Jobs · Engineering · California

AI Software Engineer, Security

Develawpers · San Francisco, CA · Yesterday
On-siteEngineering$290k–$350k/yrFull-time

About the role

Notion is looking for an experienced engineer to define the security foundations for our AI products. You will work with product and engineering teams on agent runtimes, tool permissions, retrieval, content writes, observability, and abuse-resistant design.

You will turn product risks into clear architecture, reusable guardrails, automated tests, and production systems that help teams ship new features safely. This role is based in San Francisco. We work from our offices on Mondays, Tuesdays and Thursdays (our Anchor Days).

Responsibilities

  • Define and build security architecture for product surfaces that operate across customer workspace content, including tool execution, content writes, retrieval, permission checks, provenance, and auditability.
  • Make the secure path the easy path for product teams by shipping reusable libraries, review patterns, test fixtures, and guardrails that prevent classes of vulnerabilities.
  • Build automated red-team and regression testing for risks such as prompt injection, indirect instruction following, data exfiltration, tool misuse, cross-tenant leakage, and unsafe workspace mutations.
  • Translate threat models for new product surfaces into concrete engineering requirements, production checks, and launch criteria.
  • Use production signals, incident learnings, and targeted experiments to harden Notion over time, then feed those learnings back into architecture and developer workflows.
  • Help define the security bar for how engineers use coding agents, MCP-enabled tools, hooks, and internal automation without introducing new risk.

Requirements

  • Experience building or securing products with tool use, retrieval, workflow automation, content writes, or complex permission boundaries.
  • Hands-on experience with prompt-injection testing, red teaming, model behavior evaluation, or abuse-resistant application design.
  • Experience with enterprise SaaS security models: permissions, sharing, audit logs, data residency, encryption, compliance, or customer-facing trust guarantees.
  • Experience building developer tooling, CI checks, coding-agent workflows, MCP integrations, or internal frameworks that shape how engineers build software.
  • Public security research, vulnerability writeups, conference talks, or open-source work related to product security or secure developer infrastructure.

Skills

  • Secure software engineering craft: Design, build, or secure complex software systems.
  • Security architecture judgment: Reason about permissions, data flow, or trust boundaries in complex systems.
  • Security product strategy: Turn complex security risks into product designs or architectures.
  • Builder mindset: Build useful tools, tests, libraries, or patterns rather than tasks or projects for others to pick up later.

Nice to haves

  • Experience with prompt-injection testing, red teaming, model behavior evaluation, or abuse-resistant application design.
  • Experience with enterprise SaaS security models: permissions, sharing, audit logs, data residency, encryption, compliance, or customer-facing trust guarantees.
  • Experience building developer tooling, CI checks, coding-agent workflows, MCP integrations, or internal frameworks that shape how engineers build software.
  • Public security research, vulnerability writeups, conference talks, or open-source work related to product security or secure developer infrastructure.

Pay

The compensation offered for this role will be based on multiple factors such as location, the role's scope and complexity, and the candidate's experience and expertise, and may vary from the range provided below. For roles based in San Francisco, the estimated base salary range for this role is $290,000 - $350,000 per year.

Similar jobs