Security Engineer Detection and Response
Notion is an AI workspace for capturing team knowledge, finding answers, and automating work with agents.
Funding history
About Notion
Notion Labs, Inc. operates a collaborative workspace that combines documents, knowledge management, databases, projects, search, and AI-enabled automation. Its developer platform provides an API for connecting workspaces to external tools and automating workflows.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will build and maintain high-signal detections across cloud, identity, endpoint, and SaaS environments. You will improve the detection platform and automate triage, investigation, and detection authoring. You will translate threat intelligence into durable controls, participate in incident response and postmortems, measure coverage and alert quality, and join an on-call rotation.
Requirements
- 6+ years of experience in detection engineering, security operations, incident response, or threat hunting
- Experience building and operating production detections with sustainable tuning processes
- Fluency in Sigma, KQL, SPL, YARA-L, EQL, or Panther
- Experience leading purple-team, blue-team, or adversary-emulation exercises
- Cloud security experience in AWS, GCP, or Azure, including identity-focused attack detection
- Experience with SIEM, EDR, and SOAR platforms in large-scale environments
- Ability to communicate through design documents, runbooks, and incident reports
Responsibilities
- Design and maintain high-signal detections across cloud, identity, endpoint, and SaaS environments
- Build and improve the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety
- Develop tooling and automation for triage, enrichment, investigation, and detection authoring
- Translate threat intelligence and adversary TTPs into detections, telemetry requirements, and response improvements
- Participate in investigations, incident response, and postmortems
- Define and track coverage, MTTD, and alert-quality metrics
- Participate in a shared incident-response on-call rotation
Benefits
- Equity
