Resume and JobRESUME AND JOB
Notion logo

Software Engineer, Product Security

Notion

Software Engineer, Product Security

Notion logo

Notion

full-time

Posted: December 3, 2025

Number of Vacancies: 1

Job Description

About Us:

Notion helps you build beautiful tools for your life’s work. In today's world of endless apps and tabs, Notion provides one place for teams to get everything done, seamlessly connecting docs, notes, projects, calendar, and email—with AI built in to find answers and automate work. Millions of users, from individuals to large organizations like Toyota, Figma, and OpenAI, love Notion for its flexibility and choose it because it helps them save time and money.

In-person collaboration is essential to Notion's culture. We require all team members to work from our offices on Mondays and Thursdays, our designated Anchor Days. Certain teams or positions may require additional in-office workdays.

About the Role:

Millions of people use Notion — and this number is increasing every day. Our users depend on us to deliver a secure and trustworthy experience, and we value this more than anything. In this role, we are looking for a founding member of an elite security engineering team that is responsible for all aspects of ensuring the security of our platform and users. You will be one of Notion’s foremost security expert, understanding the full attack surface of our product and working with a broad range of teams to secure it.

What You'll Achieve:

  • You'll help scale the engineering organization and mentor engineers on best practices in secure software design and architecture.

  • You’ll enable the growth of Notion’s business by building a secure foundation that earns the trust of Notion’s users.

  • You’ll design, implement, and (where possible) automate a software development life cycle that balances good vulnerability and risk detection coverage with developer velocity.

  • You'll act as a liaison for multiple stakeholders across product, engineering, go to market, and security ops / compliance, to guide and prioritize the right security investments.

  • You'll participate in security assessments and advise on on both internal and customer security and privacy needs (e.g. SOC2, ISO 27001, GDPR, penetration testing, enterprise asks)

Skills You'll Need to Bring:

  • Security architecture and expertise: You have experience building systems to secure and monitor cloud architectures. You can contribute directly to our main codebase to raise the bar on security systems design and address vulnerabilities. You bring experience in a number of following areas:

    • Threat modeling

    • Securing a cloud-based infrastructure (e.g. AWS)

    • Designing a secure development life cycle (design reviews, CI / CD integrations, bug bounty program)

    • Application security consulting

    • Secure library and framework development

    • Vulnerability discovery and response

    • Implement core security features like authentication to detecting and mitigating malicious activity

    • Offensive thinking (e.g. pentesting, red teaming)

  • Working in production: You have experience debugging systems in production. You appreciate the skill and challenge of continuously improving production components with minimal user disruption.

  • Pragmatic and business-oriented: You care about business impact and prioritize projects accordingly — you model threat risks and balance the right security investments with the right bottom line outcomes.

  • Not ideological about technology: To you, technologies and programming languages are about tradeoffs. You may be opinionated, but you're not ideological and can learn new technologies as you go.

  • Empathetic communication: You communicate nuanced ideas clearly, whether you're explaining technical decisions in writing or brainstorming in real time. In disagreements, you engage thoughtfully with other perspectives and compromise when needed.

  • Team player: For you, work isn't a solo endeavor. You enjoy collaborating cross-functionally to accomplish shared goals, and you care about learning, growing, and helping others to do the same.

Nice to Haves:

  • You've been responsible for maintaining continuous controls and participating in audits in relation to our customer facing certifications (like SOC2).

  • You have experience leading engineering teams with a security focus.

  • You've managed, maintained, and monitored systems using technologies like Amazon Web Services, Datadog, Postgres, Redis, Memcached, and Elasticsearch.

We hire talented and passionate people from a variety of backgrounds because we want our global employee base to represent the wide diversity of our customers. If you’re excited about a role but your past experience doesn’t align perfectly with every bullet point listed in the job description, we still encourage you to apply. If you’re a builder at heart, share our company values, and enthusiastic about making software toolmaking ubiquitous, we want to hear from you.

Notion is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Notion considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Notion is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, please let your recruiter know.

