Назад
4 дня назад

Detection Engineer

75 000 - 142 000€
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Ireland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Detection Engineer (Cloud Security): Building and operating high-signal detection systems, automation, and response workflows across Notion’s cloud-native environment with an accent on cloud, identity, endpoint, and SaaS security. Focus on detection-as-code, incident response, threat intelligence, LLM-based security workflows, and measuring coverage, MTTD, and alert quality.

Location: Dublin, Ireland; hybrid

Salary: €75,000–€142,000 per year

Company

Notion provides a collaborative AI workspace for knowledge, projects, meetings, and AI tools.

What you will do

  • Build and tune high-signal detections across cloud, identity, endpoint, and SaaS environments.
  • Contribute to detection platform rule lifecycle management, measurement, and safe rollouts.
  • Build automation for triage, enrichment, investigation, and detection authoring, including LLM-based workflows.
  • Translate threat intelligence and adversary TTPs into detections, telemetry requirements, and response improvements.
  • Participate in investigations, incident response, postmortems, and a shared on-call rotation.
  • Define and track metrics such as coverage, MTTD, and alert quality.

Requirements

  • 3+ years of experience in detection engineering, security operations, incident response, threat hunting, or a related security or software engineering role.
  • Experience writing or tuning production detections and improving signal quality.
  • Working knowledge of a detection or query language such as Sigma, KQL, SPL, YARA-L, EQL, or Panther, or strong SQL or Python skills.
  • Understanding of attacker behavior and MITRE ATT&CK, plus hands-on experience with AWS, GCP, or Azure.
  • Experience using SIEM, EDR, or SOAR tools and writing clear runbooks, design documents, and incident notes.
  • Hybrid work in Dublin, Ireland is required.

Nice to have

  • Experience with purple team, blue team, or adversary emulation exercises.
  • Large-scale SIEM, EDR, or SOAR platform experience and detection-as-code workflows.
  • Experience applying LLMs or agent-style tooling to security workflows or securing AI-enabled systems.
  • Kubernetes or container detection, threat intelligence, malware analysis, or digital forensics experience.
  • Security community contributions or experience at a high-growth startup or AI company.

Culture & Benefits

  • Work on systems protecting trust for millions of Notion users.
  • Collaborate with Engineering, Corporate Security, and Infrastructure teams with broad ownership.
  • Competitive cash compensation, equity, and benefits.
  • Emphasis on craft, durable systems, intellectual curiosity, and practical AI collaboration.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →