Software Engineer, Infrastructure Security

Security Engineer · Senior · Full Time

San Francisco, CaliforniaUSD 230k – 280k2w ago
Apply for this role

Opens Notion's application page

Role

What you'll do.

Join Notion's Infrastructure Security team as a Software Engineer to architect and implement secure-by-default systems protecting millions of daily users. As an IC4 engineer, you'll own end-to-end infrastructure security problems across AWS cloud environments, designing pragmatic security controls and secure defaults that scale throughout the engineering organization. This role requires proven expertise in cloud security architecture, backend development, and the ability to balance security trade-offs with business impact while fostering cross-functional collaboration.

Responsibilities

  • Proactive AWS Security Enhancement: Conduct comprehensive security assessments of AWS account configurations and cloud infrastructure to identify vulnerabilities, misconfigurations, and security gaps. Implement preventative controls that establish security baselines and reduce the attack surface across Notion's cloud environment.
  • Secrets Management and Authentication Frameworks: Design and architect secure frameworks for secrets management, credential rotation, and authentication/authorization systems. Build systems that enforce least-privilege access patterns and protect sensitive credentials across development, staging, and production environments.
  • Identity and Access Management (IAM) Solutions: Design, deploy, and maintain robust IAM solutions leveraging AWS IAM best practices and zero-trust architecture principles. Implement role-based access control (RBAC) systems that scale with organizational growth while maintaining security auditing and compliance capabilities.
  • Security Education and Cross-Functional Guidance: Provide strategic guidance and hands-on education on security and privacy best practices to engineering teams, product managers, and other cross-functional partners. Communicate nuanced security concepts clearly to both technical and non-technical audiences to build security culture across the organization.
  • Security Incident Response and Mitigation: Participate actively in security incident response efforts, helping to drive triage, root cause analysis, and mitigation strategies. Debug production systems efficiently to minimize incident impact and implement preventative measures to reduce recurrence of similar security events.
  • Secure Systems Architecture and Code Contribution: Write and ship production-grade code that raises the bar on secure system design. Contribute directly to the codebase and infrastructure architecture, applying secure coding practices, threat modeling, and security-first design principles across systems.

Qualifications

What we look for.

Technical

  • Cloud Security Architecture

    Demonstrated expertise building and maintaining systems to secure cloud architectures, including secrets management, key rotation, encryption strategies, and defense-in-depth approaches. Deep understanding of cloud-native security challenges and controls.

  • AWS Platform Expertise

    Strong hands-on experience with AWS services including IAM, VPC, KMS, Secrets Manager, CloudTrail, and security groups. Proficiency in writing infrastructure-as-code (IaC) using tools like Terraform or CloudFormation to implement secure configurations.

  • Backend and Infrastructure Development

    Proven ability to write and ship production-grade backend code. Experience with systems programming, APIs, databases, and infrastructure components. Comfortable contributing to architecture discussions and code reviews with a security-first mindset.

  • Production Debugging and Optimization

    Hands-on experience debugging complex systems in production environments with minimal disruption. Ability to read logs, trace requests, analyze metrics, and identify root causes. Proficiency with monitoring, observability, and alerting platforms.

  • Threat Modeling and Risk Assessment

    Ability to model threats, conduct risk assessments, and apply pragmatic, risk-based prioritization frameworks. Experience balancing security trade-offs against engineering velocity and business impact.

  • Identity and Access Management (IAM)

    Deep expertise in IAM systems, including authentication protocols (OAuth, SAML, MFA), authorization patterns (RBAC, ABAC), and identity governance. Understanding of federation, cross-account access, and privilege escalation vectors.

Education

  • Bachelor's Degree in Computer Science or Related Field

    Formal education in computer science, cybersecurity, information systems, or related discipline providing foundational knowledge in security principles, computer architecture, and software engineering.

Experience

  • Infrastructure Security Leadership

    3+ years of professional experience in infrastructure security, cloud security, or security engineering roles. Demonstrated ability to own security projects end-to-end from problem identification through implementation and validation.

  • Large-Scale System Design

    Experience designing security systems that scale to millions of users and complex multi-account cloud environments. Track record of making trade-offs between security, performance, and developer experience.

  • Cross-Functional Collaboration

    Proven ability to work effectively with engineering teams, product managers, and security teams. Experience communicating security concepts to both technical and non-technical stakeholders in a clear, empathetic manner.

  • Incident Response

    Direct involvement in security incident investigation, triage, and remediation. Experience learning from security events and implementing systematic improvements to prevent recurrence.

Skills

Required

  • AWS Security Best Practices

    Comprehensive understanding of AWS Well-Architected Framework's security pillar, AWS security services (IAM, KMS, Secrets Manager, GuardDuty), and implementation of security controls across compute, storage, networking, and data services.

  • Identity and Access Management

    Expert-level knowledge of IAM concepts, including role-based access control, attribute-based access control, multi-factor authentication, and delegation models for complex organizational structures.

  • Secrets Management

    Proficiency in implementing and managing secret lifecycle including generation, rotation, storage, audit logging, and revocation. Experience with AWS Secrets Manager, HashiCorp Vault, or similar solutions.

  • Threat Modeling and Security Architecture

    Ability to identify threats, model attack vectors, and design defense strategies using frameworks like STRIDE or PASTA. Experience translating threat models into concrete security requirements and architectural patterns.

  • Infrastructure-as-Code

    Hands-on experience with Terraform, CloudFormation, or similar IaC tools to implement secure infrastructure configurations consistently and repeatably.

  • Backend Development

    Strong programming skills in languages such as Python, Go, Rust, Java, or TypeScript. Ability to write, test, and deploy secure backend services and libraries.

  • Technical Communication

    Ability to articulate complex security concepts clearly in writing and verbally. Skill in creating documentation, runbooks, and security guidelines that engineering teams can understand and follow.

  • Risk-Based Prioritization

    Capability to assess security vulnerabilities and control investments through a business impact lens. Experience making pragmatic trade-offs between ideal security postures and practical implementation constraints.

Preferred

  • Zero Trust Architecture

    Nice to have

    Advanced experience designing and implementing zero-trust security models that verify every access request regardless of network location. Understanding of zero-trust principles and their application to cloud environments.

  • Data Security and Privacy Engineering

    Nice to have

    Experience implementing data classification systems, encryption strategies, and privacy controls. Knowledge of compliance frameworks like GDPR, CCPA, SOC 2, and data residency requirements.

  • AI-Assisted Security Workflows

    Nice to have

    Familiarity with applying AI and machine learning tooling to defensive security operations, threat detection, or vulnerability identification. Experience using AI for code analysis or security automation.

  • Security Community Participation

    Nice to have

    Active involvement in security communities, conferences, local security groups, or open-source security projects. Contributions to security standards, CTF competitions, or security research.

  • Incident Response Leadership

    Nice to have

    Leadership experience in security incident response, including incident command, post-incident review facilitation, and organization-wide communication during security events.

  • Cloud Compliance and Governance

    Nice to have

    Experience implementing cloud governance frameworks, compliance automation, policy enforcement, and security monitoring at scale across multiple AWS accounts.

Tech stack

Languages

PythonGoTypeScript/JavaScript

Frameworks

AWS Well-Architected FrameworkZero Trust ArchitectureInfrastructure-as-Code Frameworks

Databases

AWS DynamoDBAWS RDS

Tools

AWS Console and CLITerraformAWS Secrets ManagerAWS Identity and Access Management (IAM)AWS CloudTrailAWS KMS (Key Management Service)Monitoring and Observability PlatformsGit and Version Control

Other

AWS VPC and NetworkingMulti-Account AWS StrategySecrets Rotation AutomationAuthentication and Authorization ProtocolsSecurity Incident Response Procedures

Compensation

Pay and benefits.

Base·USD 230,000 – 280,000

Equity·Stock options

Benefits

  • Equity Compensation

    Competitive equity grants aligning your long-term interests with Notion's growth trajectory as a high-impact productivity platform serving millions of users worldwide.

  • Comprehensive Health Insurance

    Medical, dental, and vision coverage with employer contributions supporting your overall wellness and healthcare needs.

  • Flexible Work Environment

    Anchor Days policy requiring in-office presence on Mondays, Tuesdays, and Thursdays in San Francisco or New York City offices, with flexibility for remote work on other days. This hybrid structure balances collaborative thinking with focused work time.

  • Professional Development

    Access to security conferences, training programs, and continuous learning resources to stay current with evolving cloud security threats and best practices in the rapidly changing infrastructure security landscape.

