This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Notion is looking for a Security Operations Engineer to join our Detection and Response team. In this role, you will help monitor, investigate, and respond to security events across Notion’s cloud-native and SaaS-focused environment, while serving as the technical and operational lead for Detection and Response in our Hyderabad office.
Job Responsibility:
Investigate and respond to security alerts end-to-end, including triage, scoping, containment, remediation, and documentation
Participate in a 24/7 on-call rotation, responding to security alerts and incidents
Take ownership of specific detections, log sources, or investigation workflows
Contribute to detection development and tuning
Support incident response efforts, working with cross-functional partners
Participate in proactive threat hunting
Analyze and correlate logs across cloud, identity, endpoint, and SaaS platforms
Improve operational processes and documentation
Provide hands-on coaching and technical guidance to less-experienced responders
Requirements:
7+ years of experience in security operations, incident response, detection engineering, or a related security role
Experience acting as a technical lead or mentor for other security engineers
Experience triaging and investigating alerts across SIEM, EDR, and cloud-native platforms
Familiarity with detection development and tuning, including rule logic and false-positive reduction
Working knowledge of attacker TTPs and frameworks such as MITRE ATT&CK
Experience with scripting or automation (e.g., Python, Bash) to streamline investigations
Familiarity with detection logic or query languages such as Sigma, KQL, Splunk SPL, YAML, or YARA
Understanding of the incident response lifecycle
Experience supporting real-world security investigations and documenting findings
Ability to collaborate effectively with partners across Security, IT, and Engineering
Familiarity with cloud environments (e.g., AWS, GCP, Azure) and common security risks
Experience investigating identity and access activity in systems such as Okta, Google Workspace, or cloud IAM platforms
Comfort working with logs from diverse sources
Clear and thoughtful communicator who can explain technical issues to varied audiences
Strong documentation skills
Comfortable working across teams to solve complex security problems