Security Engineer, Detection and Response
Notion · Remote
- Posted
- 74 days ago
- Last confirmed live
- 1 day ago
What this role involves
The role involves building and operating detection and response systems for Notion's cloud-native environment. Responsibilities include designing high-signal detections, improving the detection platform, developing automation and tooling, and participating in incident response. The ideal candidate has 6+ years of experience in detection engineering, security operations, or incident response, with strong cloud security skills and hands-on experience with SIEM, EDR, and SOAR platforms.
Skills this posting asks for
- detection engineering
- security operations
- incident response
- threat hunting
- sigma
- kql
- spl
- yara-l
- eql
- panther
- offensive security
- purple team
- blue team
- adversary emulation
- cloud security
- aws
- gcp
- azure
- siem
- edr
- soar
- llms
- kubernetes
- container security
Requirements
- 6 years of experience
- Level: senior
From the employer’s posting
WHO WE ARE Notion is the collaborative AI workspace where teams and agents think together https://www.youtube.com/watch?v=vkpYpWfEK5s. We're building one place where your knowledge, projects, meetings, and AI tools live side by side, so work is faster, clearer, and less fragmented. Millions of ind…
Read the full description on Notion’s careers pageApply without filling the form
Approve this role and the application is completed for you, including a résumé tailored to it. You get a confirmation when it lands, and a credit is only spent when a submission is confirmed.
Other roles at Notion
- Software Engineer, New Grad (Dec 2026)Remote
- Software Engineer Intern (Summer 2027)Remote
- Software Engineer Intern (Winter 2027)Remote
- Software Engineer, Collections InfraRemote
- Software Engineer, Infrastructure SecurityRemote
- Software Engineer, AI PlatformRemote