SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer, Corporate Security

Notion - Dublin, Ireland - Hybrid - posted 2026-09-08

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Notion is seeking a hands-on Corporate Security Engineer to own and improve technical controls protecting the company's workforce, employees, and corporate environment. This is a security engineering role focused on building scalable controls and automation across identity, endpoints, SaaS, and workforce infrastructure—not traditional IT support. You will own and evolve core security controls, design systems and automation that scale with the company, and make security both stronger and easier to use. Key responsibilities include: - Harden identity and access management stack (Okta, Google Workspace) with phishing-resistant MFA, strong SSO and SCIM lifecycles, and least-privilege access across SaaS applications. - Run endpoint security program across macOS-first fleet, including MDM, EDR, and configuration baselines, with coverage for Windows and ChromeOS. - Secure AI tool usage at the endpoint, including governance of large language models, AI agents, and model context protocol integrations; detect and prevent unauthorized or risky AI service access and data exfiltration. - Reduce SaaS risk at scale through SSPM tooling and custom automation, detecting risky OAuth grants, excessive permissions, shadow IT, and configuration drift. - Write production-quality code (Python, Terraform) to automate access reviews, onboarding/offboarding, configuration drift detection, and audit evidence collection. - Partner with Detection & Response to ensure corporate systems produce telemetry needed to detect identity, endpoint, and SaaS abuse. - Support SOC 2, ISO 27001, and customer audits as a byproduct of good engineering. - Partner on investigation and response for corporate security incidents including phishing, account compromise, lost devices, and business email compromise. Required experience: 5+ years hands-on corporate security, enterprise security, or IT security engineering at a cloud-native company. Working knowledge of major identity providers (Okta, Entra, Google Workspace) and underlying protocols (SAML, OIDC, OAuth 2.0, SCIM). Hands-on experience with endpoint management and detection tooling across macOS and enterprise environments. Production-quality scripting in Python or Bash, and shipped Terraform or infrastructure-as-code for security configuration. Familiarity with SaaS security risks and vendor integration. Working knowledge of at least one major cloud platform (AWS, GCP, Azure) at security configuration level. Strong written communication and cross-functional collaboration skills. Nice-to-haves: experience at fast-growing tech or AI company, background in IT engineering/SRE/production engineering transitioning to security, experience building internal security tooling, open-source contributions or community engagement.

Similar roles