This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Millions of people use Notion — and this number is increasing every day. Our users depend on us to deliver a secure and trustworthy experience, and we value this more than anything. In this role, we are looking for a founding member of an elite security engineering team that is responsible for all aspects of ensuring the security of our platform and users. You will be one of Notion’s foremost security expert, understanding the full attack surface of our product and working with a broad range of teams to secure it.
Job Responsibility:
Help scale the engineering organization and mentor engineers on best practices in secure software design and architecture
enable the growth of Notion’s business by building a secure foundation that earns the trust of Notion’s users
design, implement, and (where possible) automate a software development life cycle that balances good vulnerability and risk detection coverage with developer velocity
act as a liaison for multiple stakeholders across product, engineering, go to market, and security ops / compliance, to guide and prioritize the right security investments
participate in security assessments and advise on on both internal and customer security and privacy needs (e.g. SOC2, ISO 27001, GDPR, penetration testing, enterprise asks)
Requirements:
Security architecture and expertise: experience building systems to secure and monitor cloud architectures
experience in threat modeling
experience securing a cloud-based infrastructure (e.g. AWS)
experience designing a secure development life cycle (design reviews, CI / CD integrations, bug bounty program)
experience in application security consulting
experience in secure library and framework development
experience in vulnerability discovery and response
experience implementing core security features like authentication to detecting and mitigating malicious activity
experience in offensive thinking (e.g. pentesting, red teaming)
experience debugging systems in production
pragmatic and business-oriented
not ideological about technology
empathetic communication
team player
curious and willing to adopt AI tools
Nice to have:
Experience responsible for maintaining continuous controls and participating in audits in relation to customer facing certifications (like SOC2)
experience leading engineering teams with a security focus
experience managing, maintaining, and monitoring systems using technologies like Amazon Web Services, Datadog, Postgres, Redis, Memcached, and Elasticsearch