Senior Detection & Threat Engineer

Company: Checkout.com
Apply for the Senior Detection & Threat Engineer
Location: London
Job Description:

Overview

In this role you will own and evolve Checkout.com’s threat detection and threat-hunting capability to raise the security baseline across the organisation. You’ll collaborate with Security Operations, GRC and Engineering to set standards and drive high‑value detection work. The position emphasizes proactive hunting, durable detections, and alignment with MITRE ATT&CK in real-world attack scenarios. This is a hands-on opportunity to shape cutting-edge security detection at scale in a fast-growing fintech environment.

Pay / Benefits

  • hybrid working model
  • opportunity for career growth and impact
  • ownership and fewer blockers
  • recognition for成果
  • supportive team culture
  • global fintech scale

Responsibilities

  • Engineer high-fidelity detections across endpoint, identity, cloud, and SaaS
  • Define detection standards, principles, and quality thresholds for Security Operations
  • Conduct proactive threat hunting based on attacker behaviour rather than vendor alerts
  • Translate threat intelligence and incident learnings into reusable detections
  • Map detections to MITRE ATT&CK and real-world attack paths
  • Reduce alert fatigue via signal refinement, correlation and enrichment
  • Advise during high-severity incidents and contribute to runbooks and escalation playbooks
  • Drive transition of advanced detection capability into Cyber Security ownership

Key requirements

  • Proven experience in detection engineering, threat hunting, or advanced SOC roles
  • Deep understanding of modern attacker tradecraft across the attack lifecycle
  • Hands-on experience building detection logic in modern SIEM platforms (e.g., Sentinel)
  • Proficiency with scripting and programming (e.g., Python, KQL) for detection pipelines and automation
  • Willingness to challenge poor detections and vanity metrics
  • Pragmatic mindset prioritising precision and impact
  • Experience operating beyond traditional SOC or MSSP models
  • Hands-on cloud detection experience (identity, control plane, SaaS)
  • Familiarity with threat intelligence platforms and frameworks such as PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud
  • Curiosity and critical thinking
  • Collaborative stakeholder engagement
  • Pragmatism with a bias for impact
  • SIEM (e.g., Microsoft Sentinel)
  • Python
  • KQL (Kusto Query Language)

Posted: September 14th, 2026