Notion

Security Operations Engineer, Detection and Response Team

Notion
Apply
7 months ago
Dublin, IrelandSenior
H1B Sponsor

Responsibilities

  • Design and implement scalable, high-fidelity security detections across cloud, endpoint, and application environments.
  • Develop automation and orchestration solutions to improve response, containment, and security workflows.
  • Own and lead major security incidents, including command, containment, and remediation efforts.
  • Conduct proactive, hypothesis-driven threat hunts using threat intelligence to identify hidden adversary activity.
  • Reverse-engineer attacks, analyze adversary behavior, and develop robust detection strategies.
  • Continuously improve security defenses based on incident findings, hunting exercises, and emerging threat trends.
  • Partner with Engineering, Infrastructure, and Security leadership to enhance detection, response, and security automation capabilities.

Requirements

  • 5+ years of experience in security detection, response, or related fields.
  • Ability to write, tune, and optimize detections across EDR, SIEM, and network-monitoring platforms.
  • Proficiency in scripting and automation using Python, Go, or similar languages.
  • Experience developing detection rules with Sigma, YARA, Splunk SPL, and KQL, plus security event correlation.
  • Deep expertise in incident investigation, containment, remediation, recovery, incident command, and post-incident learning.
  • Experience securing cloud-native environments on AWS, GCP, or Azure, including cloud workload detection and response.
  • Practical knowledge of detecting malicious activity in SaaS application and infrastructure architectures.
  • Preferred experience leading large-scale security initiatives or security automation programs.
  • Preferred background in red teaming, adversary emulation, or offensive security.
  • Preferred familiarity with application-level detections, database security monitoring, malicious-query detection, or abnormal application behavior.
  • Preferred familiarity with SOC 2 and ISO 27001.
  • Security community involvement, such as conference presentations or open-source contributions, is a plus.

Benefits

  • In-person collaboration is required on Mondays, Tuesdays, and Thursdays as designated Anchor Days; some teams or positions may require additional in-office days.
  • Equal opportunity employer with reasonable accommodations available for qualified individuals with disabilities and disabled veterans.
Notion

About Notion

501-1,000 employees

Notion blends your everyday work tools into one. Product roadmap? Company wiki? Meeting notes? With Notion, they're all in one place, and totally customizable to meet the needs of any workflow. It's the all-in-one workspace for you, your team, and your whole company. We humans are toolmakers by nature, but most of us can't build or modify the software we use every day — arguably our most powerful tool. Our team at Notion is on a mission to make it possible for everyone to shape the tools that shape their lives.

Contact me