Security Engineer, Detection and Response Team

4 weeks ago


ireland Notion Full time

About Us:

We're on a mission to make it possible for every person, team, and company to be able to tailor their software to solve any problem and take on any challenge. Computers may be our most powerful tools, but most of us can't build or modify the software we use on them every day. At Notion, we want to change this with focus, design, and craft.

We've been working on this together since 2016, and have customers like Pixar, Mitsubishi, Figma, Plaid, Match Group, and thousands more on this journey with us. Today, we're growing fast and excited for new teammates to join us who are the best at what they do. We're passionate about building a company as diverse and creative as the millions of people Notion reaches worldwide.

Notion is an in-person company, and currently requires its employees to come to the office for two Anchor Days (Mondays & Thursdays) and requests that employees spend the majority of their week in the office (including a third day).

About The Role:

Millions of people use Notion - and this number is increasing every day. Our users depend on us to deliver a secure and trustworthy experience, and we value this more than anything. We want to keep building on that trust, while also continuing to amaze our users with the tools they can build in Notion. This is where you come in - to help us forge a strong, reliable path forward to the future.

Notion is looking for a talented Security Engineer with solid communication and analytical skills to help us improve and optimize our security monitoring program. We are seeking someone with a mixture of technical ability, attention to detail, and who can function comfortably in a variety of cyber security disciplines. In addition to technical acumen and enthusiasm, we need a self-motivator to stay on top of emerging threats and vulnerabilities to Notion; providing a continuous proactive monitoring approach.

If you're passionate about data privacy and Security, understand the security monitoring process, and enjoy designing creative approaches to provide effective security monitoring at scale. This could be just the opportunity you've been looking for.

The Notion application is flexible, powerful and always evolving. With a product that needs to scale to meet the needs of many thousands of businesses globally. They rely on us to protect their data and that of their customers.

Notion's Security team builds and evolves our detection, response, and security automation capabilities to protect our users and data. We proactively monitor, detect, and investigate threats across Notion's cloud-native environment, ensuring a resilient security posture. We partner closely with Engineering, Infrastructure, and Security leadership to continuously enhance our ability to respond to emerging threats at scale.

What You'll Achieve:

  • Lead detection engineering efforts, designing scalable, high-fidelity security detections across cloud, endpoint, and application environments.
  • Develop automation & orchestration solutions to improve response and containment times and enhance security workflows.
  • Own and drive incident response and command, leading major security incidents, containment, and remediation efforts.
  • Conduct proactive threat hunting, leveraging threat intelligence and hypothesis-driven methodologies to detect hidden adversary activity.
  • Reverse-engineer attacks, analyzing adversary behavior and developing robust detection strategies.
  • Continuously improve security defenses, applying lessons learned from incidents, hunting exercises, and emerging threat trends.

Skills You'll Need to Bring:

  • 5+ years of experience in security detection, response, or related fields.

Detection Engineering & Automation

  • Strong ability to write, tune, and optimise detections across various platforms (e.g., EDR, SIEM, network monitoring).
  • Proficiency in scripting and automation (Python, Go, or similar) to enhance detection and response capabilities.
  • Experience with detection rule development (Sigma, YARA, Splunk SPL, KQL) and security event correlation.

Incident Response

  • Deep expertise in the incident response lifecycle, including investigation, containment, remediation, and recovery.
  • Lead security incidents and command response efforts, ensuring rapid containment and mitigation-even in unfamiliar environments and across team boundaries.
  • Lead post-incident learning, conducting blameless postmortems and driving follow-up actions that address systemic issues and prevent recurrence.

Cloud Security

  • Experience securing cloud-native environments (AWS, GCP, or Azure), including detection and response strategies for cloud workloads.
  • Practical knowledge of detecting malicious activity in application and infrastructure architectures in a SaaS environment.
  • Ability to assess security gaps and propose detection & response improvements across cloud and endpoint platforms.

Collaboration & Communication

  • Pragmatic and business-oriented: You focus on high-impact security efforts, balancing security investments with real-world risk.
  • Not ideological about technology: You see technologies and programming languages as tools with tradeoffs-you're opinionated but adaptable, always willing to learn new technologies.
  • Empathetic communication: You clearly articulate complex security issues, whether in technical discussions or executive briefings. You engage thoughtfully in disagreements and find common ground when needed.
  • Team player: You thrive in a team environment, collaborating cross-functionally to accomplish shared security goals. You care about mentorship, learning, and continuous improvement.

Nice to Haves:

  • Experience leading large-scale security initiatives or driving security automation programs.
  • Background in red teaming, adversary emulation, or offensive security.
  • Familiarity with application-level detections, such as database security monitoring, detecting malicious queries, or abnormal application behavior.
  • Familiarity with security compliance standards (SOC 2, ISO 27001), though not a primary focus.
  • Involvement in the security community, such as conference presentations or open-source contributions.

We encourage you to apply even if you don't meet every single qualification. The right candidate is more than a checklist-we're looking for curious, security-minded individuals who are excited about Detection & Response. If you're passionate about security and eager to grow, we'd love to hear from you

Our customers come from all walks of life and so do we. We hire great people from a wide variety of backgrounds, not just because it's the right thing to do, but because it makes our company stronger. If you share our values and our enthusiasm for small businesses, you will find a home at Notion.

Notion is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Notion considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Notion is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, please let your recruiter know.

By clicking "Submit Application", I understand and agree that Notion and its affiliates and subsidiaries will collect and process my information in accordance with Notion's Global Recruiting Privacy Policy.

