Application Security Engineer
Notion
Job Overview
Who's the hiring manager?
Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Job Description
About Notion
Notion helps you build beautiful tools for your life’s work. In today's world of endless apps and tabs, Notion provides one place for teams to get everything done, seamlessly connecting docs, notes, projects, calendar, and email—with AI built in to find answers and automate work. Millions of users, from individuals to large organizations like Toyota, Figma, and OpenAI, love Notion for its flexibility and choose it because it helps them save time and money.
In-person collaboration is essential to Notion's culture. We require all team members to work from our offices on Mondays, Tuesdays, and Thursdays, our designated Anchor Days. Certain teams or positions may require additional in-office workdays.
About The Role
Millions of people use Notion — and this number is increasing every day. Our users depend on us to deliver a secure and trustworthy experience, and we value this more than anything. We want to keep building on that trust, while also continuing to amaze our users with the tools they can build in Notion. This is where you come in — to help us forge a strong, reliable path forward to the future. The Notion application is flexible, powerful and always evolving. With a product that needs to scale to meet the needs of many thousands of businesses globally. They rely on us to protect their data and that of their customers.
Notion is looking for security engineers that have a passion for making it as easy as possible for developers to write secure code. As an Application Security Engineer you will be a consultant, advocate and builder that is hyper focused on preventing and eliminating software vulnerabilities across Notion's product suite.
What You'll Achieve
- As an early member of Notion’s Application Security team, you will have a large input in defining the direction and goals of the program.
- Make the secure path the easy path for product teams by providing design guidance and finding solutions that eliminate classes of vulnerabilities.
- Create static and dynamic analysis rules that detect weaknesses in our codebase.
- Provide developers guidance and education on security and privacy best practices that prevent the authoring of vulnerabilities.
- Participate in and drive mitigation strategies during AppSec related incident responses.
- Build and maintain tools that prevent vulnerabilities or automate remediation.
Skills You'll Need To Bring
- Security Architecture expertise: You have at least 3+ years of experience working with product teams to design and/or build secure software.
- Thoughtful problem-solving: For you, problem-solving starts with a clear and accurate understanding of the context. You can decompose tricky problems and work towards a clean solution, by yourself or with teammates. You're comfortable asking for help when you get stuck.
- Ability to advocate for and lead cross functional projects: You regularly advocate for security hardening projects that you then lead by partnered with product engineering teams to improve the security story of the products you are responsible to secure.
- Pragmatic and business-oriented: You care about business impact and prioritize projects accordingly — As a product security expert you communicate and facilitate understand of the threat model and risks with the goal to balance the right security investments with the right bottom line outcomes.
- Empathetic communication: You communicate nuanced ideas clearly, whether you're explaining technical decisions in writing or brainstorming in real time. In disagreements, you engage thoughtfully with other perspectives and compromise when needed.
- Startup mentality: You are comfortable navigating the fast moving, unstructured nature of a hyper-growth startup. You are self-motivated to add value and bias towards action.
- You don’t need to be an AI expert, but you’re curious and willing to adopt AI tools to work smarter and deliver better results
Nice To Haves
- Participation in bug bounty programs or capture the flag exercises
- Published reports of vulnerabilities you have found or AppSec related blog posts
- Involvement in local or regional security user groups or conferences
Key skills/competency
- Application Security
- Security Architecture
- Vulnerability Management
- Secure Software Development
- Threat Modeling
- Static Analysis (SAST)
- Dynamic Analysis (DAST)
- Incident Response
- Developer Education
- Security Automation
How to Get Hired at Notion
- Research Notion's culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor.
- Highlight Application Security Expertise: Customize your resume to showcase 3+ years in secure software design, vulnerability prevention, and security architecture.
- Emphasize Problem-Solving & Leadership: Provide examples of decomposing complex security problems and leading cross-functional projects with product teams.
- Demonstrate Pragmatism & Business Acumen: Illustrate how you balance security investments with business outcomes and communicate risks effectively.
- Prepare for Behavioral Questions: Practice articulating your empathetic communication style and comfort navigating a fast-paced, startup environment.
Frequently Asked Questions
Find answers to common questions about this job opportunity
Explore similar opportunities that match your background