
Notion
Senior
Own authentication migrations, AI guardrail infrastructure, and authz platform direction at Notion
Notion is hiring a security engineer with 10+ years of experience to own cross-cutting security programs spanning identity/authz, AI agent safety, and platform primitives across 5-10+ engineering teams. This interview probes deep hands-on experience with authentication migrations (SAML/OIDC, OAuth, passkeys, CSP), AI/LLM security protections (prompt injection, provenance), authorization architecture tradeoffs (e.g., SpiceDB vs Macaroons), and the judgment to drive multi-quarter, customer-facing security changes safely.
Practice this interview
Free · a live voice mock calibrated to this exact role
What this interview tests
- Authentication migrations (SAML/OIDC, OAuth, passkeys, CSP, session semantics)
- AI/LLM security: prompt injection protections and content provenance
- Authorization platform architecture tradeoffs (e.g., SpiceDB vs Macaroons)
- Driving multi-quarter, cross-team security programs via RFCs
- Mentoring and scaling security practices across partner teams
Common question themes
Walk through a multi-quarter authentication migration you owned end-to-end, including rollout and backwards-compatibility tradeoffs
How would you design prompt-injection protections and a provenance system for AI-generated content across surfaces like Mail/Calendar/MCP
Reason through an authorization architecture tradeoff (e.g., centralized policy store vs. capability-based tokens)
Tell me about writing a security RFC and aligning 5-10+ engineering teams behind it despite pushback
A time you had to balance security rigor against product velocity — how did you decide, and what happened
How do you scale security practices across partner teams without becoming a bottleneck
How candidates describe it
Real Software Engineer interview stories — retold from candidates' public write-ups, with sources.
Google · L3 Software EngineerOfferGoogle L3 software engineer interview: phone screen, four coding rounds, and the Googleyness round
A candidate with two years of experience went from recruiter outreach to offer over about four months. The onsite was four 45-minute coding rounds — three of them featuring binary trees — and one round turned into a 25-minute chain of follow-ups about approximating an optimal solution at scale.
Interviewed June 2020 · Bangalore, IN
Google · L4 Software EngineerNo offerGoogle L4 Software Engineer Interview: Eight Rounds, No Offer
An L4 Software Engineer candidate went through two phone screens, three onsite rounds, a culture conversation, and a team-matching call with a Google hiring manager, then watched the process stall for about a month and a half over a tightened experience requirement before an added extended round ended without an offer.
Interviewed February 2024 · Not specified
Google · L5 Software EngineerNo offerGoogle L5 software engineer interview: phone screening, three onsite rounds, system design, and a late rejection
A candidate interviewing for an L5 role went through a phone screening, three onsite coding rounds, a mobile system design round, and a Googleyness and Leadership round. Two of the four technical rounds went poorly by the candidate's own assessment, and after roughly two months of silence the recruiter reported that the role had been closed.
Interviewed January 2023 · Not specified
All Notion Software Engineer interviews
Related interviews

Notion
Mid
Developer Advocate

Notion
Manager
Engineering Manager, Mobile AI

Notion
Senior
Engineering Manager, Search & Context Platform

Replit
Senior
Senior Software Engineer, Trust & Safety

Affirm
Senior
Senior Software Engineer, Backend (Growth Platform)

Cohere
Senior