Have 6+ years of experience in detection engineering, security operations, incident response, or threat hunting
Have built and operated production detections with strong signal quality and sustainable tuning processes
Are fluent in one or more detection languages such as Sigma, KQL, SPL, YARA-L, EQL, or Panther
Have an offensive security mindset and have led purple team, blue team, or adversary emulation exercises that improved detections and telemetry
Have strong cloud security experience in AWS, GCP, or Azure, including identity-focused attack detection
Are hands-on with SIEM, EDR, and SOAR platforms in large-scale environments
Communicate clearly through design docs, runbooks, and incident reports, and can drive projects independently
Experience applying LLMs or agent-style tooling to security workflows
Experience securing AI-enabled systems or endpoint tooling
Kubernetes or container detection experience
Background in threat intelligence, malware analysis, or digital forensics
Contributions to the detection engineering community through research, tooling, or talks
Experience at a high-growth startup or AI company
A NOTE ON AI
You don’t need deep AI expertise for every role, but we do expect every Notino to be intellectually curious, drawn to tinkering and discovery, and excited to use AI as a real collaborator in their work. For some roles, AI fluency is a core requirement — when that’s the case, we'll say so explicitly in the qualifications. People who thrive here don’t treat AI as a novelty. They use it to think better, and make their work easier for others to build on