Detection and Response Team Engineer
NotionAbout the role
About Us:
We're on a mission to make it possible for every person, team, and company to be able to tailor their software to solve any problem and take on any challenge. Computers may be our most powerful tools, but most of us can't build or modify the software we use on them every day. At Notion, we want to change this with focus, design, and craft.
We've been working on this together since 2016, and have customers like Nike, Airbnb, Slack, Samsung and thousands more on this journey with us. Today, we're growing fast and excited for new teammates to join us who are the best at what they do. We're passionate about building a company as diverse and creative as the millions of people Notion reaches worldwide.
About The Role:
Millions of people use Notion — and this number is increasing every day. Our users depend on us to deliver a secure and trustworthy experience, and we value this more than anything. We want to keep building on that trust, while also continuing to amaze our users with the tools they can build in Notion. This is where you come in — to help us forge a strong, reliable path forward to the future.
Notion is looking for a talented Security Engineer with solid communication and analytical skills to help us improve and optimize our security monitoring program. We are seeking someone with a mixture of technical ability, attention to detail, and who can function comfortably in a variety of cyber security disciplines. In addition to technical acumen and enthusiasm, we need a self-motivator to stay on top of emerging threats and vulnerabilities to Notion; providing a continuous proactive monitoring approach.
If you're passionate about data privacy and Security, understand the security monitoring process, and enjoy designing creative approaches to provide effective security monitoring at scale. This could be just the opportunity you’ve been looking for.
The Notion application is flexible, powerful and always evolving. With a product that needs to scale to meet the needs of many thousands of businesses globally. They rely on us to protect their data and that of their customers.
Notion’s Security team develops and builds processes and tools that allow our Engineering teams to make the right, secure decisions for our customers. We partner with our Engineers and our leadership to ensure we have the right tools and techniques in place to successfully monitor and detect threats to Notion
What You'll Achieve:
Help the rapidly growing Security team build, maintain, and evolve our security tool suite. Stay updated on the latest attacks and utilize our threat intelligence and vulnerability data to effectively respond to active & potential adversaries. Additionally, collaborate with the broader Security team to solve complex problems and provide critical data and response capabilities to various pillars of the organization.
- Detect, defend it’s user base, and respond to threats against Notion and its user base
- Assisting with onboarding new data sources into our SIEM, analyze the data for anomalies and trends, and build dashboards highlighting the key trends of the data. Triage and validate security alerts and escalate incidents, as required.
- Automate and Orchestrate processes through advanced security tooling
- Secure cutting edge technology by reproducing bugs identified internally and through our bug bounty program
- Lead investigations and response efforts: escalate and respond to security events following Notion’s incident response procedures.
- Draft communications around observed threats and potentially identified exposures to engineering and security leadership
Skills You'll Need to Bring:
- Security Monitoring and Response: You have experience with MITRE or other attack frameworks and how to use it to identify and close gaps in detection capabilities. You understand the incident response lifecycle completely. You are able to be on an on-call rotation. You are comfortable reverse-engineering attacks through analysis and prototyping meaningful detections to prevent and mitigate threat and abuse actors. You can critically analyze the flow of data, its position within the environment, and how it can be analyzed for detection and protection purposes.
- Security Architecture and Cloud Security expertise: You have 3-5 years of experience building systems to secure and monitor cloud architectures, ranging from build pipelines to cloud deployment to client/server communication. You can contribute to the security operations codebase and architecture to raise the bar on security systems and tooling design.
- Hands-on experience in Security Operations: Managed a vulnerability management program, red- and / or blue-teaming, detection engineering, SIEM and endpoint protection; knowledge of Endpoin
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s