185K–280K USD / year

Security Engineer, Detection and Response

OtherHybrid — San Francisco, California
Published on 2026-09-28
These details were extracted automatically from the original listing. They may not be complete or fully up to date — it's worth checking the original job post.

About this role

As a Detection Engineer at Notion, you will build and operate systems to detect and respond to security attacks across the cloud environment. Your role includes shipping detections, improving the detection platform, and participating in incident response efforts.

About the company

Notion builds an all-in-one workspace for notes, docs, wikis, and project management. It serves individuals and teams that want connected knowledge and work in one place.

The team

Security

Stack

AWSGCPAzureSIEMEDRSOARPython

What you'll do

  • Build and tune high-signal detections across various environments
  • Contribute to the detection platform
  • Develop tooling and automation for detection workflows
  • Transform threat intelligence into actionable detections
  • Participate in investigations and incident response
  • Define and track metrics for detection quality
  • Join on-call rotation for incident response

What we're looking for

  • 3+ years of experience in detection engineering or related fields
  • Experience writing or tuning production detections
  • Knowledge of detection or query languages
  • Understanding of attacker tactics and frameworks
  • Hands-on experience with major cloud platforms
  • Familiarity with SIEM, EDR, or SOAR tools
  • Strong documentation and project management skills

Nice to have

  • Led purple or blue team exercises
  • Experience with large-scale SIEM or SOAR platforms
  • Detection-as-code workflow experience
  • Leveraged LLMs in security workflows
  • Secured AI-enabled systems or endpoints
  • Kubernetes or container detection experience
  • Background in threat intelligence or malware analysis
View original job post