Notion Logo

Notion

Security Operations Engineer, Detection and Response Team

Posted 2 Hours Ago
Be an Early Applicant
Hybrid
Dublin
Senior level
Hybrid
Dublin
Senior level
Join Notion's Detection and Response team as a Security Operations Engineer, focusing on investigating security events and mentoring junior engineers, ensuring operational excellence in security practices.
The summary above was generated by AI
About Us

We're on a mission to make it possible for every person, team, and company to tailor their software to solve any problem and take on any challenge. Computers may be our most powerful tools, but most of us can’t build or modify the software we use every day. At Notion, we’re changing that through focus, design, and craft.

Since 2016, we’ve worked alongside customers like Pixar, Mitsubishi, Figma, Plaid, Match Group, and thousands more. We’re growing quickly and are excited to welcome teammates who are passionate about building secure, trusted systems for millions of users worldwide.

Notion is an in-person company and currently requires employees to come to our Dublin office for three Anchor Days each week (Mondays, Tuesdays, and Thursdays).

About the Role

Millions of people rely on Notion to do their most important work. Protecting that trust is foundational to everything we build.

Notion is looking for a Security Operations Engineer to join our Detection and Response team. In this role, you will help monitor, investigate, and respond to security events across Notion’s cloud-native and SaaS-focused environment, while serving as the technical and operational lead for Detection and Response in our Dublin office.

This role is well-suited for someone who enjoys hands-on security operations and wants to take on meaningful ownership over investigations, detections, and response workflows over time. Over the course of the year, you will mentor and lead an expanded cast of security engineers in Dublin including the planned hiring and onboarding of additional Security Engineers, while continuing to operate as a senior individual contributor. You’ll work closely with experienced security engineers and analysts globally in a collaborative, high-trust environment that values learning, iteration, and operational excellence.

What You’ll Achieve

You will play a key role in protecting Notion’s systems, users, and employees by responding to security events and improving how we detect and respond to threats at scale.

  • Investigate and respond to security alerts end-to-end, including triage, scoping, containment, remediation, and documentation.

  • Participate in a 24/7 on-call rotation, responding to security alerts and incidents as part of a shared team responsibility.

  • Take ownership of specific detections, log sources, or investigation workflows, ensuring their quality, reliability, and ongoing improvement.

  • Contribute to detection development and tuning, identifying gaps, reducing false positives, and improving signal quality across telemetry sources.

  • Support incident response efforts, working with cross-functional partners to investigate and resolve security incidents.

  • Participate in proactive threat hunting, developing hypotheses based on threat intelligence, attacker behavior, and internal telemetry.

  • Analyze and correlate logs across cloud, identity, endpoint, and SaaS platforms to identify suspicious or anomalous behavior.

  • Improve operational processes and documentation, including runbooks, playbooks, and investigation procedures, to enable consistent execution across a growing team.

  • Provide hands-on coaching and technical guidance to less-experienced responders through investigation reviews, pairing, and real-time incident support.

Skills You’ll Need to Bring

5+ years of experience in security operations, incident response, detection engineering, or a related security role, including experience acting as a technical lead or mentor for other security engineers.

Security Monitoring & Detection
  • Experience triaging and investigating alerts across SIEM, EDR, and cloud-native platforms.

  • Familiarity with detection development and tuning, including rule logic and false-positive reduction.

  • Working knowledge of attacker TTPs and frameworks such as MITRE ATT&CK, and how to detect them using available telemetry.

  • Experience with scripting or automation (e.g., Python, Bash) to streamline investigations or improve analyst workflows.

  • Familiarity with detection logic or query languages such as Sigma, KQL, Splunk SPL, YAML, or YARA.

Incident Response
  • Understanding of the incident response lifecycle, including investigation, containment, eradication, recovery, and lessons learned.

  • Experience supporting real-world security investigations and documenting findings.

  • Ability to collaborate effectively with partners across Security, IT, and Engineering, and provide technical guidance during incidents.

Cloud & SaaS Security
  • Familiarity with cloud environments (e.g., AWS, GCP, Azure) and common security risks.

  • Experience investigating identity and access activity in systems such as Okta, Google Workspace, or cloud IAM platforms.

  • Comfort working with logs from diverse sources, including authentication, endpoint, and infrastructure systems.

Collaboration & Communication
  • Clear and thoughtful communicator who can explain technical issues to varied audiences.

  • Strong documentation skills to support consistent, repeatable incident handling.

  • Comfortable working across teams to solve complex security problems.

On-Call & Operations
  • This role participates in a 24/7 on-call rotation as part of the Detection and Response team.

  • On-call responsibilities include investigating alerts, responding to incidents, supporting less-experienced responders, escalating when appropriate, and following established response procedures.

  • The team continuously works to improve detection quality and operational processes to maintain sustainable on-call practices.

Interview Process

As part of the interview process, candidates will complete a short coding exercise designed to assess problem-solving, logic, and comfort working with data or automation commonly encountered in Detection & Response workflows. The exercise is intended to be practical and lightweight, not algorithm-focused.

Not Sure If You Meet Every Requirement?

We encourage you to apply even if you don’t meet every qualification. We’re looking for curious, security-minded individuals who are excited about Detection & Response and eager to grow their skills while protecting millions of Notion users.

Our customers come from all walks of life and so do we. We hire great people from a wide variety of backgrounds, not just because it's the right thing to do, but because it makes our company stronger. If you share our values and our enthusiasm for small businesses, you will find a home at Notion.

Notion is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Notion considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Notion is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, please let your recruiter know.

Notion is committed to providing highly competitive cash compensation, equity, and benefits. The compensation offered for this role will be based on multiple factors such as location, the role’s scope and complexity, and the candidate’s experience and expertise, and may vary from the range provided below.

Top Skills

AWS
Azure
Bash
Edr
GCP
Kql
Python
SIEM
Sigma
Splunk Spl
Yaml
Yara

Notion Dublin, Dublin, IRL Office

Dublin, Dublin, Ireland, D04 E7K5

Similar Jobs at Notion

2 Days Ago
Hybrid
Dublin, IRL
Mid level
Mid level
Artificial Intelligence • Productivity • Software
Drive customer adoption and retention for Notion, serving as a trusted advisor and helping to build Customer Success foundations. Engage with customers to gather insights for product improvements and conduct onboarding and training sessions.
Top Skills: Notion
2 Days Ago
Hybrid
Dublin, IRL
Senior level
Senior level
Artificial Intelligence • Productivity • Software
As an Account Executive, you will develop new accounts, maintain customer relationships, run product demos, and collaborate with internal teams to drive sales in the Benelux region.
2 Days Ago
Hybrid
Dublin, IRL
Entry level
Entry level
Artificial Intelligence • Productivity • Software
As a Business Development Representative, you will prospect and qualify new enterprise customers in the EMEA region, execute outbound campaigns, maintain CRM records, and collaborate with marketing while learning about the product.

What you need to know about the Dublin Tech Scene

From Bono and Oscar Wilde to today's tech leaders, Dublin has always attracted trailblazers, with more than 70,000 people working in the city's expanding digital sector. Continuing its legacy of drawing pioneers, the city is advancing rapidly. Ireland is now ranked as one of the top tech clusters in the region and the number one destination for digital companies, with the highest hiring intention of any region across all sectors.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account