Notion

Security Engineer, Detection and Response

Notion$230K — $260K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years of experience in detection engineering, security operations, incident response, or threat hunting.
  • Proven track record in building and operating production detections with strong signal quality.
  • Fluency in detection languages such as Sigma, KQL, SPL, YARA-L, EQL, or Panther.
  • Experience leading security exercises like purple team or adversary emulation to enhance detections.
  • Strong familiarity with cloud security in AWS, GCP, or Azure, focusing on identity attack detection.
  • Hands-on experience with SIEM, EDR, and SOAR platforms in large-scale environments.
  • Excellent communication skills for producing design docs, runbooks, and incident reports.

Responsibilities

  • Design and maintain high-quality detections across diverse environments.
  • Enhance the detection platform, focusing on rule management and safety in rollout.
  • Create tools and automation to expedite triage, investigation, and detection authoring.
  • Translate threat intelligence into actionable detections and response improvements.
  • Engage in incident investigations and postmortems to bolster overall security.
  • Establish and monitor crucial metrics to inform strategic investment decisions.
  • Participate in an on-call rotation for incident response duties.

Benefits

  • Competitive cash compensation and equity options.
  • Comprehensive health and wellness benefits.
  • Flexible vacation policy to promote work-life balance.
  • Opportunities for professional development and continuous learning.
  • Collaborative and innovative work culture.
Full Job Description
About The Role

Millions of people rely on Notion to do their most important work, and protecting that trust is foundational to everything we build.

We're looking for a hands-on Detection Engineer to build and operate the systems and workflows we use to detect and respond to attacks across Notion's cloud-native environment. You'll ship high-signal detections, improve the platform that powers them, participate in incident response, and help shape how detection and response engineering scales at Notion.

You'll work closely with Engineering, Corporate Security, and Infrastructure, with broad latitude to identify gaps, prioritize investments, and build what's needed next.

We view detection and response as a software engineering discipline: detections are code, platforms are products, and measurement matters

What You'll Achieve
  • Design and maintain high-signal detections across cloud, identity, endpoints, and SaaS environments.
  • Build and improve the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety.
  • Develop tooling and automation that accelerate triage, enrichment, investigation, and detection authoring, including LLM-based workflows where useful.
  • Translate threat intelligence and adversary TTPs into durable detections, telemetry requirements, and response improvements.
  • Participate in investigations, incident response, and postmortems that drive long-term security improvements.
  • Define and track key metrics such as coverage, MTTD, and alert quality to guide investment decisions.
  • Participate in a shared on-call rotation for incident response.
Skills You'll Need to Bring
  • Have 6+ years of experience in detection engineering, security operations, incident response, or threat hunting.
  • Have built and operated production detections with strong signal quality and sustainable tuning processes.
  • Are fluent in one or more detection languages such as Sigma, KQL, SPL, YARA-L, EQL, or Panther.
  • Have an offensive security mindset and have led purple team, blue team, or adversary emulation exercises that improved detections and telemetry.
  • Have strong cloud security experience in AWS, GCP, or Azure, including identity-focused attack detection.
  • Are hands-on with SIEM, EDR, and SOAR platforms in large-scale environments.
  • Communicate clearly through design docs, runbooks, and incident reports, and can drive projects independently.


Nice to Have
  • Experience applying LLMs or agent-style tooling to security workflows.
  • Experience securing AI-enabled systems or endpoint tooling.
  • Kubernetes or container detection experience.
  • Background in threat intelligence, malware analysis, or digital forensics.
  • Contributions to the detection engineering community through research, tooling, or talks.
  • Experience at a high-growth startup or AI company


Notion is committed to providing highly competitive cash compensation, equity, and benefits. The compensation offered for this role will be based on multiple factors such as location, the role's scope and complexity, and the candidate's experience and expertise, and may vary from the range provided below. For roles based in San Francisco or New York City, the estimated base salary range for this role is $230,000 - $260,000 per year.

#LI-Onsite

A Note on AI

You don't need deep AI expertise for every role, but we do expect every Notino to be intellectually curious, drawn to tinkering and discovery, and excited to use AI as a real collaborator in their work. For some roles, AI fluency is a core requirement - when that's the case, we'll make it explicit in the qualifications. People who thrive here don't treat AI as a novelty. They use it to think better, move faster, and build more creatively.

About Notion

Notion is a software company that provides a productivity and collaboration platform for teams. The company's platform offers a range of features, including note-taking, project management, and task tracking. Notion's software is designed to help teams streamline their workflows and improve their productivity. The company was founded in 2016 and is headquartered in San Francisco, California.
Learn more about Notion
Size
300 employees
Industry
Net Income
-$80 million
Founded
2016
Revenue
$80 million
NASDAQ

Similar Jobs

More Jobs at Notion

More Information Technology Jobs

Find similar Security Engineer, Detection and Response jobs: