18 hours ago

Software Engineer, Product Security

Notion

On Site
Full Time
$270,000
New York, NY

Job Overview

Job TitleSoftware Engineer, Product Security
Job TypeFull Time
Offered Salary$270,000
LocationNew York, NY

Who's the hiring manager?

Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Uncover Hiring Manager

Job Description

About Notion

Notion helps you build beautiful tools for your life’s work. In today's world of endless apps and tabs, Notion provides one place for teams to get everything done, seamlessly connecting docs, notes, projects, calendar, and email—with AI built in to find answers and automate work. Millions of users, from individuals to large organizations like Toyota, Figma, and OpenAI, love Notion for its flexibility and choose it because it helps them save time and money.

In-person collaboration is essential to Notion's culture. We require all team members to work from our offices on Mondays, Tuesdays, and Thursdays, our designated Anchor Days. Certain teams or positions may require additional in-office workdays.

About The Role: Software Engineer, Product Security

Millions of people use Notion — and this number is increasing every day. Our users depend on us to deliver a secure and trustworthy experience, and we value this more than anything. In this role, we are looking for a founding member of an elite security engineering team that is responsible for all aspects of ensuring the security of our platform and users. You will be one of Notion’s foremost security expert, understanding the full attack surface of our product and working with a broad range of teams to secure it.

What You'll Achieve

  • Help scale the engineering organization and mentor engineers on best practices in secure software design and architecture.
  • Enable the growth of Notion’s business by building a secure foundation that earns the trust of Notion’s users.
  • Design, implement, and (where possible) automate a software development life cycle that balances good vulnerability and risk detection coverage with developer velocity.
  • Act as a liaison for multiple stakeholders across product, engineering, go to market, and security ops / compliance, to guide and prioritize the right security investments.
  • Participate in security assessments and advise on both internal and customer security and privacy needs (e.g. SOC2, ISO 27001, GDPR, penetration testing, enterprise asks).

Skills You'll Need To Bring

  • Security architecture and expertise: You have experience building systems to secure and monitor cloud architectures. You can contribute directly to our main codebase to raise the bar on security systems design and address vulnerabilities. You bring experience in a number of following areas:
    • Threat modeling
    • Securing a cloud-based infrastructure (e.g. AWS)
    • Designing a secure development life cycle (design reviews, CI / CD integrations, bug bounty program)
    • Application security consulting
    • Secure library and framework development
    • Vulnerability discovery and response
    • Implement core security features like authentication to detecting and mitigating malicious activity
    • Offensive thinking (e.g. pentesting, red teaming)
  • Working in production: You have experience debugging systems in production. You appreciate the skill and challenge of continuously improving production components with minimal user disruption.
  • Pragmatic and business-oriented: You care about business impact and prioritize projects accordingly — you model threat risks and balance the right security investments with the right bottom line outcomes.
  • Not ideological about technology: To you, technologies and programming languages are about tradeoffs. You may be opinionated, but you're not ideological and can learn new technologies as you go.
  • Empathetic communication: You communicate nuanced ideas clearly, whether you're explaining technical decisions in writing or brainstorming in real time. In disagreements, you engage thoughtfully with other perspectives and compromise when needed.
  • Team player: For you, work isn't a solo endeavor. You enjoy collaborating cross-functionally to accomplish shared goals, and you care about learning, growing, and helping others to do the same.
  • You don’t need to be an AI expert, but you’re curious and willing to adopt AI tools to work smarter and deliver better results.

Nice To Haves

  • Responsible for maintaining continuous controls and participating in audits in relation to our customer facing certifications (like SOC2).
  • Experience leading engineering teams with a security focus.
  • Managed, maintained, and monitored systems using technologies like Amazon Web Services, Datadog, Postgres, Redis, Memcached, and Elasticsearch.

Key skills/competency

  • Product Security
  • Cloud Security
  • Threat Modeling
  • Application Security
  • Secure SDLC
  • Vulnerability Management
  • AWS
  • Penetration Testing
  • Security Architecture
  • GDPR/SOC2 Compliance

Tags:

Product Security Engineer
Cloud Security
Threat Modeling
Application Security
Secure SDLC
Vulnerability Management
AWS
Penetration Testing
Security Architecture
Compliance
Incident Response
Mentoring
Datadog
Postgres
Redis
Memcached
Elasticsearch
CI/CD
Authentication
Security Systems
Cloud Infrastructure

Share Job:

How to Get Hired at Notion

  • Research Notion's culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor.
  • Customize your resume: Highlight product security, cloud architecture (AWS), and secure SDLC experience for the Software Engineer, Product Security role.
  • Showcase problem-solving: Prepare examples demonstrating threat modeling, vulnerability response, and production system debugging.
  • Emphasize cross-functional collaboration: Illustrate your ability to work with product, engineering, and compliance teams effectively.
  • Understand Notion's product: Demonstrate familiarity with Notion's features and how security impacts user experience.

Frequently Asked Questions

Find answers to common questions about this job opportunity

Explore similar opportunities that match your background