Senior Detection & Threat Engineer

Checkout.com

Greater London

Hybrid

GBP 90,000 - 150,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Checkout.com is seeking a high-impact Threat Detection Engineer to own and evolve the company’s threat detection and hunting capability. You’ll translate attacker behaviour into high-fidelity detection logic and raise the security baseline across the organisation.

You’ll partner with Security Operations, GRC and Engineering to set standards and ownership, while delivering the most complex detections and driving this capability forward in a rapidly growing fintech environment.

Qualifications

  • Experience in detection engineering or threat hunting at advanced SOC.
  • Strong knowledge of attacker tradecraft and intrusion techniques.
  • Hands-on experience building detection logic in SIEM (Sentinel).
  • Proficiency in Python and KQL for detections and automation.
  • Willingness to challenge bad detections, vanity metrics.
  • Pragmatic mindset: precision and impact over coverage theatre.
  • Experience operating beyond traditional SOC or MSSP models.

Responsibilities

  • Engineer high-fidelity threat detections across endpoint, identity, cloud, and SaaS.
  • Define detection standards, principles, and quality thresholds for Security Operations.
  • Conduct proactive threat hunting based on attacker behaviour.
  • Translate threat intelligence and incident learnings into durable, reusable detections.
  • Map detections to MITRE ATT&CK and real-world attack paths.
  • Reduce alert fatigue through logic refinement, correlation, and contextual enrichment.
  • Advise and support during high‑severity security incidents; contribute to runbooks and escalation playbooks.
  • Drive the transition of advanced detection capability into Cyber Security ownership.

Skills

Threat detection
Threat hunting
SIEM (Sentinel)
Python
KQL
Cloud security
Threat intel platforms
Attack lifecycle knowledge
MSSP/SOC experience

Education

Bachelor's degree in Computer Science or related field

Tools

Sentinel SIEM
Cloud security tooling

Job description

_ Company Description _

We’re Checkout.com. You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we’re behind many of the digital experiences you use every day.

We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers.

Whether you want to book a holiday, order food, renew a subscription, or check out online, there’s a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale.

If you want to do career-defining work, you’ve come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact.

With 20 offices across six continents and London as our HQ, we’re shaping the future of fintech – and we’re just getting started.

The role

You will own and evolve the company’s threat detection and threat-hunting capability. This role defines what “good” looks like for detection and increasingly engineers it directly as capability shifts into Cyber Security.

This is not an alert-triage role. You are here to understand attacker behaviour, convert it into high-fidelity detection logic, and raise the security baseline for the entire organisation.

You will partner closely with Security Operations, GRC and Engineering—setting standards, direction, and expectations—while progressively taking ownership of the most complex and high-value detection and threat engineering work.

What you’ll be responsible for
  • Engineering high-fidelity threat detections across endpoint, identity, cloud, and SaaS
  • Defining detection standards, principles, and quality thresholds for Security Operations
  • Conducting proactive threat hunting based on attacker behaviour, not vendor alerts
  • Translating threat intelligence and incident learnings into durable, reusable detections
  • Mapping detections to MITRE ATT&CK and real-world attack paths
  • Reducing alert fatigue through logic refinement, correlation, and contextual enrichment
  • Advising and supporting during high‑severity security incidents; contribute to runbooks and escalation playbooks
  • Driving the transition of advanced detection capability into Cyber Security ownership
What we’re looking for
  • Proven experience in detection engineering, threat hunting, or advanced SOC roles
  • Deep understanding of modern attacker tradecraft and intrusion techniques across the attack lifecycle
  • Hands‑on experience buidling detection logic in modern SIEM platforms (e.g Sentinel)
  • Proficienty with scripting and programmaining (e.g. Python, KQL) to build detection pipelines and automation
  • Willingness to challenge bad detections, weak assumptions, and vanity metrics
  • Pragmatic mindset: precision and impact beat coverage theatre
  • Experience operating beyond traditional SOC or MSSP models
  • Hands‑on cloud detection experience (identity, control plane, SaaS)
  • Familiarity with threat intelligence platforms and frameworks such as PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud.
Additional Information
Bring all of you to work

We create the conditions for high performers to thrive, through real ownership, fewer blockers, and work that makes a difference from day one.

Here, you’ll move fast, take on meaningful challenges, and be recognized for the impact you deliver. It’s a place where ambition gets met with opportunity, and where your growth is in your hands.

We work as one team, and we back each other to succeed. So whatever your background or identity, if you’re ready to grow and make a difference, you’ll be right at home here.

It’s important we set you up for success and make our process as accessible as possible. So let us know in your application, or tell your recruiter directly, if you need anything to make your experience or working environment more comfortable.

Life at Checkout.com

We understand that work is just one part of your life. Our hybrid working model offers flexibility, with three days per week in the office to support collaboration and connection.

Curious about what it’s like to be part of our team? Visit our Careers Page to learn more about our culture, open roles, and what drives us.

For a closer look at daily life at Checkout.com, follow us on LinkedIn and Instagram

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer
Senior Cloud Security Engineer

Checkout.com • Greater London

On-site
GBP 90,000 - 120,000
Senior Threat Detection & Hunting Engineer
Senior Threat Detection & Hunting Engineer

Checkout.com • Greater London

Hybrid
GBP 90,000 - 150,000
Director of Cyber Security
Director of Cyber Security

0026 Checkout Technology Ltd • Greater London

Hybrid
GBP 90,000 - 130,000
Cyber Security Engineer I
Cyber Security Engineer I

Checkout.com • Greater London

On-site
GBP 60,000 - 90,000
Cyber Security Engineer I
Cyber Security Engineer I

Checkout.com • City Of London

Hybrid
GBP 60,000 - 95,000
Cyber Security Engineer I
Cyber Security Engineer I

Visa Hunt • Greater London

Hybrid
GBP 65,000 - 90,000
Cyber Security Engineer I Software engineering London
Cyber Security Engineer I Software engineering London

Checkout • Greater London

Hybrid
GBP 70,000 - 120,000
Engineer, IT Engineering Information security London
Engineer, IT Engineering Information security London

Checkout Ltd • Greater London

Hybrid
GBP 65,000 - 90,000
Hybrid work model
Sr. SDET - Cloud, Detection Engineer , London)
Sr. SDET - Cloud, Detection Engineer , London)

CrowdStrike • Greater London

On-site
GBP 90,000 - 150,000
Market-leading compensation and equity
Wellness programs
Paid parental leave
+2
Senior Security Engineer, Detection and Response
Senior Security Engineer, Detection and Response

Jackalope Digital LLC • Greater London

Hybrid
GBP 100,000 - 110,000
Health, vision and dental insurance
Equity stock options
Retirement plans
+4