Senior Cyber Security Engineer
Summary
A hands-on cyber security engineer role at Checkout.com (London, hybrid) focused on securing AI systems — LLM apps, model integrations, and cloud infrastructure. Day to day: design AI security controls, assess AI risks (prompt injection, data leakage), build guardrails, and add AI-driven detection to security operations.
Company Description
We’re . You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we’re behind many of the digital experiences you use every day.
We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers.
Whether you want to book a holiday, order food, renew a subscription, or check out online, there’s a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale.
If you want to do career-defining work, you’ve come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact.
With 20 offices across six continents and London as our HQ, we’re shaping the future of fintech – and we’re just getting started.
The role
You will be a hands-on operator at the heart of the Cyber Security team, helping to run, harden, and continuously improve the day-to-day machinery of security. Where the Detection & Threat Engineer defines what "good" looks like, you help make it real, turning standards, runbooks, and tooling into reliable, repeatable operational practice.
This is a delivery-focused role for an experienced practitioner. You will spend your time in the tooling, in the tickets, and in the detail: enhancing the platforms the team depends on, tightening procedures, and making sure findings, alerts, and remediation work actually get closed out rather than left to drift.
You will partner closely with Senior Detection & Threat Engineers, Application Security, Information Security, Security Operations, and Engineering executing against the standards they set, feeding operational insight back up, and progressively taking ownership of the tooling and procedures that keep security operations running.
What you'll be responsible for
Supporting and enhancing security tooling SIEM, EDR, DLP, vulnerability management, and automation platforms including configuration, tuning, and day-to-day maintenance
Building and improving operational procedures, runbooks, and playbooks so the team's response is consistent and repeatable
Triaging and handling security alerts, escalating high-severity events, and contributing to incident response under the direction of senior engineers
Tracking, coordinating, and driving pentest and vulnerability findings through to remediation across engineering teams (ownership, action plans, status, closure)
Maintaining the accuracy and hygiene of security data asset inventories, finding trackers, and remediation records
Supporting detection deployment and validation, and feeding operational feedback into detection tuning to reduce noise and alert fatigue
Assisting with scripting and automation to remove manual toil from recurring operational tasks
Producing clear operational reporting and metrics on findings, remediation progress, and tooling health
What we're looking for
5+ years of hands-on experience in a Security Operations, SOC, or equivalent operational security role
Practical experience operating modern security tooling SIEM (e.g. Sentinel), Data Loss Prevention (DLP) tools, EDR, and vulnerability management platforms
Solid understanding of security operations workflows: alert triage, incident handling, and vulnerability/finding remediation lifecycles
Comfort with scripting to support automation and tooling (e.g. Python, KQL)
Experience coordinating remediation across multiple engineering or platform teams, and keeping work moving to closure
Working knowledge of cloud environments (e.g. AWS, Azure and GCP) and how security operations apply across cloud and SaaS
Familiarity with common frameworks and standards such as PCI DSS, NIST CSF, SOC 2, ISO 27001, CIS Benchmarks, and MITRE ATT&CK
A pragmatic, ownership-minded operator: methodical, detail-oriented, and focused on getting things fixed rather than just logged
Additional Information
Bring all of you to work
We create the conditions for high performers to thrive, through real ownership, fewer blockers, and work that makes a difference from day one.
Here, you’ll move fast, take on meaningful challenges, and be recognized for the impact you deliver. It’s a place where ambition gets met with opportunity, and where your growth is in your hands.
We work as one team, and we back each other to succeed. So whatever your background or identity, if you’re ready to grow and make a difference, you’ll be right at home here.
It’s important we set you up for success and make our process as accessible as possible. So let us know in your application, or tell your recruiter directly, if you need anything to make your experience or working environment more comfortable.
Life at
We understand that work is just one part of your life. Our hybrid working model offers flexibility, with three days per week in the office to support collaboration and connection.
Curious about what it’s like to be part of our team? Visit our Careers Page to learn more about our culture, open roles, and what drives us.
For a closer look at daily life at , follow us on LinkedIn and Instagram
Skills
As published by ashby · 9 questions · 2 written answers
Basics
Name, Email, Resume
Short answers (4)
- Phone Number
- LinkedIn Profile optional
- Expected Salary: What are your yearly base salary expectations? Please include currency
- Notice: What is your notice period?
Pick from a list (3)
- Hybrid work: Are you willing to work in the office 3 days per week?
- Are you currently legally authorised to work as an employee in the country you are applying?
- Do you require reasonable adjustments? optional
Written answers (2)
- Visa status: What is your right to work or visa status?
- Reasonable Adjustments: Please let us know if you require any specific accommodations or adjustments during the interview stages. This information is kept confidential, used only for your support, and will not affect our hiring decision. optional