Skip to content
← Back to job listings

Security Engineer (Detection and Response)

Notion · Ireland

RemoteImported listingfull-time18 days ago

About The Role

Join Notion, a company trusted by millions for their important work. As a Security Engineer focused on Detection and Response, you will build and operate systems to detect and respond to attacks in Notion's cloud-native environment. You will work closely with various teams, participate in incident response, and help shape the future of detection and response engineering at Notion.

  • Design and maintain high-signal detections across cloud, identity, endpoints, and SaaS environments.
  • Build and improve the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety.
  • Translate threat intelligence and adversary TTPs into durable detections, telemetry requirements, and response improvements.
  • Are fluent in one or more detection languages such as Sigma, KQL, SPL, YARA-L, EQL, or Panther
  • Communicate clearly through design docs, runbooks, and incident reports, and can drive projects independently
  • Have strong cloud security experience in AWS, GCP, or Azure, including identity-focused attack detection
  • Are hands-on with SIEM, EDR, and SOAR platforms in large-scale environments
  • Have 6+ years of experience in detection engineering, security operations, incident response, or threat hunting
  • Have an offensive security mindset and have led purple team, blue team, or adversary emulation exercises that improved detections and telemetry
  • Have built and operated production detections with strong signal quality and sustainable tuning processes
  • You don’t need deep AI expertise for every role, but we do expect every Notino to be intellectually curious, drawn to tinkering and discovery, and excited to use AI as a real collaborator in their work
  • We hire talented and passionate people from a variety of backgrounds because we want our teams to reflect the wide diversity of our customers. If you’re excited about a role but your experience doesn’t align perfectly with every bullet point listed, we still encourage you to apply
  • Kubernetes or container detection experience
  • Contributions to the detection engineering community through research, tooling, or talks
  • Experience at a high-growth startup or AI company
  • Experience applying LLMs or agent-style tooling to security workflows
  • Experience securing AI-enabled systems or endpoint tooling
  • Background in threat intelligence, malware analysis, or digital forensics

This is an external listing. JobSpring does not represent or verify the employer. Report this listing