Notion logo

Notion

Software Engineer, AI Product Security

Hybrid

Part remote, part office, you need to live within commuting distance of a named location.

Hybrid · San Francisco, California

Employer listed it 4 months ago · Added 4 days ago

Been open since 4 months ago. Long-running listings are sometimes left up after the role is filled.

Salary

$270k–$340k a year

Location

Hybrid · San Francisco, California

Timezone

Not stated

Contract

Full-time

Experience

Senior

Category

Software

Stated by the employer in the job description

Remote flexibility

Hybrid

This role is only partly remote, the employer expects time in the office around San Francisco, California, New York, New York, Hybrid, so you need to live within commuting distance.

What the employer says

  • Source listing states candidate location: "San Francisco, California, New York, New York, Hybrid"
  • Listing mentions "Hybrid"

What Nomaders makes of it

  • Not suitable if you plan to move between countries

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

Who We Are

Notion is the collaborative AI workspace where teams and agents think together . We're building one place where your knowledge, projects, meetings, and AI tools live side by side, so work is faster, clearer, and less fragmented. Millions of individuals, small teams, and large companies run their work on Notion.

Notinos (our employees) are customer zero in bringing this future of work to life. We care about craft, building things that last, and the belief that great work is still fundamentally human. Our goal isn’t to ship the next feature. Each and every team of Notinos is working to set the standard for how humans work together in the AI era. From building a business’s system of record to making and managing AI agents to automating away the busy work, we care deeply about giving our customers more time for their life’s work.

About the Role:

Notion is looking for an experienced engineer who has designed and built secure software systems to help define the security foundations for our AI products. You’ll work with product and engineering teams on agent runtimes, tool permissions, retrieval, content writes, observability, and abuse-resistant design. You’ll turn product risks into clear architecture, reusable guardrails, automated tests, and production systems that help teams ship new features safely.

This role is based in San Francisco. We work from our offices on Mondays, Tuesdays and Thursdays (our Anchor Days) because we do our best thinking and building together in person. We’re looking for someone who’s excited to work alongside the team during those days.

What You'll Achieve:

Define and build security architecture for product surfaces that operate across customer workspace content, including tool execution, content writes, retrieval, permission checks, provenance, and auditability.

Make the secure path the easy path for product teams by shipping reusable libraries, review patterns, test fixtures, and guardrails that prevent classes of vulnerabilities.

Build automated red-team and regression testing for risks such as prompt injection, indirect instruction following, data exfiltration, tool misuse, cross-tenant leakage, and unsafe workspace mutations.

Translate threat models for new product surfaces into concrete engineering requirements, production checks, and launch criteria.

Use production signals, incident learnings, and targeted experiments to harden Notion over time, then feed those learnings back into architecture and developer workflows.

Help define the security bar for how engineers use coding agents, MCP-enabled tools, hooks, and internal automation without introducing new risk.

Skills You'll Need to Bring:

Secure software engineering craft: You have 8-10+ years of experience designing, building, or securing complex software systems, and you are comfortable working in production code with product and platform engineers.

Security architecture judgment: You can look at a complex system and reason about where the permissions, data flow, or trust boundaries are likely to get weird, and help re-design it to make them better.

Security product strategy: You can turn a complex security risk you see into a product design or architecture that can be built.

Builder mindset: You’d rather leave behind a useful tool, test, library, or pattern than a task or project for someone else to pick up later.

Nice to Haves:

Experience building or securing products with tool use, retrieval, workflow automation, content writes, or complex permission boundaries.

Hands-on experience with prompt-injection testing, red teaming, model behavior evaluation, or abuse-resistant application design.

Experience with enterprise SaaS security models: permissions, sharing, audit logs, data residency, encryption, compliance, or customer-facing trust guarantees.

Experience building developer tooling, CI checks, coding-agent workflows, MCP integrations, or internal frameworks that shape how engineers build software.

Public security research, vulnerability writeups, conference talks, or open-source work related to product security or secure developer infrastructure.

Requirements

  • ·Secure software engineering craft: You have 8-10+ years of experience designing, building, or securing complex software systems, and you are comfortable working in production code with product and platform engineers.
  • ·Security architecture judgment: You can look at a complex system and reason about where the permissions, data flow, or trust boundaries are likely to get weird, and help re-design it to make them better.
  • ·Security product strategy: You can turn a complex security risk you see into a product design or architecture that can be built.
  • ·Builder mindset: You’d rather leave behind a useful tool, test, library, or pattern than a task or project for someone else to pick up later.
  • ·Experience building or securing products with tool use, retrieval, workflow automation, content writes, or complex permission boundaries.

Benefits

No benefits package published with this listing. Ask about it at first interview.

How to apply

  1. 1Check the flexibility label above, hybrid, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Notion, mentioning your remote working experience.
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 5d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

$270k–$340k a year · You'll be taken to the employer's careers page.