Senior Detection & Threat Engineer
Checkout.com · London
- Location
- London
- Employment
- Full time
- Level
- Senior
- Posted
- Last week
About this role
Company Description
We’re Checkout.com. You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we’re behind many of the digital experiences you use every day.
We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers.
Whether you want to book a holiday, order food, renew a subscription, or check out online, there’s a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale.
If you want to do career-defining work, you’ve come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact.
With 20 offices across six continents and London as our HQ, we’re shaping the future of fintech - and we’re just getting started.
The role
You will own and evolve the company’s threat detection and threat-hunting capability. This role defines what “good” looks like for detection and increasingly engineers it directly as capability shifts into Cyber Security.
This is not an alert-triage role. You are here to understand attacker behaviour, convert it into high-fidelity detection logic, and raise the security baseline for the entire organisation.
You will partner closely with Security Operations, GRC and Engineering - setting standards, direction, and expectations - while progressively taking ownership of the most complex and high-value detection and threat engineering work.
What you’ll be responsible for
Engineering high-fidelity threat detections across endpoint, identity, cloud, and SaaS
Defining detection standards, principles, and quality thresholds for Security Operations
Conducting proactive threat hunting based on attacker behaviour, not vendor alerts
Translating threat intelligence and incident learnings into durable, reusable detections
Mapping detections to MITRE ATT&CK and real-world attack paths
Reducing alert fatigue through logic refinement, correlation, and contextual enrichment
Advising and supporting during high-severity security incidents; contribute to runbooks and escalation playbooks
Driving the transition of advanced detection capability into Cyber Security ownership
What we’re looking for
Proven experience in detection engineering, threat hunting, or advanced SOC roles
Deep understanding of modern attacker tradecraft and intrusion techniques across the attack lifecycle
Hands-on experience buidling detection logic in modern SIEM platforms (e.g Sentinel)
Proficienty with scripting and programmaining (e.g. Python, KQL) to build detection pipelines and automation
Willingness to challenge bad detections, weak assumptions, and vanity metrics
Pragmatic mindset: precision and impact beat coverage theatre
Experience operating beyond traditional SOC or MSSP models
Hands-on cloud detection experience (identity, control plane, SaaS)
Familiarity with threat intelligence platforms and frameworks such as PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud.
Additional Information
Bring all of you to work
We create the conditions for high performers to thrive, through real ownership, fewer blockers, and work that makes a difference from day one.
Here, you’ll move fast, take on meaningful challenges, and be recognized for the impact you deliver. It’s a place where ambition gets met with opportunity, and where your growth is in your hands.
We work as one team, and we back each other to succeed. So whatever your background or identity, if you’re ready to grow and make a difference, you’ll be right at home here.
It’s important we set you up for success and make our process as accessible as possible. So let us know in your application, or tell your recruiter directly, if you need anything to make your experience or working environment more comfortable.
Life at Checkout.com
We understand that work is just one part of your life. Our hybrid working model offers flexibility, with three days per week in the office to support collaboration and connection.
Curious about what it’s like to be part of our team? Visit our Careers Page to learn more about our culture, open roles, and what drives us.
For a closer look at daily life at Checkout.com, follow us on LinkedIn and Instagram
As published by Checkout.com. Applications are handled on their site.
One click, then it is written
Apply to Checkout.com with a resume written for this role.
Queue Senior Detection & Threat Engineer and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Checkout.com’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Checkout.com
See all- Today
- Today
- Today
- Yesterday
- Yesterday
- Yesterday
Similar roles elsewhere
See more- Today
AI Forward Deployed Engineer
DatabricksLondon, United KingdomRemote
$80k - $150k/yrMid levelEngineering - Today
Principal Partner Manager - Channels (UKI Security)
DatadogLondon, United KingdomRemote
ExecutiveEngineering - Today
Senior Forward Deployed Engineer (Technical Data Architect)
DatabricksLondon, United Kingdom
SeniorEngineering
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Checkout.com publishes. Refolk is not the employer and does not handle their hiring. Applications go to Checkout.com directly.