Notion

Security Engineer, Detection and Response

Notion
Apply
18 hours ago
Dublin, IrelandMid Level

Responsibilities

  • Build and tune high-signal detections across cloud, identity, endpoint, and SaaS environments.
  • Contribute to detection platform rule lifecycle management, tuning, measurement, and rollout safety.
  • Build tooling and automation for triage, enrichment, investigation, and detection authoring, including LLM-based workflows where useful.
  • Translate threat intelligence and adversary tactics and techniques into detections, telemetry requirements, and response improvements.
  • Participate in investigations, incident response, postmortems, and a shared incident-response on-call rotation.
  • Define and track metrics including detection coverage, mean time to detect, and alert quality.
  • Own well-scoped security engineering projects end to end and collaborate with Engineering, Corporate Security, and Infrastructure.

Requirements

  • 3+ years of experience in detection engineering, security operations, incident response, threat hunting, or a closely related security or software engineering role.
  • Production experience writing or tuning detections with a focus on signal quality and reducing noise.
  • Working knowledge of at least one detection or query language, such as Sigma, KQL, SPL, YARA-L, EQL, or Panther, or strong SQL or Python skills with the ability to learn one quickly.
  • Understanding of attacker behavior, such as MITRE ATT&CK, and the ability to use it to determine detection priorities.
  • Hands-on experience with AWS, GCP, or Azure, ideally including identity and access logs.
  • Experience using SIEM, EDR, or SOAR tools in an environment of any size.
  • Ability to write clearly in runbooks, design documents, and incident notes.
  • Preferred qualifications include leading purple-team, blue-team, or adversary-emulation exercises; operating SIEM, EDR, or SOAR platforms at scale; and building detection-as-code workflows.
  • Preferred experience includes applying LLMs or agent-style tooling to security workflows, securing AI-enabled systems or endpoint tooling, Kubernetes or container detection, threat intelligence, malware analysis, digital forensics, and security community contributions.

Benefits

  • Competitive cash compensation, equity, and benefits are offered.
  • Estimated base salary range is €75,000–€142,000 per year.
  • The role includes participation in a shared on-call rotation for incident response.
Notion

About Notion

5,001-10,000 employees

Notion builds an all-in-one workspace that combines docs, wikis, databases, and project management with collaborative AI features for individuals and teams. It operates a freemium, subscription-based, land‑and‑expand model used from small groups to large enterprises. Founded in 2016 and headquartered in San Francisco, the privately held company focuses on unifying knowledge, projects, and workflows in a customizable platform.

Contact me