Security Engineer, Detection and Response, Dublin
Core
Design and maintain high-signal detections across cloud, identity, endpoints, and SaaS environments to detect and respond to attacks in Notion's cloud-native environment.
Role type
Senior Detection Engineer (Cloud Security & Incident Response)
Builds
Production detection systems, rule lifecycle management platforms, and automation tooling for triage and investigation.
Domain
Cloud Security, Threat Detection, Incident Response
Required skills
Detection engineering, incident response, threat hunting, cloud security (AWS/GCP/Azure), SIEM/EDR/SOAR operations, detection languages (Sigma/KQL/SPL/YARA-L/EQL/Panther), offensive security mindset, telemetry design
Preferred skills
LLM/agent tooling for security workflows, AI system security, Kubernetes/container detection, threat intelligence, malware analysis, digital forensics
Technologies
AWS, GCP, Azure, Sigma, KQL, SPL, YARA-L, EQL, Panther, SIEM, EDR, SOAR
Responsibilities
Design and maintain high-signal detections across cloud, identity, endpoints, and SaaS environments; Build and improve the detection platform including rule lifecycle management and rollout safety; Develop tooling and automation for triage, enrichment, and investigation; Translate threat intelligence and adversary TTPs into durable detections; Participate in investigations, incident response, and postmortems; Define and track key metrics such as coverage, MTTD, and alert quality
Seniority
Senior, hands-on IC