← Back to job listings
NO
Software Engineer (AI Security)
Notion · United States
About The Role
Join Notion, a fast-growing company in the AI space, as an AI Software Engineer (Security). In this role, you will define and build security architecture for our AI products, work with product and engineering teams, and help make the secure path the easy path for product teams. You will be based in San Francisco and work from the office on Mondays, Tuesdays, and Thursdays.
- Definir y construir la arquitectura de seguridad para las superficies del producto que operan en el contenido del espacio de trabajo del cliente, incluyendo la ejecución de herramientas, las escrituras de contenido, la recuperación, las verificaciones de permisos, la procedencia y la auditabilidad.
- Hacer que el camino seguro sea el camino fácil para los equipos de producto al enviar bibliotecas reutilizables, patrones de revisión, accesorios de prueba y guardrails que prevengan clases de vulnerabilidades.
- Construir pruebas automatizadas de red-team y regresión para riesgos como la inyección de indicaciones, el seguimiento de instrucciones indirectas, la exfiltración de datos, el uso indebido de herramientas, la fuga entre inquilinos y las mutaciones inseguras del espacio de trabajo.
- Secure software engineering craft: You have 8-10+ years of experience designing, building, or securing complex software systems, and you are comfortable working in production code with product and platform engineers
- Builder mindset: You’d rather leave behind a useful tool, test, library, or pattern than a task or project for someone else to pick up later
- Security product strategy: You can turn a complex security risk you see into a product design or architecture that can be built
- Security architecture judgment: You can look at a complex system and reason about where the permissions, data flow, or trust boundaries are likely to get weird, and help re-design it to make them better
- Experience building or securing products with tool use, retrieval, workflow automation, content writes, or complex permission boundaries
- Hands-on experience with prompt-injection testing, red teaming, model behavior evaluation, or abuse-resistant application design
- Experience building developer tooling, CI checks, coding-agent workflows, MCP integrations, or internal frameworks that shape how engineers build software
- Experience with enterprise SaaS security models: permissions, sharing, audit logs, data residency, encryption, compliance, or customer-facing trust guarantees
- Public security research, vulnerability writeups, conference talks, or open-source work related to product security or secure developer infrastructure
- We hire talented people from a wide range of backgrounds. If you’re excited about this role but don’t meet every bullet, we still encourage you to apply
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring