection and response within its cloud environment. This role involves creating high-signal detections, automating security processes, and contributing to incident response. Candidates with experience in detection engineering, cloud security, and an offensive security mindset should consider applying.
About the role
This role focuses on building and refining the mechanisms that identify and respond to security threats within Notion's cloud-native infrastructure. The work involves designing effective detection rules across various environments, including cloud, identity, endpoints, and SaaS applications. A key part of the job is to enhance the detection platform itself, managing the lifecycle of rules from creation to tuning and deployment, ensuring they are robust and accurate.
The Security Engineer will also develop tools and automation to streamline security operations, making incident triage, investigation, and detection authoring more efficient. This includes translating threat intelligence into actionable detections and improving response strategies. Success in this position means consistently improving the company's ability to detect and mitigate attacks, measured by metrics like coverage and alert quality.
Collaboration is central to this role, as the engineer will work with various teams to integrate security measures and participate in incident response activities. This includes contributing to investigations and post-mortems to drive long-term security enhancements. The position requires participation in an on-call rotation to address incidents as they arise, ensuring continuous protection of user trust and company assets.
The estimated base salary for this role ranges from $230,000 to $260,000 per year, specifically for positions based in San Francisco or New York City.
Skills that matter here
- detection engineering: This role requires designing and maintaining high-signal detections across various environments and building the platform that supports them.
- security operations: The engineer will develop tooling and automation to accelerate triage, enrichment, investigation, and detection authoring as part of daily security operations.
- incident response: Participation in investigations, incident response, and postmortems is a core responsibility, including a shared on-call rotation.
- threat hunting: The role involves translating threat intelligence and adversary tactics into durable detections and response improvements.
- cloud security: Strong experience with cloud security in AWS, GCP, or Azure is required, specifically for identity-focused attack detection.
- SIEM: Hands-on experience with SIEM platforms in large-scale environments is necessary for managing and analyzing security data.
Who this role suits
- A person who has spent at least six years working in detection engineering, security operations, incident response, or threat hunting.
- Someone who has successfully built and operated production-level detections, focusing on signal quality and sustainable tuning processes.
- An individual with an offensive security mindset who has led purple team, blue team, or adversary emulation exercises.
- A clear communicator who can drive projects independently, documenting work through design docs, runbooks, and incident reports.
From the employer
- Design and maintain high-signal detections across cloud, identity, endpoints, and SaaS environments.
- Build and improve the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety.
- Develop tooling and automation that accelerate triage, enrichment, investigation, and detection authoring, including LLM-based workflows where useful.
- Translate threat intelligence and adversary TTPs into durable detections, telemetry requirements, and response improvements.
- Participate in investigations, incident response, and postmortems that drive long-term security improvements.
- Define and track key metrics such as coverage, MTTD, and alert quality to guide investment decisions.
- Participate in a shared on-call rotation for incident response.
- Have 6+ years of experience in detection engineering, security operations, incident response, or threat hunting.
- Have built and operated production detections with strong signal quality and sustainable tuning processes.
- Are fluent in one or more detection languages such as Sigma, KQL, SPL, YARA-L, EQL, or Panther.
- Have an offensive security mindset and have led purple team, blue team, or adversary emulation exercises that improved detections and telemetry.
- Have strong cloud security experience in AWS, GCP, or Azure, including identity-focused attack detection.
- Are hands-on with SIEM, EDR, and SOAR platforms in large-scale environments.
- Communicate clearly through design docs, runbooks, and incident reports, and can drive projects independently.
- Notion is committed to providing highly competitive cash compensation, equity, and benefits.
- The estimated base salary range for this role is $230,000 - $260,000 per year for roles based in San Francisco or New York City.
Questions about this role
What is the remote work policy for this role?
This is a remote position, but the listed salary range is specifically for roles based in San Francisco or New York City.
What level of experience is expected for this position?
Candidates should have at least 6 years of experience in relevant fields such as detection engineering, security operations, incident response, or threat hunting.
What are the key technical skills required?
Required skills include experience with detection engineering, cloud security (AWS, GCP, Azure), SIEM, EDR, SOAR platforms, and fluency in detection languages like Sigma, KQL, or SPL.