# Senior Cloud Security Engineer

[Checkout Com](https://gurify.com/jobs?q=Checkout%20Com) · London · Posted 3 months ago

Senior

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/checkout.com/1fd8071b-5fe8-4b1a-83e7-a011a901ee2c)

## Job description

### Company Description

We’re http://checkout.comCheckout.com http://Checkout.com. You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we’re behind many of the digital experiences you use every day.

We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers.

Whether you want to book a holiday, order food, renew a subscription, or check out online, there’s a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale.

If you want to do career-defining work, you’ve come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact.

With 20 offices across six continents and London as our HQ, we’re shaping the future of fintech – and we’re just getting started.

### THE ROLE

You will evolve Checkout.com http://Checkout.com's security posture across our multi-cloud environments and SIEM platform. This role sits at the intersection of cloud security engineering and detection capability — responsible for both hardening the infrastructure we operate on and ensuring we can see what's happening across it.

You will lead security integration projects, guide cloud engineering teams, and drive continuous improvement across monitoring and detection, including applying AI to accelerate security operations.

This is not a tool-monitoring role. You are here to architect secure cloud environments, build and enhance detection logic at scale, and drive measurable improvements to our security baseline across AWS, Azure, and GCP.

You will partner closely with Engineering, GRC, Technology Risk and Security Operations - defining standards, fine tuning the SIEM, and progressively taking on the most complex cloud security and detection engineering challenges across the organisation.

### WHAT YOU’LL BE RESPONSIBLE FOR

### Cloud Security

- Secure and continuously improve our multi-cloud estate (AWS, Azure, GCP) using cloud native tooling to keep our cloud infrastructure hardened and compliant

- Partner with Engineering and Security Operation team to make security a natural part of how we design and deliver, automating compliance checks so security scales without friction

- Defining and enforcing cloud security architecture standards, guardrails, and policy-as-code inline with industry best practices including NIST, CIS, and PCI DSS.

- Use Wiz or equivalent CNAPP/CSPM to continuously assess, prioritise, and drive remediation of misconfigurations and vulnerabilities against CIS, NIST, and PCI DSS benchmarks.

### Security Monitoring

- Fine tune, and maintain modern SIEM platform (e.g. Sentinel) including KQL detection rules, workbooks, logging pipelines, and AI-assisted alert triage.

- Map detection coverage against MITRE ATT&CK tactics and techniques. Identify and close visibility gaps across the cloud estate.

- Maintain alignment to PCI DSS, SOC2, ISO27001 NIST, and CIS frameworks. Produce documentation and evidence to support audit and assurance activities.

### AI Security

- Design and implement guardrails for AI/LLM systems, covering data exposure, prompt injection, and model misuse risks.

- Leverage AI and automation to enhance alert investigation, enrichment, and response workflows.

- Maintain technical policies and standards for the secure use of AI tools across the organisation.

### WHAT WE’RE LOOKING FOR

- 6+ years of hands-on experience securing AWS, Azure, and GCP environments, including Azure Policy, IAM, Infrastructure-as-code (IAC) security or other cloud native tooling.

- Experience with security tools: Microsoft Sentinel, SentinelOne, NetSkope, Flashpoint, Wiz or similar tooling.

- Strong Microsoft Sentinel expertise: KQL, detection rules, workbooks, and logging pipelines.

- Working knowledge of DLP and threat intelligence monitoring.

- Experience applying AI/ML to security workflows - automated triage, behavioural analytics, or LLM-assisted investigation.

- Understanding of AI security risks and frameworks: OWASP LLM Top 10, NIST AI RMF.

- Scripting proficiency in Python, PowerShell, or Bash for security automation.

- Strong grasp of PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud.

### NICE TO HAVE

- AZ-500, AWS Certified Security – Specialty, or equivalent cloud security certification.

- Experience integrating ATT&CK Navigator into SOC workflows.

### Additional Information

### Bring all of you to work

We create the conditions for high performers to thrive, through real ownership, fewer blockers, and work that makes a difference from day one.

Here, you’ll move fast, take on meaningful challenges, and be recognized for the impact you deliver. It’s a place where ambition gets met with opportunity, and where your growth is in your hands.

We work as one team, and we back each other to succeed. So whatever your background or identity, if you’re ready to grow and make a difference, you’ll be right at home here.

