The opportunity
Millions of people rely on Notion to do their most important work, and protecting that trust is foundational to everything we build.
What you'll do
Build and tune high-signal detections across cloud, identity, endpoint, and: SaaS environments, with review and mentorship from senior teammates as you ramp up.
Contribute to the detection platform, including rule lifecycle management,: tuning, measurement, and rollout safety.
Build tooling and automation that speed up triage, enrichment, investigation,: and detection authoring, including LLM-based workflows where useful.
Turn threat intelligence and adversary TTPs into detections, telemetry: requirements, and response improvements.
Take part in investigations, incident response, and postmortems, and help: turn what we learn into lasting fixes.
Help define and track metrics such as coverage, MTTD, and alert quality.
What they're looking for
- Join a shared on-call rotation for incident response.
- We're hiring across a range of experience levels. If you have some of these: skills but not all, we'd still like to hear from you. 3+ years of experience in detection engineering, security operations, incident response, threat hunting, or a closely related security or software engineering role.
- Have written or tuned detections that run in production, and care about signal quality and cutting noise.
- Working knowledge of at least one detection or query language (Sigma, KQL,: SPL, YARA-L, EQL, or Panther), or strong SQL or Python skills and the drive to learn one quickly.