The opportunity
Notion helps you build beautiful tools for your life’s work. In today's world of endless apps and tabs, Notion provides one place for teams to get everything done, seamlessly connecting docs, notes, projects, calendar, and email—with AI built in to find answers and automate work.
What you'll do
Harden our identity and access management stack, including Okta and Google: Workspace, with phishing-resistant MFA, strong SSO and SCIM lifecycles, and least-privilege access across SaaS.
Run our endpoint security program across a macOS-first fleet, including MDM,: EDR, and configuration baselines, with working coverage for Windows and ChromeOS.
Secure AI tool usage at the endpoint, including governance of large language: models, AI agents, and model context protocol (MCP) integrations; detect and prevent unauthorized or risky AI service access and data exfiltration through AI-enabled tools.
Reduce SaaS risk at scale through SSPM tooling and custom automation,: including detection of risky OAuth grants, excessive permissions, shadow IT, and configuration drift.
Write code (Python, Terraform) to automate access reviews, onboarding and: offboarding, configuration drift detection, and audit evidence collection.
Partner with Detection & Response to ensure corporate systems produce the: telemetry needed to detect identity, endpoint, and SaaS abuse.
What they're looking for
- Support SOC 2, ISO 27001, and customer audits as a byproduct of good engineering, not a separate workstream.
- Partner with Detection & Response on investigation and response for corporate: security incidents, including phishing, account compromise, lost devices, and BEC.
- Have 5+ years of hands-on experience in corporate security, enterprise: security, or IT security engineering at a cloud-native company.
- Have working knowledge of a major identity provider (Okta, Entra, or Google: Workspace) and the underlying protocols (SAML, OIDC, OAuth 2.0, SCIM).