Application Security Engineer, AI Security

Notion Notion · Enterprise · San Francisco, CA · Security

Notion is seeking an Application Security Engineer focused on AI Security to consult, advocate, and build solutions to prevent and eliminate security risks in their AI products. The role involves defining security models, performing automated red teaming for AI and agentic features, providing design guidance, and educating developers on security best practices.

What you'd actually do

  1. Help define the security models for Notion’s products as they ship, giving guidance to engineering and product teams to ensure new features meet strict enterprise security requirements.
  2. Perform hands on testing and develop automated red teaming for AI and agentic features, especially focused on AI specific risks like prompt injection.
  3. Make the secure path the easy path for product teams by providing design guidance and finding architectural solutions that eliminate classes of vulnerabilities.
  4. Provide developers guidance and education on security and privacy best practices that prevent the authoring of vulnerabilities; leverage skills, MCP enabled tools, and hooks to help prevent vulnerabilities for developers using agentic coding tools.
  5. Participate in and drive mitigation strategies during AppSec related incident responses.

Skills

Required

  • Security Architecture expertise (6+ years)
  • Thoughtful problem-solving
  • Impact-driven approach to technology
  • Pragmatic and business-oriented
  • Empathetic communication
  • Startup mentality

Nice to have

  • Experience building AI-enabled applications in production (LLMs and/or classical ML), including prompt + tool orchestration, retrieval, evaluation, and iteration based on real-world feedback.
  • Published reports of vulnerabilities you have found or AppSec related blog posts, especially anything AI related
  • Participation in bug bounty programs or capture the flag exercises
  • Involvement in local or regional security user groups or conferences

What the JD emphasized

  • AI specific risks
  • agentic features
  • prompt injection
  • security models
  • automated red teaming

Other signals

  • AI Security
  • AI specific risks
  • agentic features