We're on a mission to make it possible for every person, team, and company to be able to tailor their software to solve any problem and take on any challenge. Computers may be our most powerful tools, but most of us can't build or modify the software we use on them every day. At Notion, we want to change this with focus, design, and craft.
We've been working on this together since 2016, and have customers like Pixar, Mitsubishi, Figma, Plaid, Match Group, and thousands more on this journey with us. Today, we're growing fast and excited for new teammates to join us who are the best at what they do. We're passionate about building a company as diverse and creative as the millions of people Notion reaches worldwide.
Notion is an in person company, and currently requires its employees to come to the office for two Anchor Days (Mondays & Thursdays).
About The Role:
Millions of people use Notion — and this number is increasing every day. Our users depend on us to deliver a secure and trustworthy experience, and we value this more than anything. We want to keep building on that trust, while also continuing to amaze our users with the tools they can build in Notion. This is where you come in — to help us forge a strong, reliable path forward to the future.
Notion is looking for a passionate security engineer that loves to discover potential weaknesses and then create solutions to eliminate those weaknesses. Your skills will be the foundation of security initiatives that protect the security and privacy of Notion users. You will provide engineering and product teams across Notion (on the web, desktop, and mobile apps) the security expertise necessary to make confident product decisions.
The Notion application is flexible, powerful and always evolving. With a product that needs to scale to meet the needs of many thousands of businesses globally. They rely on us to protect their data and that of their customers.
What You'll Achieve:
As an early member of Notion’s Product Security team you will help lay the foundation of the security and privacy of our products long into the future. You will hunt for vulnerabilities in our existing products, threat model new products and features, and drive the creation of solutions that eliminate classes of vulnerabilities.
- Secure Notion’s future products through design and implementation reviews
- Make the secure path the easy path for product teams through hardened libraries and building solutions that eliminate classes of vulnerabilities
- Discover Notion’s vulnerabilities through red teaming and partnering with product teams to conduct internal penetration testing
- Automate detection of weaknesses in our codebase through static and dynamic analysis.
- Provide developers guidance and education on security and privacy best practices that prevent the authoring of vulnerabilities
- Continue to mature a world class bug bounty program
- Participate in and drive mitigation strategies during security related incident responses.
Skills You'll Need to Bring:
- Secure Software Development Expertise: You have at least 5+ years of implementing software that must be secure, scalable, and used by multiples teams. You are empathetic software engineers that will utilize your software, looking for sharp edges and eliminating them. You are able to use your experience to educate others and make those around you a better software engineer.
- Security Architecture expertise: You have at least 5+ years of experience building systems that are secure by design. Your system designs have scaled from 10s to 100s of millions of users in order to ensure user data is protected while enabling product teams to be more productive.
- Product Security expertise: You have at least 5+ years hunting for and remediating vulnerabilities in products. Your solutions to vulnerabilities address the immediate issues to mitigate risks while identifying the systematic cause that lead to the vulnerability in the first place. You combine your security, software development, and architecture expertises to prevent future vulnerabilities from being introduced.
- Ability to advocate for and lead cross functional projects: You regularly advocate for security hardening projects that you then lead by partnered with product engineering teams to improve the security story of the products you are responsible to secure.
- Pragmatic and business-oriented: You care about business impact and prioritize projects accordingly — As a product security expert you communicate and facilitate understand of the threat model and risks with the goal to balance the right security investments with the right bottom line outcomes.
- Empathetic communication: You communicate nuanced ideas clearly, whether you're explaining technical decisions in writing or brainstorming in real time. In disagreements, you engage thoughtfully with other perspectives and compromise when needed.
Nice to Haves:
- Participates in other companies bug bounty programs or capture the flag experience
- Published reports of vulnerabilities you have found
- Involvement in local or regional security user groups or conferences
We hire talented and passionate people from a variety of backgrounds because we want our global employee base to represent the wide diversity of our customers. If you’re excited about a role but your past experience doesn’t align perfectly with every bullet point listed in the job description, we still encourage you to apply. If you’re a builder at heart, share our company values, and enthusiastic about making software toolmaking ubiquitous, we want to hear from you.
Notion is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Notion considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Notion is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, please let your recruiter know.
Notion is committed to providing highly competitive cash compensation, equity, and benefits. The compensation offered for this role will be based on multiple factors such as location, the role’s scope and complexity, and the candidate’s experience and expertise, and may vary from the range provided below. For roles based in San Francisco, the estimated base salary range for this role is $145,000 - $270,000 per year.