Notion is committed to providing highly competitive cash compensation, equity, and benefits. The compensation offered for this role will be based on multiple factors such as location, the role’s scope and complexity, and the candidate’s experience and expertise, and may vary from the range provided below. For roles based in San Francisco or New York City, the estimated base salary range for this role is $240,000 - $290,000 per year.

By clicking “Submit Application”, I understand and agree that Notion and its affiliates and subsidiaries will collect and process my information in accordance with Notion’s Global Recruiting Privacy Policy and NYLL 144.

#LI-Onsite

Locations

  • San Francisco, California, United States
  • New York, New York, United States

Salary

240,000 - 290,000 USD / yearly

Skills Required

  • Security architectureintermediate
  • Threat modelingintermediate
  • Securing cloud-based infrastructure (AWS)intermediate
  • Secure development life cycle (design reviews, CI/CD integrations, bug bounty program)intermediate
  • Application security consultingintermediate
  • Secure library and framework developmentintermediate
  • Vulnerability discovery and responseintermediate
  • Core security features (authentication, detecting and mitigating malicious activity)intermediate
  • Offensive thinking (pentesting, red teaming)intermediate
  • Debugging systems in productionintermediate
  • Empathetic communicationintermediate
  • Cross-functional collaborationintermediate

Required Qualifications

  • Security architecture and expertise: You have experience building systems to secure and monitor cloud architectures. You can contribute directly to our main codebase to raise the bar on security systems design and address vulnerabilities. (experience)
  • Threat modeling (experience)
  • Securing a cloud-based infrastructure (e.g. AWS) (experience)
  • Designing a secure development life cycle (design reviews, CI / CD integrations, bug bounty program) (experience)
  • Application security consulting (experience)
  • Secure library and framework development (experience)
  • Vulnerability discovery and response (experience)
  • Implement core security features like authentication to detecting and mitigating malicious activity (experience)
  • Offensive thinking (e.g. pentesting, red teaming) (experience)
  • Working in production: You have experience debugging systems in production. You appreciate the skill and challenge of continuously improving production components with minimal user disruption. (experience)
  • Pragmatic and business-oriented: You care about business impact and prioritize projects accordingly — you model threat risks and balance the right security investments with the right bottom line outcomes. (experience)
  • Not ideological about technology: To you, technologies and programming languages are about tradeoffs. You may be opinionated, but you're not ideological and can learn new technologies as you go. (experience)
  • Empathetic communication: You communicate nuanced ideas clearly, whether you're explaining technical decisions in writing or brainstorming in real time. In disagreements, you engage thoughtfully with other perspectives and compromise when needed. (experience)
  • Team player: For you, work isn't a solo endeavor. You enjoy collaborating cross-functionally to accomplish shared goals, and you care about learning, growing, and helping others to do the same. (experience)

Preferred Qualifications

  • You've been responsible for maintaining continuous controls and participating in audits in relation to our customer facing certifications (like SOC2). (experience)
  • You have experience leading engineering teams with a security focus. (experience)
  • You've managed, maintained, and monitored systems using technologies like Amazon Web Services, Datadog, Postgres, Redis, Memcached, and Elasticsearch. (experience)

Responsibilities

  • You'll help scale the engineering organization and mentor engineers on best practices in secure software design and architecture.
  • You’ll enable the growth of Notion’s business by building a secure foundation that earns the trust of Notion’s users.
  • You’ll design, implement, and (where possible) automate a software development life cycle that balances good vulnerability and risk detection coverage with developer velocity.
  • You'll act as a liaison for multiple stakeholders across product, engineering, go to market, and security ops / compliance, to guide and prioritize the right security investments.
  • You'll participate in security assessments and advise on on both internal and customer security and privacy needs (e.g. SOC2, ISO 27001, GDPR, penetration testing, enterprise asks)

Target Your Resume for "Software Engineer, Product Security" , Notion

Get personalized recommendations to optimize your resume specifically for Software Engineer, Product Security. Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "Software Engineer, Product Security" , Notion

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

EngineeringEngineering

Related Jobs You May Like

No related jobs found at the moment.

