- Company Name
- Notion
- Job Title
- Software Engineer, Product Security
- Job Description
-
**Job Title**
Software Engineer, Product Security
**Role Summary**
Founding member of a security‑engineering team responsible for protecting a cloud‑native product that serves millions of users. Design, implement, and enforce secure architecture, code, and processes while collaborating across product, engineering, and compliance functions.
**Expectations**
- Scale the security division, mentor engineers, and embed secure design across teams.
- Build a trustworthy foundation that supports business growth and customer confidence.
- Deliver a balanced secure development lifecycle (SDLC) that protects the product without slowing velocity.
- Prioritize security investments based on risk, business impact, and stakeholder needs.
- Participate in external and internal assessments (SOC 2, ISO 27001, GDPR, penetration testing) and advise on customer security requirements.
**Key Responsibilities**
- Architect and evolve cloud‑based security controls on AWS.
- Conduct threat modeling, secure design reviews, and risk assessments.
- Design and implement secure development practices, including CI/CD integrations and bug‑bounty programs.
- Build and maintain core security features: authentication, authorization, threat detection, incident response.
- Perform offensive security testing (pentesting, red‑team tactics) and respond to vulnerabilities.
- Debug and harden production systems with minimal user disruption.
- Lead security reviews for new product features and releases.
- Liaise with product, engineering, go‑to‑market, and compliance teams to align security initiatives.
- Maintain continuous controls and support audit activities (SOC 2, ISO 27001, GDPR).
**Required Skills**
- Security architecture and engineering for cloud environments (AWS).
- Threat modeling and risk analysis.
- Secure SDLC design, CI/CD integration, and bug‑bounty management.
- Application security consulting and secure library/framework development.
- Vulnerability discovery, exploitation, and remediation.
- Offensive security skills (pentesting, red teaming).
- Production debugging and resilience.
- Business‑oriented risk prioritization and trade‑off analysis.
- Clear technical communication and cross‑functional collaboration.
- Team‑player mindset and empathy for diverse stakeholders.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Cybersecurity, or related field (or equivalent practical experience).
- Relevant security certifications preferred: CISSP, CISM, CEH, OSCP, AWS Certified Security – Specialty, or equivalent.
- Knowledge of regulatory frameworks: SOC 2, ISO 27001, GDPR acceptable but not mandatory.
San francisco, United states
On site
31-12-2025