Security Engineer, Detection and Response

Hack Chicago

San Francisco (CA)

On-site

USD 230,000 - 260,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Hack Chicago is looking for a Detection Engineer to enhance and manage detection systems in its cloud-native environment. You will collaborate with various teams to build systems that detect and respond to attacks effectively.

The ideal candidate has a minimum of 6 years in detection engineering, strong experience in cloud security (AWS, GCP, Azure), and is fluent in detection languages. The role offers significant autonomy and involvement in shaping detection responses.

Qualifications

  • 6+ years of experience in detection engineering, security operations, incident response, or threat hunting.
  • Experience building and operating production detections with high signal quality.
  • Fluent in one or more detection languages such as Sigma, KQL, or YARA-L.

Responsibilities

  • Design and maintain high-signal detections across various environments.
  • Build and improve the detection platform with effective lifecycle management.
  • Translate threat intelligence into durable detections and improvements.

Skills

Detection engineering experience
Incident response
Threat hunting
Detection languages
Cloud security in AWS, GCP, Azure
SIEM, EDR, SOAR platforms
Communication skills

Job description

About The Role

Millions of people rely on Notion to do their most important work, and protecting that trust is foundational to everything we build.

We’re looking for a hands‑on Detection Engineer to build and operate the systems and workflows we use to detect and respond to attacks across Notion’s cloud‑native environment. You’ll ship high‑signal detections, improve the platform that powers them, participate in incident response, and help shape how detection and response engineering scales at Notion.

You’ll work closely with Engineering, Corporate Security, and Infrastructure, with broad latitude to identify gaps, prioritize investments, and build what’s needed next.

We view detection and response as a software engineering discipline: detections are code, platforms are products, and measurement matters.

What You’ll Achieve
  • Design and maintain high‑signal detections across cloud, identity, endpoints, and SaaS environments.
  • Build and improve the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety.
  • Develop tooling and automation that accelerate triage, enrichment, investigation, and detection authoring, including LLM‑based workflows where useful.
  • Translate threat intelligence and adversary TTPs into durable detections, telemetry requirements, and response improvements.
  • Participate in investigations, incident response, and postmortems that drive long‑term security improvements.
  • Define and track key metrics such as coverage, MTTD, and alert quality to guide investment decisions.
  • Participate in a shared on‑call rotation for incident response.
Skills You’ll Need to Bring
  • Have 6+ years of experience in detection engineering, security operations, incident response, or threat hunting.
  • Have built and operated production detections with strong signal quality and sustainable tuning processes.
  • Are fluent in one or more detection languages such as Sigma, KQL, SPL, YARA‑L, EQL, or Panther.
  • Have an offensive security mindset and have led purple team, blue team, or adversary emulation exercises that improved detections and telemetry.
  • Have strong cloud security experience in AWS, GCP, or Azure, including identity‑focused attack detection.
  • Are hands‑on with SIEM, EDR, and SOAR platforms in large‑scale environments.
  • Communicate clearly through design docs, runbooks, and incident reports, and can drive projects independently.
Nice to Have
  • Experience applying LLMs or agent‑style tooling to security workflows.
  • Experience securing AI‑enabled systems or endpoint tooling.
  • Kubernetes or container detection experience.
  • Background in threat intelligence, malware analysis, or digital forensics.
  • Contributions to the detection engineering community through research, tooling, or talks.
  • Experience at a high‑growth startup or AI company.
Compensation

Notion is committed to providing highly competitive cash compensation, equity, and benefits. For roles based in San Francisco or New York City, the estimated base salary range for this role is $230,000 – $260,000 per year.

A Note on AI

You don’t need deep AI expertise for every role, but we do expect every Notino to be intellectually curious, drawn to tinkering and discovery, and excited to use AI as a real collaborator in their work. For some roles, AI fluency is a core requirement — when that’s the case, we’ll say so explicitly in the qualifications.

Equal Opportunity & Accommodations

Notion is an equal opportunity employer and does not discriminate on the basis of any legally protected characteristic. We will consider qualified applicants with arrest and conviction records, and provide reasonable accommodations during the application process for individuals with disabilities or veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Detection and Response, San Francisco
Security Engineer, Detection and Response, San Francisco

Notion • San Francisco (CA)

On-site
USD 230,000 - 260,000
Highly competitive cash compensation
Equity
Comprehensive benefits
Security Engineer, Detection and Response, San Francisco
Security Engineer, Detection and Response, San Francisco

Monograph • San Francisco (CA)

On-site
USD 230,000 - 260,000
Security Engineer, Detection and Response, San Francisco
Security Engineer, Detection and Response, San Francisco

Intermedia Lab • San Francisco (CA)

On-site
USD 230,000 - 260,000
Competitive cash compensation
Equity
Full benefits
Security Engineer, Corporate Security
Security Engineer, Corporate Security

Apply • New York (NY)

On-site
USD 220,000 - 260,000
Security Engineer, Corporate Security
Security Engineer, Corporate Security

Monograph • San Francisco (CA)

On-site
USD 220,000 - 260,000
Software Engineer, Infrastructure Security
Software Engineer, Infrastructure Security

Notion • New York (NY)

On-site
USD 230,000 - 280,000
Equity
Benefits
Software Engineer, Infrastructure Security
Software Engineer, Infrastructure Security

Monograph • San Francisco (CA)

Hybrid
USD 230,000 - 280,000
Software Engineer, Infrastructure Security
Software Engineer, Infrastructure Security

Notion • San Francisco (CA)

Hybrid
USD 230,000 - 280,000
Software Engineer, Infrastructure Security
Software Engineer, Infrastructure Security

Notion • United States

On-site
USD 230,000 - 280,000
Security Engineer, Corporate Security
Security Engineer, Corporate Security

Notion • New York (NY)

On-site
USD 220,000 - 260,000
Highly competitive salary
Equity and benefits