← Back to list

Job
Security Engineer, Detection and Response
Security Engineer
• Remote
• Full-time
•
EU/EMEA
As a hands-on Detection Engineer, you'll build and operate the systems and workflows Notion uses to detect and respond to attacks across its cloud-native environment, working closely with Engineering, Corporate Security, and Infrastructure.
Stack
Responsibilities
- ▹Design and maintain high-signal detections across cloud, identity, endpoint, and SaaS environments
- ▹Build and improve the detection platform, including rule lifecycle management, tuning, and rollout safety
- ▹Develop tooling and automation to accelerate triage, enrichment, investigation, and detection authoring, including LLM-based workflows
- ▹Translate threat intelligence and adversary TTPs into durable detections and telemetry requirements
- ▹Participate in investigations, incident response, and postmortems
- ▹Define and track key metrics such as coverage, MTTD, and alert quality
- ▹Participate in a shared on-call rotation for incident response
Requirements
- ▹6+ years of experience in detection engineering, security operations, incident response, or threat hunting
- ▹Track record of building and operating production detections with strong signal quality
- ▹Fluency in one or more detection languages such as Sigma, KQL, SPL, YARA-L, EQL, or Panther
- ▹Offensive security mindset, having led purple team, blue team, or adversary emulation exercises
- ▹Strong cloud security experience in AWS, GCP, or Azure, including identity-focused attack detection
- ▹Hands-on experience with SIEM, EDR, and SOAR platforms at scale
- ▹Clear communication through design docs, runbooks, and incident reports; ability to drive projects independently
Nice to have
- ▹Experience applying LLMs or agent-style tooling to security workflows
- ▹Experience securing AI-enabled systems or endpoint tooling
- ▹Kubernetes or container detection experience
- ▹Background in threat intelligence, malware analysis, or digital forensics
- ▹Contributions to the detection engineering community
- ▹Experience at a high-growth startup or AI company
Soft skills
Independent project ownership and clear written communicationOffensive-minded, proactive problem-solvingCross-team collaboration with Engineering, Corporate Security, and Infrastructure
What we offer
- ▹Estimated base salary: EUR 127,000-142,000 per year
About the company
Notion is the collaborative AI workspace where teams and agents think together — one place for knowledge, projects, meetings, and AI tools. Millions of individuals, small teams, and large companies run their work on Notion.
Similar jobs

Job
Offensive Security Engineer
ClickHouse
Clickhouse
+2
💰 Salary: not specified
🏢 On-site
🗣️ EN

Job
Security Engineer
Stripe
+1
$194,251–$268,400/yr
gross
🌍 Remote
Anywhere in the World
🗣️ EN

Job
Cloud Security Specialist – Detection Engineering
Ubisoft
Azure DevopsCloudformation
+10
💰 Salary: not specified
🏢 On-site
Saint-Mandé
🗣️ EN

Job
Cyber Security - Manager (Engineering)
Riveron
Cloudformation
+7
$130,000–$180,000/yr
gross
🌍 Remote
United States - Remote
🗣️ EN

Job
Offensive Security Engineer
Palantir
+2
💰 Salary: not specified
🏢 On-site
New York
🗣️ EN

Job
Offensive Security Engineer
Palantir
+2
💰 Salary: not specified
🏢 On-site
Washington
🗣️ EN