Security Engineer, Corporate Security

Notion Labs
San Francisco, New York
Workplace: HybridFull timeFunction: CybersecuritySkills: ["Python","Terraform","Okta","Google workspace","Mdm","Edr","Mcp","Ai governance","Sspm","Oauth","Scim","Mfa","Sso"]

Hands-on security engineering role focused on building scalable controls across identity, endpoints, SaaS, and workforce infrastructure. You’ll own security programs, write code to automate access reviews and onboarding, and partner with IT, Infra, GRC, and Detection & Response to strengthen Notion’s security foundations while enabling a productive workforce.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Notion Labs
Notion Labs
2 months ago

Security Engineer, Corporate Security

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 22 hours agoStatus: Live

Job Summary

Hands-on security engineering role focused on building scalable controls across identity, endpoints, SaaS, and workforce infrastructure. You’ll own security programs, write code to automate access reviews and onboarding, and partner with IT, Infra, GRC, and Detection & Response to strengthen Notion’s security foundations while enabling a productive workforce.
Location: San Francisco, New York
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Harden our identity and access management stack across SaaS, implementing phishing-resistant MFA, strong SSO, SCIM lifecycles, and least-privilege access.
  • •Operate and govern the endpoint security program for a macOS-first fleet (MDM, EDR, configuration baselines) with coverage for Windows and ChromeOS.
  • •Govern AI tool usage at the endpoint, including LLMs, AI agents, and model context protocol integrations; detect and prevent unauthorized access and data exfiltration.
  • •Reduce SaaS risk at scale using SSPM tooling and automation to detect risky OAuth grants, excessive permissions, shadow IT, and drift.
  • •Write code (Python, Terraform) to automate access reviews, onboarding/offboarding, drift detection, and audit evidence collection.

Key Requirements

  • •Hands-on security engineering experience focused on identity, endpoints, SaaS, and workforce infrastructure
  • •Ability to write code (Python, Terraform) to automate security workflows (access reviews, onboarding/offboarding, drift detection, audit evidence)
  • •Experience hardening identity and access management stacks (Okta, Google Workspace) with phishing-resistant MFA, SSO, SCIM lifecycles, and least-privilege access
  • •Experience running endpoint security programs (macOS-first fleet, MDM, EDR, configuration baselines) with Windows/ChromeOS coverage
  • •Knowledge of SaaS risk management, SSPM tooling, OAuth grants, and shadow IT; governance of AI tools at endpoints (LLMs, AI agents) and data exfiltration controls
Experience:SecurityIdentitySaaSAI governanceEndpoint security
Skills:PythonTerraformOktaGoogle workspaceMdmEdrMcpAi governanceSspmOauthScimMfaSso
Tech Stack:PythonTerraformOktaGoogle WorkspaceMDMEDRSSOSCIMMFAAWSKubernetes

Company Brief

Notion Labs
Notion builds a customizable all-in-one workspace for notes, docs, databases, and collaboration, now adding AI-powered features and enterprise capabilities to serve teams and organizations worldwide.
Industry: Enterprise Software
Company Size: Large (251 to 1,000 employees)
Revenue: USD 500M to 1B
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series C
Headquarters: San Francisco, United States
Founded: 2016
Glassdoor
Glassdoor: 4.5
WebsiteLinkedInGlassdoor