# Security Engineer, Detection and Response, San Francisco

Hiring organization: [Notion](https://career.thegoodapps.co/organizations/notion)

Canonical page: https://career.thegoodapps.co/jobs/08f1c671-4040-48a7-b8b8-52d95c98ce92

Listed on Notion's own careers site. Applications go to them directly.

- Employment type: full time
- Seniority: Senior
- Location: San Francisco, CA
- Remote: yes
- Salary: 230000 – 260000 USD per year

## Summary

Notion is hiring a hands-on detection engineer to build and operate systems that identify and respond to attacks across their cloud infrastructure. The role suits security engineers with strong detection platform experience who want to blend offensive and defensive thinking in a fast-growing company.

_Our summary, not Notion's wording._

## Skills named

Amazon Web Services (AWS), Kubernetes, Kusto Query Language (KQL), Microsoft Azure

## Required

- 6+ years in detection engineering, security operations, incident response, or threat hunting
- Built and operated production detections with strong signal quality
- Fluent in at least one detection language (Sigma, KQL, SPL, YARA-L, EQL, or Panther)
- Offensive security mindset and experience with purple team or adversary emulation
- Strong cloud security experience in AWS, GCP, or Azure with identity-focused attack detection
- Hands-on experience with SIEM, EDR, and SOAR platforms at scale
- Clear communication through design docs, runbooks, and incident reports

## Nice to have

- Experience applying LLMs or agent-style tooling to security workflows
- Experience securing AI-enabled systems or endpoint tooling
- Kubernetes or container detection experience
- Background in threat intelligence, malware analysis, or digital forensics
- Contributions to detection engineering community through research, tooling, or talks
- Experience at a high-growth startup or AI company

Apply on Notion's site: https://jobs.ashbyhq.com/notion/c0fcf37b-e00f-4aae-a2e0-b008f9939a7e/application