It’s important we set you up for success and make our process as accessible as possible. So let us know in your application, or tell your recruiter directly, if you need anything to make your experience or working environment more comfortable.

### Life at Checkout.com http://Checkout.com

We understand that work is just one part of your life. Our hybrid working model offers flexibility, with three days per week in the office to support collaboration and connection.

Curious about what it’s like to be part of our team? Visit our Careers Page https://www.checkout.com/careers to learn more about our culture, open roles, and what drives us.

For a closer look at daily life at Checkout.com http://Checkout.com, follow us on LinkedIn https://www.linkedin.com/company/checkout/life/ and Instagram https://www.instagram.com/checkout_com/

**Live in Checkout Com’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- IN [Senior Infrastructure and Cloud Security Engineer (m/f/d)](https://gurify.com/job/senior-infrastructure-and-cloud-security-engineer-m-f-d-at-3f7722b49cef) Internationalcopyrightenterpriseservices · London · 3 days ago
- CC [Cyber Security Engineer I](https://gurify.com/job/cyber-security-engineer-i-at-checkout-com-b3744d8ed0a5) Checkout Com · London · 2 weeks ago
- CO [Senior Cloud Native Security Engineer](https://gurify.com/job/senior-cloud-native-security-engineer-at-controlplane-1a80f4fea92c) Controlplane · London · 6 days ago
- CO [Cloud Native Security Engineer](https://gurify.com/job/cloud-native-security-engineer-at-controlplane-7b45fcfb1a4d) Controlplane · London · 6 days ago
- CO [Security Engineer](https://gurify.com/job/security-engineer-at-conduct-354c5d006329) Conduct · London, United Kingdom · last week
- HA [Senior Security Engineer, Detection and Response](https://gurify.com/job/senior-security-engineer-detection-and-response-at-hackerone-45f09130ce13) Hackerone · London · last week

