Security Engineer, Detection and Response

Notion Notion · Enterprise · San Francisco, CA · Security

This role focuses on building and operating systems for detecting and responding to security threats within Notion's cloud-native environment. The engineer will design and maintain detections, improve the detection platform, develop automation tools (potentially using LLMs), translate threat intelligence into detections, participate in incident response, and define key security metrics. The role emphasizes a software engineering discipline for security, with detections as code and platforms as products.

What you'd actually do

  1. Design and maintain high-signal detections across cloud, identity, endpoints, and SaaS environments.
  2. Build and improve the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety.
  3. Develop tooling and automation that accelerate triage, enrichment, investigation, and detection authoring, including LLM-based workflows where useful.
  4. Translate threat intelligence and adversary TTPs into durable detections, telemetry requirements, and response improvements.
  5. Participate in investigations, incident response, and postmortems that drive long-term security improvements.

Skills

Required

  • 6+ years of experience in detection engineering, security operations, incident response, or threat hunting.
  • Built and operated production detections with strong signal quality and sustainable tuning processes.
  • Fluent in one or more detection languages such as Sigma, KQL, SPL, YARA-L, EQL, or Panther.
  • Offensive security mindset and have led purple team, blue team, or adversary emulation exercises that improved detections and telemetry.
  • Strong cloud security experience in AWS, GCP, or Azure, including identity-focused attack detection.
  • Hands-on with SIEM, EDR, and SOAR platforms in large-scale environments.
  • Communicate clearly through design docs, runbooks, and incident reports, and can drive projects independently.

Nice to have

  • Experience applying LLMs or agent-style tooling to security workflows.
  • Experience securing AI-enabled systems or endpoint tooling.
  • Kubernetes or container detection experience.
  • Background in threat intelligence, malware analysis, or digital forensics.
  • Contributions to the detection engineering community through research, tooling, or talks.
  • Experience at a high-growth startup or AI company

What the JD emphasized

  • production detections with strong signal quality and sustainable tuning processes
  • offensive security mindset
  • cloud security experience
  • SIEM, EDR, and SOAR platforms in large-scale environments