security
Posted 3 days agoSecurity Engineer, Detection and Response
at Notion
San Francisco, United StatesRemote
Responsibilities
- - Build and improve the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety.
- - Develop tooling and automation that accelerate triage, enrichment, investigation, and detection authoring, including LLM-based workflows where useful.
Requirements
- We're building one place where your knowledge, projects, meetings, and AI tools live side by side, so work is faster, clearer, and less fragmented.
- Each and every team of Notinos is working to set the standard for how humans work together in the AI era.
- From building a business’s system of record to making and managing AI agents to automating away the busy work, we care deeply about giving our customers more time for their life’s work.
- experience in detection engineering, security operations, incident response, or threat hunting. - Have built and operated production detections with strong signal quality and sustainable tuning processes. - Are fluent in one or more detection languages such as Sigma, KQL, SPL, YARA-L, EQL, or Panther. - Have an offensive security mindset and have led purple team, blue team, or adversary emulation exercises that improved detections and telemetry. - Have strong cloud security
- experience in AWS, GCP, or Azure, including identity-focused attack detection. - Are hands-on with SIEM, EDR, and SOAR platforms in large-scale environments. - Communicate clearly through design docs, runbooks, and incident reports, and can drive projects independently. NICE TO HAVE -
- Experience applying LLMs or agent-style tooling to security workflows. -
- Experience securing AI-enabled systems or endpoint tooling. - Kubernetes or container detection experience. - Background in threat intelligence, malware analysis, or digital forensics. - Contributions to the detection engineering community through research, tooling, or talks. -
Experience
- SKILLS YOU'LL NEED TO BRING - Have 6+ years of