Security Engineer, Detection and Response
Core
Build and operate detection systems and workflows to identify and respond to attacks across Notion's cloud-native environment, focusing on high-signal detections and incident response.
Role type
hands-on detection engineer (cloud security)
Builds
detection platforms, automation tooling, and response workflows for cloud, identity, endpoint, and SaaS environments
Domain
cybersecurity, cloud security, threat detection
Deliverable
production ML models
Required skills
detection engineering, incident response, threat hunting, detection/query languages (Sigma, KQL, SPL, YARA-L, EQL, Panther), SQL, Python, MITRE ATT&CK, cloud platforms (AWS, GCP, Azure), SIEM/EDR/SOAR tools
Preferred skills
purple team/blue team exercises, detection-as-code workflows, LLM/agent tooling for security, Kubernetes/container detection, threat intelligence, malware analysis, digital forensics
Technologies
AWS, GCP, Azure, SIEM, EDR, SOAR, Sigma, KQL, SPL, YARA-L, EQL, Panther, Python, SQL, Kubernetes
Responsibilities
build and tune high-signal detections across cloud, identity, endpoint, and SaaS environments; contribute to detection platform rule lifecycle management and rollout safety; build tooling and automation for triage, enrichment, investigation, and detection authoring; translate threat intelligence and adversary TTPs into detections and response improvements; participate in investigations, incident response, and postmortems; define and track metrics like coverage, MTTD, and alert quality; join shared on-call rotation for incident response
Seniority
Mid-level, hands-on IC
