Overview
In this role you will elevate Checkout.com’s security posture across AWS, Azure, and GCP, focusing on secure cloud design and scalable detection. You will lead security integration projects, guide cloud engineering teams, and drive continuous improvements in monitoring and AI‑assisted response. You’ll partner with Engineering, GRC, and Security Operations to define standards and refine visibility across the multi‑cloud estate. This is a hands‑on, architecture‑driven position that combines cloud security, detection engineering, and AI guardrails to reduce risk at scale. You’ll work in a fast‑paced fintech environment where secure, compliant delivery enables global digital payments.”
Pay / Benefits
- hybrid working model with three days in the office
- opportunity for growth and impact
- team‑driven culture
- recognition for delivery of impactful work
- supportive environment for diverse backgrounds
- flexible, accessible recruitment process
Responsibilities
- Secure and continuously improve multi‑cloud estate (AWS, Azure, GCP) using cloud native tooling to harden and ensure compliance
- Collaborate with Engineering and Security Operations to embed security into design and delivery, automating compliance checks for scalable security
- Define and enforce cloud security architecture standards, guardrails, and policy‑as‑code aligned with NIST, CIS, PCI DSS
- Use Wiz or CNAPP/CSPM tools to assess, prioritize, and remediate misconfigurations and vulnerabilities against CIS, NIST, PCI DSS
- Fine tune and maintain SIEM platform (e.g., Microsoft Sentinel) with KQL rules, workbooks, logging pipelines, and AI‑assisted alert triage
- Map detection coverage to MITRE ATT&CK tactics and close visibility gaps across the cloud estate
- Maintain alignment to PCI DSS, SOC2, ISO27001, NIST, CIS frameworks; produce audit‑ready documentation
- Design and implement AI/LLM guardrails to mitigate data exposure, prompt injection, and model misuse risks
- Leverage AI to enhance alert investigation, enrichment, and incident response workflows
- Maintain technical standards for secure use of AI tools across the organisation
Key requirements
- 6+ years of hands‑on experience securing AWS, Azure, and GCP environments
- Experience with Azure Policy, IAM, IAC security or equivalents
- Proficiency with security tools including Microsoft Sentinel, SentinelOne, NetSkope, Flashpoint, Wiz
- Strong Microsoft Sentinel expertise: KQL, detection rules, workbooks, logging pipelines
- Knowledge of DLP and threat intelligence monitoring
- Experience applying AI/ML to security workflows; understanding of AI security risks and frameworks (OWASP LLM Top 10, NIST AI RMF)
- Scripting in Python, PowerShell, or Bash for security automation
- Solid understanding of PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, MITRE ATT&CK for Cloud
- Nice to have: cloud security certifications (AZ-500, AWS Certified Security – Specialty)
- Experience integrating ATT&CK Navigator into SOC workflows
- collaboration with cross‑functional teams
- strong communication
- problem solving
- AWS
- Azure
- GCP
…
