Security Engineer Detection and Response

Notion is an AI workspace for capturing team knowledge, finding answers, and automating work with agents.

Series C0 current maintainers0 active leadsTeam intelligence

Maintainer signals as of 9/25/2026

San Francisco, United States
About Notion

Notion Labs, Inc. operates a collaborative workspace that combines documents, knowledge management, databases, projects, search, and AI-enabled automation. Its developer platform provides an API for connecting workspaces to external tools and automating workflows.

View jobs by Notion

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will build and tune high-signal detections across cloud, identity, endpoint, and SaaS environments. You will improve the detection platform, develop automation for triage and investigations, translate threat intelligence into detections, participate in incident response and postmortems, track detection metrics, and join an on-call rotation.

Requirements

  • 3+ years of experience in detection engineering, security operations, incident response, threat hunting, or a related security or software engineering role
  • Experience writing or tuning production detections with attention to signal quality
  • Working knowledge of Sigma, KQL, SPL, YARA-L, EQL, Panther, SQL, or Python
  • Understanding of attacker operations and MITRE ATT&CK
  • Hands-on experience with AWS, GCP, or Azure, including identity and access logs
  • Experience using SIEM, EDR, or SOAR tools
  • Ability to write runbooks, design documents, and incident notes and own well-scoped projects end to end

Responsibilities

  • Build and tune high-signal detections across cloud, identity, endpoint, and SaaS environments
  • Contribute to the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety
  • Build tooling and automation for triage, enrichment, investigation, and detection authoring
  • Turn threat intelligence and adversary TTPs into detections, telemetry requirements, and response improvements
  • Participate in investigations, incident response, and postmortems
  • Define and track metrics including coverage, MTTD, and alert quality
  • Join a shared on-call rotation for incident response

Benefits

  • Equity