Security Operations Engineer, Detection and Response Team

Notion
Notion
Spain (Hybrid)HybridCompetitiveAdded yesterdayRemote: Hybrid
Notion

Security Operations Engineer, Detection and Response Team

Original Advert

About Us

Notion helps you build beautiful tools for your life's work. In today's world of endless apps and tabs, Notion provides one place for teams to get everything done, seamlessly connecting docs, notes, projects, calendar, and email-with AI built in to find answers and automate work. Millions of users, from individuals to large organizations like Toyota, Figma, and OpenAI, love Notion for its flexibility and choose it because it helps them save time and money.

In-person collaboration is essential to Notion's culture. We require all team members to work from our offices on Mondays, Tuesdays, and Thursdays, our designated Anchor Days. Certain teams or positions may require additional in-office workdays.

About the Role

Notion is looking for a Security Operations Engineer to join our Detection and Response team. In this role, you will help monitor, investigate, and respond to security events across Notion's cloud-native and SaaS-focused environment, while serving as the technical and operational lead for Detection and Response in our Hyderabad office.

This role is well-suited for someone who enjoys hands-on security operations and wants to take on meaningful ownership over investigations, detections, and response workflows over time. Over the course of the year, you will mentor and lead an expanded cast of security engineers in Hyderabad, including the planned hiring and onboarding of additional Security Engineers, while continuing to operate as a senior individual contributor. You'll work closely with experienced security engineers and analysts globally in a collaborative, high-trust environment that values learning, iteration, and operational excellence.

What You'll Achieve

You will play a key role in protecting Notion's systems, users, and employees by responding to security events and improving how we detect and respond to threats at scale.

  • Investigate and respond to security alerts end-to-end, including triage, scoping, containment, remediation, and documentation.

  • Participate in a 24/7 on-call rotation, responding to security alerts and incidents as part of a shared team responsibility.

  • Take ownership of specific detections, log sources, or investigation workflows, ensuring their quality, reliability, and ongoing improvement.

  • Contribute to detection development and tuning, identifying gaps, reducing false positives, and improving signal quality across telemetry sources.

  • Support incident response efforts, working with cross-functional partners to investigate and resolve security incidents.

  • Participate in proactive threat hunting, developing hypotheses based on threat intelligence, attacker behavior, and internal telemetry.

  • Analyze and correlate logs across cloud, identity, endpoint, and SaaS platforms to identify suspicious or anomalous behavior.

  • Improve operational processes and documentation, including runbooks, playbooks, and investigation procedures, to enable consistent execution across a growing team.

  • Provide hands-on coaching and technical guidance to less-experienced responders through investigation reviews, pairing, and real-time incident support.

Skills You'll Need to Bring

7+ years of experience in security operations, incident response, detection engineering, or a related security role, including experience acting as a technical lead or mentor for other security engineers.

Security Monitoring & Detection

  • Experience triaging and investigating alerts across SIEM, EDR, and cloud-native platforms.

  • Familiarity with detection development and tuning, including rule logic and false-positive reduction.

  • Working knowledge of attacker TTPs and frameworks such as MITRE ATT&CK, and how to detect them using available telemetry.

  • Experience with scripting or automation (e.g., Python, Bash) to streamline investigations or improve analyst workflows.

  • Familiarity with detection logic or query languages such as Sigma, KQL, Splunk SPL, YAML, or YARA.

Incident Response

  • Understanding of the incident response lifecycle, including investigation, containment, eradication, recovery, and lessons learned.

  • Experience supporting real-world security investigations and documenting findings.

  • Ability to collaborate effectively with partners across Security, IT, and Engineering, and provide technical guidance during incidents.

Cloud & SaaS Security

  • Familiarity with cloud environments (e.g., AWS, GCP, Azure) and common security risks.

  • Experience investigating identity and access activity in systems such as Okta, Google Workspace, or cloud IAM platforms.

  • Comfort working with logs from diverse sources, including authentication, endpoint, and infrastructure systems.

Collaboration & Communication

  • Clear and thoughtful communicator who can explain technical issues to varied audiences.

  • Strong documentation skills to support consistent, repeatable incident handling.

  • Comfortable working across teams to solve complex security problems.

On-Call & Operations

  • This role participates in a 24/7 on-call rotation as part of the Detection and Response team.

  • On-call responsibilities include investigating alerts, responding to incidents, supporting less-experienced responders, escalating when appropriate, and following established response procedures.