#LI-Onsite

#J-18808-Ljbffr

  • ireland airbnb, Inc. Full time

    Senior Security Engineer, Threat Detection and ResponseAirbnb was born in 2007 when two Hosts welcomed three guests to their San Francisco home, and has since grown to over 4 million Hosts who have welcomed more than 1 billion guest arrivals in almost every country across the globe. Every day, Hosts offer unique stays and experiences that make it possible...


  • ireland Airbnb Full time

    Airbnb was born in 2007 when two Hosts welcomed three guests to their San Francisco home, and has since grown to over 4 million Hosts who have welcomed more than 1 billion guest arrivals in almost every country across the globe. Every day, Hosts offer unique stays and experiences that make it possible for guests to connect with communities in a more...

  • Senior Detection

    4 weeks ago


    ireland Expel Full time

    Imagine yourself as a SOC analyst and a new alert shoots to the top of the queue. You open the alert and all of the relevant facts are laid out for you. You know the who, the what, and the where of what happened and it’s all right there in the alert. You notice the attacker IP immediately and wonder, “Where is that IP located?”. Wonder no more because...


  • ireland Google Full time

    Minimum qualifications:Bachelor's degree or equivalent practical experience.2 years of experience with security assessments or security design reviews or threat modeling.2 years of experience with security engineering, computer and network security and security protocols.2 years of coding experience in one or more general purpose languages.Preferred...

  • Senior Detection

    4 weeks ago


    ireland nineDots.io Full time

    Direct message the job poster from nineDots.ioTech Recruiter | Plant Whisperer | Heavy Metal Addict @ nineDots.ioLooking for a role where you can shape the future of security operations? Want to work in a company that truly cares about its people and the tech they build? This might be the opportunity you’ve been waiting for.You can join a talented security...


  • ireland Google Full time

    Minimum qualifications:Bachelor's degree or equivalent practical experience.5 years of experience in incident response or emergency management.2 years of experience as a technical security professional, with digital forensics or systems administration.Experience with executive or customer stakeholder management and communication.Experience with a data-driven...


  • ireland Amazon Full time

    Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats such as malware and intrusion attempts, and provide security services to safeguard...


  • ireland Sumitomo Mitsui Financial Group, Inc. Full time

    SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 130 offices and 80,000 employees worldwide in nearly 40 countries. Sumitomo Mitsui Financial Group,...


  • ireland Amazon Full time

    Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats such as malware and intrusion attempts, and provide security services to safeguard...

  • Security Engineer 4

    4 weeks ago


    ireland Oracle Full time

    Job DescriptionWe are seeking a Detection Engineer to enhance our SaaS cloud security posture by developing, optimizing, and automating threat detection and response capabilities. This role involves designing and implementing detection-as-code, leveraging cloud-native security tools, and collaborating with security operations and engineering teams to...


  • ireland Amazon Full time

    Come and build innovative services that protect our cloud from advanced security threats!As a Security Engineer on our team, you'll help build and manage services that detect and automate the mitigation of cybersecurity threats across Amazon's infrastructure, including advanced persistent threats. You'll work with data scientists, software development...


  • ireland Amazon Full time

    Come and build innovative services that protect our cloud from advanced security threats!As a Senior Security Engineer on our team, you'll help build and manage services that detect and automate the mitigation of cybersecurity threats across Amazon's infrastructure, including advanced persistent threats. You'll work with data scientists, software development...

  • Security Engineer

    4 weeks ago


    ireland State Street Corporation Full time

    Job DescriptionWho we are looking forThe Red Team Engineer will perform as a member of the Offensive Security team within the Global Cyber Security group and will serve as a technical resource for penetration testing as well as an advisor on technical matters involving the security of information systems.The Red Team Engineer will conduct comprehensive...


  • ireland Amazon Full time

    AWS Managed Services (AMS) Security is looking for technical Security Engineers that are passionate about learning new concepts and work well within a team environment to keep customers secure. We value engineers that can work through ambiguity to identify suspicious activity, lead security response, and can explain technical security concepts to...


  • ireland Microsoft Full time

    In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day and we need you as a Network Security Service Engineer.Microsoft's Cloud Operations & Innovation (CO+I) is the engine that powers our cloud services. As a Network Security Service Engineer, you...


  • ireland Expel Full time

    You know that NOP sleds don’t go down snowbanks, and that IR isn’t just on the electromagnetic spectrum. In fact, you’ve owned a few boxes with Metasploit, maybe even tinkered with exploit code. You were really excited the first time you got a reverse shell. Meterpreter might be your payload of choice, maybe even Beacon. You have a lab where you’re...


  • ireland Squarespace Full time

    Squarespace is looking for a Security Engineer with a focus on Investigations and Incident Response to join a dedicated team responsible for monitoring and responding to attacks on our platform. You'll partner with teams across the organization as you investigate security events specific to our platform and corporate environment.This is a hybrid role working...

  • Apprentice Fire

    3 weeks ago


    ireland Johnson Controls Full time

    Job SummaryAre you excited to kickstart your career in the dynamic realm of fire and security systems? Join Johnson Controls, a global frontrunner in the fire and security sector, and play a vital role in crafting safer environments for our diverse clientele!What You'll Do at WorkEmbark on a thrilling journey as you install, commission, and maintain...


  • ireland Tree Trust Full time

    Global IT, Security, & Business Systems, Amsterdam, Netherlands / Dublin, IrelandSurveyMonkey is the world’s most popular platform for surveys and forms, built for business—loved by users. We combine powerful capabilities with intuitive design, effectively serving every use case, from customer experience to employee engagement, market research to payment...


  • ireland Dell, Inc. Full time

    Senior Consultant, Cyber Incident Response CommanderThe Dell Security & Resiliency organization manages the security risk across all aspects of Dell's business. We are currently experiencing incredible growth in order to meet the security needs of the world's largest technology company. With team members located in over 15 countries, you will have an...