Notion logo
Notion4 days ago

Security Engineer, Detection and Response

$230,000–$260,000 year

Remote · United States or New York City, New York, United States

Type
Full Time
Level
Senior Level
Education
Not Specified
Company size
Startup

Job Summary

Hands-on Detection Engineer to design and maintain high-signal detections across cloud, identity, endpoints, and SaaS environments; build and improve the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety; develop tooling and automation to accelerate triage, enrichment, investigation, and detection authoring (including LLM-based workflows); translate threat intelligence and adversary TTPs into durable detections and telemetry requirements; participate in investigations, incident response, and postmortems; define and track metrics (coverage, MTTD, alert quality) to guide investments; participate in a shared on-call rotation for incident response; requires 6+ years of experience in detection/security operations/incident response; proficient with Sigma, KQL, SPL, YARA-L, EQL, Panther; strong cloud security in AWS/GCP/Azure; hands-on with SIEM, EDR, SOAR; capable of working independently and communicating via design docs and runbooks.

Required Qualifications

  • 6+ years of experience in detection engineering, security operations, incident response, or threat hunting
  • Built and operated production detections with strong signal quality and sustainable tuning processes
  • Fluent in detection languages such as Sigma, KQL, SPL, YARA-L, EQL, Panther
  • Offensive security mindset and leadership in purple/blue team exercises that improved detections and telemetry
  • Strong cloud security experience in AWS, GCP, or Azure including identity-focused attack detection
  • Hands-on experience with SIEM, EDR, and SOAR platforms in large-scale environments
  • Clear communication through design docs, runbooks, and incident reports, and ability to drive projects independently
Sorce

Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

$230k – $260k / yr

Security Engineer, Detection and Response · Notion

Apply on Sorce