Application Security Operations Engineer
Notion
About Us:
We're on a mission to make it possible for every person, team, and company to be able to tailor their software to solve any problem and take on any challenge. Computers may be our most powerful tools, but most of us can't build or modify the software we use on them every day. At Notion, we want to change this with focus, design, and craft.
We've been working on this together since 2016, and have customers like Pixar, Mitsubishi, Figma, Plaid, Match Group, and thousands more on this journey with us. Today, we're growing fast and excited for new teammates to join us who are the best at what they do. We're passionate about building a company as diverse and creative as the millions of people Notion reaches worldwide.
About The Role:
Millions of people use Notion — and this number is increasing every day. Our customers depend on us to deliver a secure and trustworthy experience, and we value this more than anything. We want to keep building on that trust, while also continuing to amaze our users with the tools they can build in Notion. This is where you come in — to help us forge a strong, reliable path forward to the future.
Notion is looking for a talented Senior Application Security Operations Engineer with solid communication and analytical skills to help us improve and optimize our security program. We are seeking someone with a mixture of technical ability, attention to detail, and who can function comfortably in a variety of offensive and defensive disciplines. In addition to technical acumen and enthusiasm, we need a self-motivator to stay on top of emerging threats and Application vulnerabilities to Notion; providing a continuous proactive assessments of our platform.
If you're passionate about application security, love hunting for vulnerabilities, while designing creative approaches to provide effective security defenses at scale. This could be just the opportunity you’ve been looking for.
About The Team:
The Notion application is flexible, powerful and always evolving. With a product that needs to scale to meet the needs of many thousands of businesses globally. They rely on us to protect their data and that of their customers.
Notion’s Security team develops and builds processes and tools that allow our Engineering teams to make the right, secure decisions for our customers. We partner with our Engineers and our leadership to ensure we have the right tools and techniques in place to successfully monitor and detect threats to Notion’s infrastructure and platform.
What You'll Achieve:
Help a rapidly growing Security team develop and maintain our Security Operations and Response capabilities. Keep abreast to the latest attacks while using our threat intelligence & vulnerability data to ensure Notion is effectively responding to active and potential threats. You’ll also be working with the broader Security team to tackle complex problems while providing integral data to various pillars of the organization.
- Orchestrate processes through a security information and event management system.
- Maintain, implement, and own various security tools and dashboards.
- Plan for, scope and kick-off penetration testing with 3rd parties in accordance with our compliance program.
- Detect, defend, and respond to threats to Notion and its user base.
- Conduct research and developing new security tools and technologies
- Be a vital part of our vulnerability management program ensuring we’re monitoring and mitigating application layer vulnerabilities which pose a risk to our platform.
- Be a vital part of our responsible disclosure program. Reproduce vulnerabilities, prioritizing, and reporting them to various engineering teams for remediation.
- Foster deep relationships with our Engineering teams to ensure we are monitoring our application and infrastructure effectively.
- At least 3 years working in an application or product security focused role.
Skills You'll Need to Bring:
- Application Security: You have strong experience finding and reproducing bugs in software and are able to show how they can be exploited. You will drive the strategy for AppSecOps engineering in close collaboration with key partners with a pragmatic, risk focused approach.
- Security architecture and expertise: You have experience building systems or tooling to secure and monitor cloud environments ranging from build pipelines to cloud deployment to client/server communication. You can contribute to the security teams codebase and architecture to raise the bar on security systems and tooling design.
- Security Monitoring and Response: You are familiar with attack frameworks and how to use it to identify and close gaps in our detection capabilities. Understanding of SOC disciplines and comfortable working in various roles. You understand the incident response lifecycle completely. You are able to be on an on-call rotation.
- Pragmatic and business-oriented: You care about business impact and prioritize projects accordingly — you model threat risks and balance the right security investments with the right bottom line outcomes.
- Not ideological about technology: To you, technologies and programming languages are about tradeoffs. You may be opinionated, but you're not ideological and can learn new technologies as you go.
- Empathetic communication: You communicate nuanced ideas clearly, whether you're explaining technical decisions in writing or brainstorming in real time. In disagreements, you engage thoughtfully with other perspectives and compromise when needed.
- Team player: For you, work isn't a solo endeavor. You enjoy a team-first, collaborating cross-functionally to accomplish shared goals, and you care about learning, growing, and helping others to do the same.
Nice to Haves:
- Ability to lead projects with little guidance, have worked along with engineering teams in a SaaS environment.
- Infrastructure as code security best practices
- Involvement in local or regional security user groups or conferences would be an added bonus too, but not essential.
We hire talented and passionate people from a variety of backgrounds because we want our global employee base to represent the wide diversity of our customers. If you’re excited about a role but your past experience doesn’t align perfectly with every bullet point listed in the job description, we still encourage you to apply. If you’re a builder at heart, share our company values, and enthusiastic about making software toolmaking ubiquitous, we want to hear from you.
Notion is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Notion considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Notion is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, please let your recruiter know.
Notion is committed to providing highly competitive cash compensation, equity, and benefits. The compensation offered for this role will be based on multiple factors such as location, the role’s scope and complexity, and the candidate’s experience and expertise, and may vary from the range provided below. For roles based in San Francisco or New York City, the estimated range for total on target earnings (including base salary and on target incentive pay) for this role is $180,000 - $200,000 per year.
#LI-Onsite