Notion logo

Software Engineer, Product Security

Notion

Software Engineer, Product Security

Notion logo

Notion

full-time

Posted: December 3, 2025

Number of Vacancies: 1

Job Description

About Us:

Notion helps you build beautiful tools for your life’s work. In today's world of endless apps and tabs, Notion provides one place for teams to get everything done, seamlessly connecting docs, notes, projects, calendar, and email—with AI built in to find answers and automate work. Millions of users, from individuals to large organizations like Toyota, Figma, and OpenAI, love Notion for its flexibility and choose it because it helps them save time and money.

In-person collaboration is essential to Notion's culture. We require all team members to work from our offices on Mondays and Thursdays, our designated Anchor Days. Certain teams or positions may require additional in-office workdays.

About the Role:

Millions of people use Notion — and this number is increasing every day. Our users depend on us to deliver a secure and trustworthy experience, and we value this more than anything. In this role, we are looking for a founding member of an elite security engineering team that is responsible for all aspects of ensuring the security of our platform and users. You will be one of Notion’s foremost security expert, understanding the full attack surface of our product and working with a broad range of teams to secure it.

What You'll Achieve:

  • You'll help scale the engineering organization and mentor engineers on best practices in secure software design and architecture.

  • You’ll enable the growth of Notion’s business by building a secure foundation that earns the trust of Notion’s users.

  • You’ll design, implement, and (where possible) automate a software development life cycle that balances good vulnerability and risk detection coverage with developer velocity.

  • You'll act as a liaison for multiple stakeholders across product, engineering, go to market, and security ops / compliance, to guide and prioritize the right security investments.

  • You'll participate in security assessments and advise on on both internal and customer security and privacy needs (e.g. SOC2, ISO 27001, GDPR, penetration testing, enterprise asks)

Skills You'll Need to Bring:

  • Security architecture and expertise: You have experience building systems to secure and monitor cloud architectures. You can contribute directly to our main codebase to raise the bar on security systems design and address vulnerabilities. You bring experience in a number of following areas:

    • Threat modeling

    • Securing a cloud-based infrastructure (e.g. AWS)

    • Designing a secure development life cycle (design reviews, CI / CD integrations, bug bounty program)

    • Application security consulting

    • Secure library and framework development

    • Vulnerability discovery and response

    • Implement core security features like authentication to detecting and mitigating malicious activity

    • Offensive thinking (e.g. pentesting, red teaming)

  • Working in production: You have experience debugging systems in production. You appreciate the skill and challenge of continuously improving production components with minimal user disruption.

  • Pragmatic and business-oriented: You care about business impact and prioritize projects accordingly — you model threat risks and balance the right security investments with the right bottom line outcomes.

  • Not ideological about technology: To you, technologies and programming languages are about tradeoffs. You may be opinionated, but you're not ideological and can learn new technologies as you go.

  • Empathetic communication: You communicate nuanced ideas clearly, whether you're explaining technical decisions in writing or brainstorming in real time. In disagreements, you engage thoughtfully with other perspectives and compromise when needed.

  • Team player: For you, work isn't a solo endeavor. You enjoy collaborating cross-functionally to accomplish shared goals, and you care about learning, growing, and helping others to do the same.

Nice to Haves:

  • You've been responsible for maintaining continuous controls and participating in audits in relation to our customer facing certifications (like SOC2).

  • You have experience leading engineering teams with a security focus.

  • You've managed, maintained, and monitored systems using technologies like Amazon Web Services, Datadog, Postgres, Redis, Memcached, and Elasticsearch.

We hire talented and passionate people from a variety of backgrounds because we want our global employee base to represent the wide diversity of our customers. If you’re excited about a role but your past experience doesn’t align perfectly with every bullet point listed in the job description, we still encourage you to apply. If you’re a builder at heart, share our company values, and enthusiastic about making software toolmaking ubiquitous, we want to hear from you.

Notion is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Notion considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Notion is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, please let your recruiter know.

