18 hours ago
Dublin, IrelandMid Level
Responsibilities
- Build and tune high-signal detections across cloud, identity, endpoint, and SaaS environments.
- Contribute to detection platform rule lifecycle management, tuning, measurement, and rollout safety.
- Build tooling and automation for triage, enrichment, investigation, and detection authoring, including LLM-based workflows where useful.
- Translate threat intelligence and adversary tactics and techniques into detections, telemetry requirements, and response improvements.
- Participate in investigations, incident response, postmortems, and a shared incident-response on-call rotation.
- Define and track metrics including detection coverage, mean time to detect, and alert quality.
- Own well-scoped security engineering projects end to end and collaborate with Engineering, Corporate Security, and Infrastructure.
Requirements
- 3+ years of experience in detection engineering, security operations, incident response, threat hunting, or a closely related security or software engineering role.
- Production experience writing or tuning detections with a focus on signal quality and reducing noise.
- Working knowledge of at least one detection or query language, such as Sigma, KQL, SPL, YARA-L, EQL, or Panther, or strong SQL or Python skills with the ability to learn one quickly.
- Understanding of attacker behavior, such as MITRE ATT&CK, and the ability to use it to determine detection priorities.
- Hands-on experience with AWS, GCP, or Azure, ideally including identity and access logs.
- Experience using SIEM, EDR, or SOAR tools in an environment of any size.
- Ability to write clearly in runbooks, design documents, and incident notes.
- Preferred qualifications include leading purple-team, blue-team, or adversary-emulation exercises; operating SIEM, EDR, or SOAR platforms at scale; and building detection-as-code workflows.
- Preferred experience includes applying LLMs or agent-style tooling to security workflows, securing AI-enabled systems or endpoint tooling, Kubernetes or container detection, threat intelligence, malware analysis, digital forensics, and security community contributions.
Benefits
- Competitive cash compensation, equity, and benefits are offered.
- Estimated base salary range is €75,000–€142,000 per year.
- The role includes participation in a shared on-call rotation for incident response.
Categories
About Notion
Notion builds an all-in-one workspace that combines docs, wikis, databases, and project management with collaborative AI features for individuals and teams. It operates a freemium, subscription-based, land‑and‑expand model used from small groups to large enterprises. Founded in 2016 and headquartered in San Francisco, the privately held company focuses on unifying knowledge, projects, and workflows in a customizable platform.
