Security Engineer, Detection and Response, San Francisco
NotionSan Francisco, CA · Remote · full time · Senior
$230,000 – $260,000
Listed on Notion’s own careers site. You apply with them directly — we never stand between you and the employer.
What this role is
Notion is hiring a hands-on detection engineer to build and operate systems that identify and respond to attacks across their cloud infrastructure. The role suits security engineers with strong detection platform experience who want to blend offensive and defensive thinking in a fast-growing company.
Our summary, not Notion’s wording. The full posting is on their site.
Skills this role names
Log in to see which of these are already on your profile.
What they ask for
Required
- 6+ years in detection engineering, security operations, incident response, or threat hunting
- Built and operated production detections with strong signal quality
- Fluent in at least one detection language (Sigma, KQL, SPL, YARA-L, EQL, or Panther)
- Offensive security mindset and experience with purple team or adversary emulation
- Strong cloud security experience in AWS, GCP, or Azure with identity-focused attack detection
- Hands-on experience with SIEM, EDR, and SOAR platforms at scale
- Clear communication through design docs, runbooks, and incident reports
Nice to have
- Experience applying LLMs or agent-style tooling to security workflows
- Experience securing AI-enabled systems or endpoint tooling
- Kubernetes or container detection experience
- Background in threat intelligence, malware analysis, or digital forensics
- Contributions to detection engineering community through research, tooling, or talks
- Experience at a high-growth startup or AI company