Security Engineer, Detection and Response, Dublin
Core
Design and maintain high-signal detections across cloud, identity, endpoints, and SaaS environments to detect and respond to attacks in Notion's cloud-native environment.
Role type
Senior Detection Engineer (Cloud Security & Incident Response)
Builds
Production detection systems, rule lifecycle management platforms, and automation tooling for triage and investigation.
Domain
Cloud Security, Threat Detection, Incident Response
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Detection engineering, incident response, threat hunting, cloud security (AWS/GCP/Azure), SIEM/EDR/SOAR operations, detection languages (Sigma/KQL/SPL/YARA-L/EQL/Panther), offensive security mindset, telemetry design
Preferred skills
LLM/agent tooling for security workflows, AI system security, Kubernetes/container detection, threat intelligence, malware analysis, digital forensics
Technologies
AWS, GCP, Azure, Sigma, KQL, SPL, YARA-L, EQL, Panther, SIEM, EDR, SOAR
Responsibilities
Design and maintain high-signal detections across cloud, identity, endpoints, and SaaS environments; Build and improve the detection platform including rule lifecycle management and rollout safety; Develop tooling and automation for triage, enrichment, and investigation; Translate threat intelligence and adversary TTPs into durable detections; Participate in investigations, incident response, and postmortems; Define and track key metrics such as coverage, MTTD, and alert quality
Seniority
Senior, hands-on IC