Jobs / United States / Notion Labs INC

Security Engineer, Detection and Response

Notion Labs INC · 🇺🇸 San Francisco, California; New York, New York

Sponsorship verdict

Sponsorship possible

One solid signal, not two — worth applying, and worth asking about sponsorship early.

  • Employer is on a government sponsor recordThe US Department of Labor certified 25 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 8 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
  • The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
  • No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
  • What Notion Labs INC paid sponsored hires in similar roles15 certified filings for “Software Engineer” (Software Developers) in CA: $172k–$231k, median $180k. Most were filed at wage level II (40%) — 2 lottery entries, ≈31% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
  • Confirmed live todayWhen a source last listed this job as open.

US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).

A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.

Start free →

Or apply yourself on the official page →

Sponsor Radar — Notion Labs INC

25 H-1B filings certified since Oct 2025

The US Department of Labor certified 25 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 8 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).

Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Notion Labs INC →

About the role

WHO WE ARE Notion is the collaborative AI workspace where teams and agents think together https://www.youtube.com/watch?v=vkpYpWfEK5s. We're building one place where your knowledge, projects, meetings, and AI tools live side by side, so work is faster, clearer, and less fragmented. Millions of individuals, small teams, and large companies run their work on Notion. Notinos (our employees) are customer zero in bringing this future of work to life. We care about craft, building things that last, and the belief that great work is still fundamentally human. Our goal isn’t to ship the next feature. Each and every team of Notinos is working to set the standard for how humans work together in the AI era. From building a business’s system of record to making and managing AI agents to automating away the busy work, we care deeply about giving our customers more time for their life’s work. ABOUT THE ROLE Millions of people rely on Notion to do their most important work, and protecting that trust is foundational to everything we build. We’re looking for a hands-on Detection Engineer to build and operate the systems and workflows we use to detect and respond to attacks across Notion’s cloud-native environment. You’ll ship high-signal detections, improve the platform that powers them, participate in incident response, and help shape how detection and response engineering scales at Notion. You’ll work closely with Engineering, Corporate Security, and Infrastructure, with broad latitude to identify gaps, prioritize investments, and build what’s needed next. We view detection and response as a software engineering discipline: detections are code, platforms are products, and measurement matters WHAT YOU'LL ACHIEVE - Build and tune high-signal detections across cloud, identity, endpoint, and SaaS environments, with review and mentorship from senior teammates as you ramp up. - Contribute to the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety. - Build tooling and automation that speed up triage, enrichment, investigation, and detection authoring, including LLM-based workflows where useful. - Turn threat intelligence and adversary TTPs into detections, telemetry requirements, and response improvements. - Take part in investigations, incident response, and postmortems, and help turn what we learn into lasting fixes. - Help define and track metrics such as coverage, MTTD, and alert quality. - Join a shared on-call rotation for incident response. SKILLS YOU'LL NEED TO BRING - We're hiring across a range of experience levels. If you have some of these skills but not all, we'd still like to hear from you. - 3+ years of experience in detection engineering, security operations, incident response, threat hunting, or a closely related security or software engineering role. - Have written or tuned detections that run in production, and care about signal quality and cutting noise. - Working knowledge of at least one detection or query language (Sigma, KQL, SPL, YARA-L, EQL, or Panther), or strong SQL or Python skills and the drive to learn one quickly. - An understanding of how attackers operate (for example, MITRE ATT&CK), and the ability to use it to decide what to detect. - Hands-on experience with AWS, GCP, or Azure, ideally including identity and access logs. - Have used SIEM, EDR, or SOAR tools in any size of environment. - Write clearly in runbooks, design docs, and incident notes, and can own well-scoped projects end to end. NICE TO HAVE - Have led purple team, blue team, or adversary emulation exercises that improved detections or telemetry. - Experience running SIEM, EDR, or SOAR platforms at la

View the official posting →

Source: Ashby (employer board) First seen: 2026-01-29 Last confirmed: 2026-10-03 How our data works → Report this job

Similar opportunities