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Senior Cloud Security Engineer","description":"\u003Ch3\u003ECompany Description\u003C/h3\u003E\u003Cp\u003EWe\u2019re  http://checkout.comCheckout.com http://Checkout.com. You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we\u2019re behind many of the digital experiences you use every day.\u003C/p\u003E\u003Cp\u003EWe are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers.\u003C/p\u003E\u003Cp\u003EWhether you want to book a holiday, order food, renew a subscription, or check out online, there\u2019s a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale.\u003C/p\u003E\u003Cp\u003EIf you want to do career-defining work, you\u2019ve come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact.\u003C/p\u003E\u003Cp\u003EWith 20 offices across six continents and London as our HQ, we\u2019re shaping the future of fintech \u2013 and we\u2019re just getting started.\u003C/p\u003E\u003Ch3\u003ETHE ROLE\u003C/h3\u003E\u003Cp\u003EYou will evolve Checkout.com http://Checkout.com\u0026#39;s security posture across our multi-cloud environments and SIEM platform. This role sits at the intersection of cloud security engineering and detection capability \u2014 responsible for both hardening the infrastructure we operate on and ensuring we can see what\u0026#39;s happening across it.\u003C/p\u003E\u003Cp\u003EYou will lead security integration projects, guide cloud engineering teams, and drive continuous improvement across monitoring and detection, including applying AI to accelerate security operations.\u003C/p\u003E\u003Cp\u003EThis is not a tool-monitoring role. You are here to architect secure cloud environments, build and enhance detection logic at scale, and drive measurable improvements to our security baseline across AWS, Azure, and GCP.\u003C/p\u003E\u003Cp\u003EYou will partner closely with Engineering, GRC, Technology Risk and Security Operations - defining standards, fine tuning the SIEM, and progressively taking on the most complex cloud security and detection engineering challenges across the organisation.\u003C/p\u003E\u003Ch3\u003EWHAT YOU\u2019LL BE RESPONSIBLE FOR\u003C/h3\u003E\u003Ch3\u003ECloud Security\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ESecure and continuously improve our multi-cloud estate (AWS, Azure, GCP) using cloud native tooling to keep our cloud infrastructure hardened and compliant\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPartner with Engineering and Security Operation team to make security a natural part of how we design and deliver, automating compliance checks so security scales without friction\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDefining and enforcing cloud security architecture standards, guardrails, and policy-as-code inline with industry best practices including NIST, CIS, and PCI DSS.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EUse Wiz or equivalent CNAPP/CSPM to continuously assess, prioritise, and drive remediation of misconfigurations and vulnerabilities against CIS, NIST, and PCI DSS benchmarks.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ESecurity Monitoring\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EFine tune, and maintain modern SIEM platform (e.g. Sentinel) including KQL detection rules, workbooks, logging pipelines, and AI-assisted alert triage.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMap detection coverage against MITRE ATT\u0026amp;CK tactics and techniques. Identify and close visibility gaps across the cloud estate.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMaintain alignment to PCI DSS, SOC2, ISO27001 NIST, and CIS frameworks. Produce documentation and evidence to support audit and assurance activities.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EAI Security\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EDesign and implement guardrails for AI/LLM systems, covering data exposure, prompt injection, and model misuse risks.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELeverage AI and automation to enhance alert investigation, enrichment, and response workflows.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMaintain technical policies and standards for the secure use of AI tools across the organisation.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWHAT WE\u2019RE LOOKING FOR\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E6\u002B years of  hands-on experience securing AWS, Azure, and GCP environments, including Azure Policy, IAM, Infrastructure-as-code (IAC) security or other cloud native tooling.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with security tools: Microsoft Sentinel, SentinelOne, NetSkope, Flashpoint, Wiz or similar tooling.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong Microsoft Sentinel expertise: KQL, detection rules, workbooks, and logging pipelines.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWorking knowledge of DLP and threat intelligence monitoring.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience applying AI/ML to security workflows - automated triage, behavioural analytics, or LLM-assisted investigation.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EUnderstanding of AI security risks and frameworks: OWASP LLM Top 10, NIST AI RMF.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EScripting proficiency in Python, PowerShell, or Bash for security automation.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong grasp of PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT\u0026amp;CK for Cloud.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ENICE TO HAVE\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EAZ-500, AWS Certified Security \u2013 Specialty, or equivalent cloud security certification.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience integrating ATT\u0026amp;CK Navigator into SOC workflows.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EAdditional Information\u003C/h3\u003E\u003Ch3\u003EBring all of you to work\u003C/h3\u003E\u003Cp\u003EWe create the conditions for high performers to thrive, through real ownership, fewer blockers, and work that makes a difference from day one.\u003C/p\u003E\u003Cp\u003EHere, you\u2019ll move fast, take on meaningful challenges, and be recognized for the impact you deliver. It\u2019s a place where ambition gets met with opportunity, and where your growth is in your hands.\u003C/p\u003E\u003Cp\u003EWe work as one team, and we back each other to succeed. So whatever your background or identity, if you\u2019re ready to grow and make a difference, you\u2019ll be right at home here.\u003C/p\u003E\u003Cp\u003EIt\u2019s important we set you up for success and make our process as accessible as possible. So let us know in your application, or tell your recruiter directly, if you need anything to make your experience or working environment more comfortable.\u003C/p\u003E\u003Ch3\u003ELife at Checkout.com http://Checkout.com\u003C/h3\u003E\u003Cp\u003EWe understand that work is just one part of your life. Our hybrid working model offers flexibility, with three days per week in the office to support collaboration and connection.\u003C/p\u003E\u003Cp\u003ECurious about what it\u2019s like to be part of our team? Visit our Careers Page https://www.checkout.com/careers to learn more about our culture, open roles, and what drives us.\u003C/p\u003E\u003Cp\u003EFor a closer look at daily life at Checkout.com http://Checkout.com, follow us on LinkedIn https://www.linkedin.com/company/checkout/life/ and Instagram https://www.instagram.com/checkout_com/\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"senior-cloud-security-engineer-at-checkout-com-cc8e3f75d7e3"},"url":"https://gurify.com/job/senior-cloud-security-engineer-at-checkout-com-cc8e3f75d7e3","datePosted":"2026-05-26","validThrough":"2026-11-04T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Checkout Com","sameAs":"https://jobs.ashbyhq.com/checkout.com"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"GB","addressLocality":"London"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United Kingdom","item":"https://gurify.com/jobs/united-kingdom"},{"@type":"ListItem","position":3,"name":"Senior Cloud Security Engineer","item":"https://gurify.com/job/senior-cloud-security-engineer-at-checkout-com-cc8e3f75d7e3"}]}
```
