3 months ago
Base Salary
$230k - $260k/yr
Responsibilities
- Design and maintain high-signal detections across cloud, identity, endpoints, and SaaS environments.
- Build and improve the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety.
- Develop tooling and automation for triage, enrichment, investigation, and detection authoring, including LLM-based workflows where useful.
- Translate threat intelligence and adversary TTPs into durable detections, telemetry requirements, and response improvements.
- Participate in investigations, incident response, postmortems, and a shared incident-response on-call rotation.
- Define and track metrics such as coverage, MTTD, and alert quality to guide investment decisions.
- Work with Engineering, Corporate Security, and Infrastructure to identify gaps, prioritize investments, and build needed capabilities.
Requirements
- 6+ years of experience in detection engineering, security operations, incident response, or threat hunting.
- Experience building and operating production detections with strong signal quality and sustainable tuning processes.
- Fluency in one or more detection languages such as Sigma, KQL, SPL, YARA-L, EQL, or Panther.
- Offensive security mindset and experience leading purple team, blue team, or adversary emulation exercises.
- Strong cloud security experience in AWS, GCP, or Azure, including identity-focused attack detection.
- Hands-on experience with SIEM, EDR, and SOAR platforms in large-scale environments.
- Ability to communicate through design documents, runbooks, and incident reports and drive projects independently.
- Preferred experience applying LLMs or agent-style tooling to security workflows and securing AI-enabled systems or endpoint tooling.
- Preferred Kubernetes or container detection experience.
- Preferred background in threat intelligence, malware analysis, or digital forensics.
- Contributions to the detection engineering community through research, tooling, or talks are a plus.
- Experience at a high-growth startup or AI company is a plus.
Benefits
- Estimated base salary range of $230,000-$260,000 per year for roles based in San Francisco or New York City.
- Equity and benefits are offered in addition to cash compensation.
- The role is based in San Francisco and is marked onsite.
- Participation in a shared on-call rotation is required.
Tech Stack
Categories
About Notion
Notion blends your everyday work tools into one. Product roadmap? Company wiki? Meeting notes? With Notion, they're all in one place, and totally customizable to meet the needs of any workflow. It's the all-in-one workspace for you, your team, and your whole company. We humans are toolmakers by nature, but most of us can't build or modify the software we use every day — arguably our most powerful tool. Our team at Notion is on a mission to make it possible for everyone to shape the tools that shape their lives.
