Software Engineer, Product Security
Listed on 2026-01-12
-
IT/Tech
Cybersecurity
Software Engineer, Product Security
Join to apply for the Software Engineer, Product Security role at Notion.
About UsNotion helps you build beautiful tools for your life’s work. In today's world of endless apps and tabs, Notion provides one place for teams to get everything done, seamlessly connecting docs, notes, projects, calendar, and email—with AI built in to find answers and automate work. Millions of users, from individuals to large organizations like Toyota, Figma, and OpenAI, love Notion for its flexibility and choose it because it helps them save time and money.
In-person collaboration is essential to Notion's culture. We require all team members to work from our offices on Mondays and Thursdays, our designated Anchor Days. Certain teams or positions may require additional in-office workdays.
AboutThe Role
Millions of people use Notion—and this number is increasing every day. Our users depend on us to deliver a secure and trustworthy experience, and we value this more than anything. In this role, we are looking for a founding member of an elite security engineering team that is responsible for all aspects of ensuring the security of our platform and users.
You will be one of Notion’s foremost security experts, understanding the full attack surface of our product and working with a broad range of teams to secure it.
Key responsibilities:
- Help scale the engineering organization and mentor engineers on best practices in secure software design and architecture.
- Enable the growth of Notion’s business by building a secure foundation that earns the trust of users.
- Design, implement, and (where possible) automate a software development life cycle that balances good vulnerability and risk detection coverage with developer velocity.
- Act as a liaison for multiple stakeholders across product, engineering, go-to-market, and security ops/compliance, to guide and prioritize the right security investments.
- Participate in security assessments and advise on internal and customer security and privacy needs (e.g., SOC2, ISO 27001, GDPR, penetration testing, enterprise asks).
- Security architecture and expertise:
Experience building systems to secure and monitor cloud architectures; capacity to contribute directly to our main codebase to raise the bar on security systems design and address vulnerabilities. - Threat modeling
- Securing a cloud-based infrastructure (e.g., AWS)
- Designing a secure development life cycle (design reviews, CI/CD integrations, bug bounty program)
- Application security consulting
- Secure library and framework development
- Vulnerability discovery and response
- Implement core security features like authentication, detecting and mitigating malicious activity
- Offensive thinking (e.g., pen testing, red teaming)
- Working in production:
Experience debugging systems in production with minimal user disruption. - Pragmatic and business-oriented:
Prioritize projects based on business impact; balance security investments with ROI. - Not ideological about technology:
Comfortable learning new technologies; not tied to any particular language. - Empathetic communication:
Explain nuanced ideas clearly; engage thoughtfully with others. - Team player:
Enjoy collaborating cross-functionally and helping others grow.
- Responsible for maintaining continuous controls and participating in audits for customer-facing certifications (e.g., SOC2).
- Experience leading engineering teams with a security focus.
- Managed, maintained, and monitored systems using Amazon Web Services, Datadog, Postgres, Redis, Memcached, and Elasticsearch.
We hire talented and passionate people from a variety of backgrounds because we want our global employee base to represent the wide diversity of our customers. If you’re excited about a role but your past experience doesn’t align perfectly with every bullet point listed in this job description, we still encourage you to apply. If you’re a builder at heart, share our company values, and enthusiastic about making software toolmaking ubiquitous, we want to hear from you.
EqualOpportunity Employer
Notion is proud to be an equal opportunity employer. We do not…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).