Security Engineer Detection and Response

Notion is an AI workspace for capturing team knowledge, finding answers, and automating work with agents.

San Francisco, United States
About Notion

Notion Labs, Inc. operates a collaborative workspace that combines documents, knowledge management, databases, projects, search, and AI-enabled automation. Its developer platform provides an API for connecting workspaces to external tools and automating workflows.

View jobs by Notion

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will build and maintain high-signal detections across cloud, identity, endpoint, and SaaS environments. You will improve the detection platform and automate triage, investigation, and detection authoring. You will translate threat intelligence into durable controls, participate in incident response and postmortems, measure coverage and alert quality, and join an on-call rotation.

Requirements

  • 6+ years of experience in detection engineering, security operations, incident response, or threat hunting
  • Experience building and operating production detections with sustainable tuning processes
  • Fluency in Sigma, KQL, SPL, YARA-L, EQL, or Panther
  • Experience leading purple-team, blue-team, or adversary-emulation exercises
  • Cloud security experience in AWS, GCP, or Azure, including identity-focused attack detection
  • Experience with SIEM, EDR, and SOAR platforms in large-scale environments
  • Ability to communicate through design documents, runbooks, and incident reports

Responsibilities

  • Design and maintain high-signal detections across cloud, identity, endpoint, and SaaS environments
  • Build and improve the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety
  • Develop tooling and automation for triage, enrichment, investigation, and detection authoring
  • Translate threat intelligence and adversary TTPs into detections, telemetry requirements, and response improvements
  • Participate in investigations, incident response, and postmortems
  • Define and track coverage, MTTD, and alert-quality metrics
  • Participate in a shared incident-response on-call rotation

Benefits

  • Equity
Security Engineer Detection and Response at Notion | JobStash