SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer, Detection and Response

Notion - Dublin, Ireland - In-office - posted 2026-09-28

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: EUR 75,000 - 142,000 / annual

Notion is a collaborative AI workspace used by millions of individuals, teams, and companies. The company is hiring a Detection and Response Engineer to build and operate detection and response systems protecting Notion's cloud-native environment. In this role, you will ship high-signal detections, improve the detection platform, participate in incident response, and help scale detection and response engineering at Notion. You'll work closely with Engineering, Corporate Security, and Infrastructure teams with broad latitude to identify gaps and prioritize investments. Key responsibilities include: - Building and tuning high-signal detections across cloud, identity, endpoint, and SaaS environments - Contributing to the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety - Building tooling and automation to speed up triage, enrichment, investigation, and detection authoring, including LLM-based workflows - Translating threat intelligence and adversary TTPs into detections, telemetry requirements, and response improvements - Participating in investigations, incident response, and postmortems to drive lasting fixes - Defining and tracking metrics such as coverage, MTTD, and alert quality - Joining a shared on-call rotation for incident response Notion views detection and response as a software engineering discipline where detections are code, platforms are products, and measurement matters. REQUIREMENTS: - 3+ years of experience in detection engineering, security operations, incident response, threat hunting, or closely related security or software engineering role - Experience writing or tuning detections in production with focus on signal quality and noise reduction - Working knowledge of at least one detection or query language (Sigma, KQL, SPL, YARA-L, EQL, or Panther), or strong SQL or Python skills with drive to learn quickly - Understanding of how attackers operate (e.g., MITRE ATT&CK) and ability to use it to decide what to detect - Hands-on experience with AWS, GCP, or Azure, ideally including identity and access logs - Experience using SIEM, EDR, or SOAR tools in any size environment - Ability to write clearly in runbooks, design docs, and incident notes; can own well-scoped projects end to end NICE TO HAVE: - Led purple team, blue team, or adversary emulation exercises - Experience running SIEM, EDR, or SOAR platforms at large scale - Experience building or maintaining detection-as-code workflows - Experience applying LLMs or agent-style tooling to security workflows - Experience securing AI-enabled systems or endpoint tooling - Kubernetes or container detection experience - Background in threat intelligence, malware analysis, or digital forensics - Security community contributions through research, tooling, CTFs, or talks - Experience at high-growth startup or AI company

Similar roles