About Us:
We're on a mission to make it possible for every person, team, and company to be able to tailor their software to solve any problem and take on any challenge. Computers may be our most powerful tools, but most of us can't build or modify the software we use on them every day. At Notion, we want to change this with focus, design, and craft.We've been working on this together since 2016, and have customers like Pixar, Mitsubishi, Figma, Plaid, Match Group, and thousands more on this journey with us.
Today, we're growing fast and excited for new teammates to join us who are the best at what they do. We're passionate about building a company as diverse and creative as the millions of people Notion reaches worldwide.
About The Role:
Millions of people use Notion — and this number is increasing every day. Our users depend on us to deliver a secure, consistent and trustworthy experience, and we value this more than anything. We want to keep building on that trust, while also continuing to amaze our users with the tools they can build in Notion. This is where you come in — partnering with teams across the organization to envision, plan and build Notion's Information Security posture for governance, risk and compliance.
What You'll Achieve:
- Help mature, and scale our Security GRC program based on industry best practices for (some or all of) the following functions including Risk Management, and Business Continuity
- Implement and manage scalable process and procedures for security risk lifecycle management, risk assessments and remediation monitoring
- Develop metrics related to the risk program and overall organization’s risk posture for leadership and board level reporting
- Lead effective implementation of security risk management controls to retain SOC2 Type II, ISO 27001, HIPAA, and other certifications that exhibit assurance internally and externally
- Work with business stakeholders to develop a roadmap for business continuity using a risk based approach
- Organize and lead steering committee targeted towards reducing and managing Notion’s security risk posture
Skills You'll Need to Bring:
- Security Assessment Expertise: You have experience working with various stakeholders to review and help improve their current processes through assessments or other tools.
- Pragmatic and business-oriented: You care about business impact and prioritize projects accordingly — you understand the risks and balance the right security investments with the right bottom line outcomes.
- Empathetic communication: You communicate nuanced ideas clearly, whether you're explaining compliance requirements in writing or brainstorming in real time. When building consensus, you engage thoughtfully with other perspectives and compromise when needed.
- Team player: For you, work isn't a solo endeavor. You enjoy collaborating cross-functionally to accomplish shared goals, and you care about learning, growing, and helping others to do the same.
Nice to Haves:
- With a minimum of 5-7 years experience, you may have one or more of the following: CISSP, CISA, CRISC, CIPP
- You have experience in implementing security risk management processes and frameworks (like NIST CSF, FAIR, COSO ERM, ISO 31000).
- You have experience in creating tactical and strategic risk metrics for driving visibility and action towards security risk remediations.
- You have a good understanding of how AI can impact security frameworks and can articulate its risks and benefits.
- You are experienced in developing Business Continuity Program, including: Risk Assessment, Business Impact Assessment, Recovery Procedure Planning, Tabletop Exercises, etc.
- You've managed, maintained, and monitored GRC tools.
- You've been responsible for maintaining continuous controls and participating in audits in relation to our customer facing certifications (like SOC2, ISO).
- You have experience leading projects from start to finish across multiple teams and time zones.
We hire talented and passionate people from a variety of backgrounds because we want our global employee base to represent the wide diversity of our customers. If you’re excited about a role but your past experience doesn’t align perfectly with every bullet point listed in the job description, we still encourage you to apply. If you’re a builder at heart, share our company values, and enthusiastic about making software toolmaking ubiquitous, we want to hear from you.Notion is proud to be an equal opportunity employer.
We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Notion considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Notion is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures.
If you need assistance or an accommodation due to a disability, please let your recruiter know.Notion is committed to providing highly competitive cash compensation, equity, and benefits. The compensation offered for this role will be based on multiple factors such as location, the role’s scope and complexity, and the candidate’s experience and expertise, and may vary from the range provided below. For roles based in San Francisco or New York City, the estimated base salary range for this role is $160,000 - $215,000 per year.#LI-Onsite