Senior Detection & Threat Engineer
Checkout.com
London · Onsite · Full Time
Posted
Job description
Company Description We’re Checkout.com . You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we’re behind many of the digital experiences you use every day. We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers. Whether you want to book a holiday, order food, renew a subscription, or check out online, there’s a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale. If you want to do career-defining work, you’ve come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact. With 20 offices across six continents and London as our HQ, we’re shaping the future of fintech – and we’re just getting started. The role You will own and evolve the company’s threat detection and threat-hunting capability. This role defines what “good” looks like for detection and increasingly engineers it directly as capability shifts into Cyber Security. This is not an alert-triage role. You are here to understand attacker behaviour, convert it into high-fidelity detection logic, and raise the security baseline for the entire organisation. You will partner closely with Security Operations, GRC and Engineering—setting standards, direction, and expectations—while progressively taking ownership of the most complex and high-value detection and threat engineering work. What you’ll be responsible for Engineering high-fidelity threat detections across endpoint, identity, cloud, and SaaS Defining detection standards, principles, and quality thresholds for Security Operations Conducting proactive threat hunting based on attacker behaviour, not vendor alerts Translating threat intelligence and incident learnings into durable, reusable detections Mapping detections to MITRE ATT&CK and real-world attack paths Reducing alert fatigue through logic refinement, correlation, and contextual enrichment Advising and supporting during high-severity security incidents; contribute to runbooks and escalation playbooks Driving the transition of advanced detection capability into Cyber Security ownership What we’re looking for Proven experience in detection engineering, threat hunt…