  • Collaborative Culture

    Work alongside world-class engineering and security teams in a company culture that values craft, builds things that last, and maintains a fundamentally human approach to solving problems in the AI era.

  • Impact at Scale

    Directly influence the security posture of a platform used by millions of individuals and teams daily. Your infrastructure security work protects millions of users' data and enables Notion's continued growth.

Full posting

Original listing.

Who We Are

Notion is the collaborative AI workspace where teams and agents think together. We're building one place where your knowledge, projects, meetings, and AI tools live side by side, so work is faster, clearer, and less fragmented. Millions of individuals, small teams, and large companies run their work on Notion.

Notinos (our employees) are customer zero in bringing this future of work to life. We care about craft, building things that last, and the belief that great work is still fundamentally human. Our goal isn’t to ship the next feature. Each and every team of Notinos is working to set the standard for how humans work together in the AI era. From building a business’s system of record to making and managing AI agents to automating away the busy work, we care deeply about giving our customers more time for their life’s work.

About the Role:

Millions of people use Notion every day, and we’re growing quickly. The Infrastructure Security team’s mission is to build a secure-by-default foundation across Notion’s technical stacks—architecting systems that make the secure path the easy path. As an IC4 on this team, you’ll own meaningful infrastructure security problems end-to-end: from identifying risk, to designing pragmatic controls, to shipping secure defaults that scale across engineering.

This role can be based in either San Francisco or New York City. We work from our offices on Mondays, Tuesdays and Thursdays (our Anchor Days) because we do our best thinking and building together in person. We’re looking for someone who’s excited to work alongside the team during those days.

 

What You'll Achieve:

  • Proactively enhance the security posture of our AWS accounts and cloud infrastructure.

  • Create secure frameworks for secrets management and authentication/authorization.

  • Design and deploy robust Identity and Access Management (IAM) solutions.

  • Provide guidance and education on security and privacy best practices to cross-functional partners.

  • Participate in (and help drive) mitigation strategies during security-related incident response.

 

Skills You'll Need to Bring:

  • Security architecture and expertise: you’ve built and maintained systems to secure cloud architectures, ranging from secrets management to Identity and Access Management solutions.

  • Backend/infrastructure development: you’ve written and shipped production-grade code, and can contribute to the codebase and architecture to raise the bar on secure systems design.

  • Working in production: you can debug systems in production and continuously improve components with minimal disruption.

  • Pragmatic, risk-based prioritization: you model threats, balance trade-offs, and focus security investments where they drive the most business impact.

  • Empathetic communication: you communicate nuanced ideas clearly in writing and in real time; in disagreements, you engage thoughtfully and look for the right compromise.

 

Nice to Haves:

  • AWS security best practices, zero trust architectures, and/or deep IAM expertise.

  • Data security or privacy engineering experience.

  • Experience applying AI tooling to defensive security workflows.

  • Participation in security communities (local or regional groups, conferences).

 

Notion is committed to providing highly competitive cash compensation, equity, and benefits. The compensation offered for this role will be based on multiple factors such as location, the role’s scope and complexity, and the candidate’s experience and expertise, and may vary from the range provided below. For roles based in San Francisco or New York City, the estimated base salary range for this role is $230,000 - $280,000 per year.

 

By clicking “Submit Application”, I understand and agree that Notion and its affiliates and subsidiaries will collect and process my information in accordance with Notion’s Global Recruiting Privacy Policy and NYLL 144.

#LI-Onsite

A Note on AI

You don’t need deep AI expertise for every role, but we do expect every Notino to be intellectually curious, drawn to tinkering and discovery, and excited to use AI as a real collaborator in their work. For some roles, AI fluency is a core requirement — when that’s the case, we'll say so explicitly in the qualifications. People who thrive here don’t treat AI as a novelty. They use it to think better, and make their work easier for others to build on.

Equal Opportunity & Accommodations

We hire talented people from a wide range of backgrounds. If you’re excited about this role but don’t meet every bullet, we still encourage you to apply. Notion is an equal opportunity employer and does not discriminate on the basis of any legally protected characteristic. Consistent with applicable law, we will consider for employment qualified applicants with arrest and conviction records. Notion provides reasonable accommodations during the application process; if you need one, please let your recruiter know.

Notion is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Notion considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Notion is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, please let your recruiter know.

Redirects to Notion's application page.

Other roles

More at Notion.

View all 13 roles