Detection & Threat Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+1 more
Job description
You will own and evolve the companyâs threat detection and threat-hunting capability. This role defines what âgoodâ looks like for detection and increasingly engineers it directly as capability shifts into Cyber Security.
This is not an alert-triage role. You are here to understand attacker behaviour, convert it into high-fidelity detection logic, and raise the security baseline for the entire organisation.
You will partner closely with Security Operations, GRC and Engineering-setting standards, direction, and expectations-while progressively taking ownership of the most complex and high-value detection and threat engineering work.
What youâll be responsible for
- Engineering high-fidelity threat detections across endpoint, identity, cloud, and SaaS
- Defining detection standards, principles, and quality thresholds for Security Operations
- Conducting proactive threat hunting based on attacker behaviour, not vendor alerts
- Translating threat intelligence and incident learnings into durable, reusable detections
- Mapping detections to MITRE ATT&CK and real-world attack paths
- Reducing alert fatigue through logic refinement, correlation, and contextual enrichment
- Advising and supporting during high-severity security incidents; contribute to runbooks and escalation playbooks
- Driving the transition of advanced detection capability into Cyber Security ownership
Requirements
Do you have experience in SaaS?, * Proven experience in detection engineering, threat hunting, or advanced SOC roles
- Deep understanding of modern attacker tradecraft and intrusion techniques across the attack lifecycle
- Hands-on experience buidling detection logic in modern SIEM platforms (e.g Sentinel)
- Proficienty with scripting and programmaining (e.g. Python, KQL) to build detection pipelines and automation
- Willingness to challenge bad detections, weak assumptions, and vanity metrics
- Pragmatic mindset: precision and impact beat coverage theatre
- Experience operating beyond traditional SOC or MSSP models
- Hands-on cloud detection experience (identity, control plane, SaaS)
- Familiarity with threat intelligence platforms and frameworks such as PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud.
About the company
Weâre Checkout.com. You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because weâre behind many of the digital experiences you use every day.
We are where the world checks out, enabling over 10 billion transactions daily for more than one billion global shoppers.
Whether you want to book a holiday, order food, renew a subscription, or check out online, thereâs a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale.
If you want to do career-defining work, youâve come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact.
With 20 offices across six continents and London as our HQ, weâre shaping the future of fintech - and weâre just getting started., We create the conditions for high performers to thrive, through real ownership, fewer blockers, and work that makes a difference from day one.
Here, youâll move fast, take on meaningful challenges, and be recognized for the impact you deliver. Itâs a place where ambition gets met with opportunity, and where your growth is in your hands.
We work as one team, and we back each other to succeed. So whatever your background or identity, if youâre ready to grow and make a difference, youâll be right at home here.
Itâs important we set you up for success and make our process as accessible as possible. So let us know in your application, or tell your recruiter directly, if you need anything to make your experience or working environment more comfortable.
Life at Checkout.com
We understand that work is just one part of your life. Our hybrid working model offers flexibility, with three days per week in the office to support collaboration and connection.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 191: Malware interviews, EU â¤ď¸ Open Source and Skilled Agents
Dev Digest 134 - Where pixels sing?