Security Operations Engineer, Detection and Response Team

Notion Notion · Enterprise · Dublin, Ireland · Security

Security Operations Engineer focused on detection, response, and automation within a cloud-native environment. The role involves designing and implementing advanced detections, automating security workflows, leading incident investigations, and conducting threat hunts. Experience with scripting, cloud security, and incident response lifecycle is required. While not an AI-building role, the candidate is expected to be curious and adopt AI tools.

What you'd actually do

  1. Lead detection engineering efforts, designing scalable, high-fidelity security detections across cloud, endpoint, and application environments.
  2. Develop automation & orchestration solutions to improve response and containment times and enhance security workflows.
  3. Own and drive incident response and command, leading major security incidents, containment, and remediation efforts.
  4. Conduct proactive threat hunting, leveraging threat intelligence and hypothesis-driven methodologies to detect hidden adversary activity.
  5. Reverse-engineer attacks, analyzing adversary behavior and developing robust detection strategies.

Skills

Required

  • Security detection
  • Security response
  • Detection engineering
  • Automation
  • Orchestration
  • Incident response
  • Threat hunting
  • Reverse engineering
  • Cloud security (AWS, GCP, Azure)
  • Scripting (Python, Go)
  • EDR
  • SIEM
  • Network monitoring
  • Sigma
  • YARA
  • Splunk SPL
  • KQL
  • Communication
  • Analytical skills

Nice to have

  • Leading large-scale security initiatives
  • Security automation programs
  • Red teaming
  • Adversary emulation
  • Offensive security
  • Application-level detections
  • Database security monitoring
  • SOC 2
  • ISO 27001

What the JD emphasized

  • 5+ years of experience in security detection, response, or related fields
  • Strong ability to write, tune, and optimize detections
  • Proficiency in scripting and automation (Python, Go, or similar)
  • Deep expertise in the incident response lifecycle
  • Lead security incidents and command response efforts
  • Experience securing cloud-native environments (AWS, GCP, or Azure)