  • The team continuously works to improve detection quality and operational processes to maintain sustainable on-call practices.

Interview Process

As part of the interview process, candidates will complete a short coding exercise designed to assess problem-solving, logic, and comfort working with data or automation commonly encountered in Detection & Response workflows. The exercise is intended to be practical and lightweight, not algorithm-focused.

We hire talented and passionate people from a variety of backgrounds because we want our global employee base to represent the wide diversity of our customers. If you're excited about a role but your past experience doesn't align perfectly with every bullet point listed in the job description, we still encourage you to apply. If you're a builder at heart, share our company values, and enthusiastic about making software toolmaking ubiquitous, we want to hear from you.

Notion is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Notion considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Notion is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation made due to a disability, please let your recruiter know.

By clicking "Submit Application", I understand and agree that Notion and its affiliates and subsidiaries will collect and process my information in accordance with Notion's Global Recruiting Privacy Policy.

#LI-Onsite

Account Executive, Mid-Market

Spain
US$180K - US$230K1d ago

Head of Support, APAC

Spain (Hybrid)
1d ago

AI Solutions Specialist

Spain
US$217K - US$255K1d ago

Corporate Finance, Special Projects

Spain
US$190K - US$220K1d ago

Customer Success Manager, Dedicated, DACH

Spain
1d ago

Staff Accountant

Spain (Hybrid)
US$105K - US$120K1d ago

Help Center Lead

Spain
US$160K - US$180K1d ago

Sales Development Representative, Japan

Spain (Hybrid)
1d ago

Market Development, Startups, Japan (Contract)

Spain
1d ago

GRC Senior Analyst

Spain (Hybrid)
US$180K - US$210K1d ago

Marketing Strategy & Operations Manager, EMEA

Spain
1d ago

Head of Support, AMER

Spain (Hybrid)
US$220K - US$260K1d ago

Director of Revenue Operations

Barcelona, Spain (Hybrid)
1d ago

Senior Technical Program Manager - Travel & Spend

Barcelona, Spain (Hybrid)
1d ago

Senior Product Operations Manager - Payments

Barcelona, Spain (Hybrid)
1d ago
Visa Sponsor

Marketing Operations Manager

Barcelona, Spain (Hybrid)
1d ago
Visa Sponsor

Revenue Operations Analyst - 6 Month Maternity Cover

Barcelona, Spain (Hybrid)
1d ago
Visa Sponsor

Director of Customer Care Operations - US

Barcelona, Spain (Hybrid)
US$151K - US$178K1d ago

Senior Manager, Sales Operations

Barcelona, Spain (Hybrid)
1d ago

Manager, Revenue Strategy & Operations

Barcelona, Spain (Hybrid)
1d ago
Visa Sponsor

Director of Customer Care Operations - EU

Barcelona, Spain (Hybrid)
1d ago
Visa Sponsor

Supply Chain Transportation – BY TMS Solution Architect

Madrid, Spain
1d ago

Operations Manager (m/f/d)

Spain
€38K1d ago

Multi-Site Operations Specialist (m/w/d)

Spain
1d ago

Data Product Partner - Barcelona

Barcelona, Spain (Hybrid)
1d ago
Visa Sponsor

Account Manager DACH

Barcelona, Spain (Hybrid)
1d ago
Visa Sponsor

Director of Customer Care Operations - EU

Barcelona, Spain (Hybrid)
1d ago
Visa Sponsor

Senior Event Sales Specialist - US

Barcelona, Spain (Hybrid)
US$64K - US$75K1d ago
Visa Sponsor

Inside Sales Development Manager - Perk Events

Barcelona, Spain (Hybrid)
1d ago

Sales Development Representative - Spain (internship)

Barcelona, Spain (Hybrid)
1d ago

Director of Revenue Operations

Barcelona, Spain (Hybrid)
1d ago

SDR Growth Markets - Italy and CEE

Barcelona, Spain (Hybrid)
1d ago

Senior Site Reliability Engineer (SRE)

Barcelona, Spain (Hybrid)
1d ago

Sales Development Representative UKI

Barcelona, Spain (Hybrid)
1d ago

Engineering Manager (Financial Platform) - Barcelona

Barcelona, Spain (Hybrid)
1d ago

Staff Product Manager - Billing (VAT)

Barcelona, Spain (Hybrid)
1d ago

Application managed by Notion