Notion is committed to providing highly competitive cash compensation, equity, and benefits. The compensation offered for this role will be based on multiple factors such as location, the role’s scope and complexity, and the candidate’s experience and expertise, and may vary from the range provided below. For roles based in San Francisco or New York City, the estimated base salary range for this role is $240,000 - $290,000 per year.

By clicking “Submit Application”, I understand and agree that Notion and its affiliates and subsidiaries will collect and process my information in accordance with Notion’s Global Recruiting Privacy Policy and NYLL 144.

#LI-Onsite

Locations

  • San Francisco, California, United States
  • New York, New York, United States

Salary

240,000 - 290,000 USD / yearly

Skills Required

  • Security architectureintermediate
  • Threat modelingintermediate
  • Securing cloud-based infrastructure (AWS)intermediate
  • Secure development life cycle (design reviews, CI/CD integrations, bug bounty program)intermediate
  • Application security consultingintermediate
  • Secure library and framework developmentintermediate
  • Vulnerability discovery and responseintermediate
  • Core security features (authentication, detecting and mitigating malicious activity)intermediate
  • Offensive thinking (pentesting, red teaming)intermediate
  • Debugging systems in productionintermediate
  • Empathetic communicationintermediate
  • Cross-functional collaborationintermediate

Required Qualifications

  • Security architecture and expertise: You have experience building systems to secure and monitor cloud architectures. You can contribute directly to our main codebase to raise the bar on security systems design and address vulnerabilities. (experience)
  • Threat modeling (experience)
  • Securing a cloud-based infrastructure (e.g. AWS) (experience)
  • Designing a secure development life cycle (design reviews, CI / CD integrations, bug bounty program) (experience)
  • Application security consulting (experience)
  • Secure library and framework development (experience)
  • Vulnerability discovery and response (experience)
  • Implement core security features like authentication to detecting and mitigating malicious activity (experience)
  • Offensive thinking (e.g. pentesting, red teaming) (experience)
  • Working in production: You have experience debugging systems in production. You appreciate the skill and challenge of continuously improving production components with minimal user disruption. (experience)
  • Pragmatic and business-oriented: You care about business impact and prioritize projects accordingly — you model threat risks and balance the right security investments with the right bottom line outcomes. (experience)
  • Not ideological about technology: To you, technologies and programming languages are about tradeoffs. You may be opinionated, but you're not ideological and can learn new technologies as you go. (experience)
  • Empathetic communication: You communicate nuanced ideas clearly, whether you're explaining technical decisions in writing or brainstorming in real time. In disagreements, you engage thoughtfully with other perspectives and compromise when needed. (experience)
  • Team player: For you, work isn't a solo endeavor. You enjoy collaborating cross-functionally to accomplish shared goals, and you care about learning, growing, and helping others to do the same. (experience)

Preferred Qualifications

  • You've been responsible for maintaining continuous controls and participating in audits in relation to our customer facing certifications (like SOC2). (experience)
  • You have experience leading engineering teams with a security focus. (experience)
  • You've managed, maintained, and monitored systems using technologies like Amazon Web Services, Datadog, Postgres, Redis, Memcached, and Elasticsearch. (experience)

Responsibilities

  • You'll help scale the engineering organization and mentor engineers on best practices in secure software design and architecture.
  • You’ll enable the growth of Notion’s business by building a secure foundation that earns the trust of Notion’s users.
  • You’ll design, implement, and (where possible) automate a software development life cycle that balances good vulnerability and risk detection coverage with developer velocity.
  • You'll act as a liaison for multiple stakeholders across product, engineering, go to market, and security ops / compliance, to guide and prioritize the right security investments.
  • You'll participate in security assessments and advise on on both internal and customer security and privacy needs (e.g. SOC2, ISO 27001, GDPR, penetration testing, enterprise asks)

Target Your Resume for "Software Engineer, Product Security" , Notion

Get personalized recommendations to optimize your resume specifically for Software Engineer, Product Security. Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "Software Engineer, Product Security" , Notion

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

EngineeringEngineering

Related Jobs You May Like

No related jobs found at the moment.