Security Engineer Detection and Response
Notion is an AI workspace for capturing team knowledge, finding answers, and automating work with agents.
Maintainer signals as of 9/25/2026
Funding history
About Notion
Notion Labs, Inc. operates a collaborative workspace that combines documents, knowledge management, databases, projects, search, and AI-enabled automation. Its developer platform provides an API for connecting workspaces to external tools and automating workflows.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will build and tune high-signal detections across cloud, identity, endpoint, and SaaS environments. You will improve the detection platform, develop automation for triage and investigations, translate threat intelligence into detections, participate in incident response and postmortems, track detection metrics, and join an on-call rotation.
Requirements
- 3+ years of experience in detection engineering, security operations, incident response, threat hunting, or a related security or software engineering role
- Experience writing or tuning production detections with attention to signal quality
- Working knowledge of Sigma, KQL, SPL, YARA-L, EQL, Panther, SQL, or Python
- Understanding of attacker operations and MITRE ATT&CK
- Hands-on experience with AWS, GCP, or Azure, including identity and access logs
- Experience using SIEM, EDR, or SOAR tools
- Ability to write runbooks, design documents, and incident notes and own well-scoped projects end to end
Responsibilities
- Build and tune high-signal detections across cloud, identity, endpoint, and SaaS environments
- Contribute to the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety
- Build tooling and automation for triage, enrichment, investigation, and detection authoring
- Turn threat intelligence and adversary TTPs into detections, telemetry requirements, and response improvements
- Participate in investigations, incident response, and postmortems
- Define and track metrics including coverage, MTTD, and alert quality
- Join a shared on-call rotation for incident response
Benefits
- Equity
