At a Glance
- Tasks: Secure and enhance our multi-cloud environments while driving AI-powered security improvements.
- Company: Join Checkout.com, a leader in fintech powering major brands like eBay and Spotify.
- Benefits: Flexible hybrid work model, competitive salary, and opportunities for personal growth.
- Other info: Collaborative culture where your ambition meets opportunity and growth is in your hands.
- Why this job: Make a real impact on cloud security and shape the future of digital payments.
- Qualifications: 6+ years in cloud security with expertise in AWS, Azure, and GCP.
The predicted salary is between 70000 - 90000 £ per year.
We’re Checkout.com. You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we’re behind many of the digital experiences you use every day. We are where the world checks out, enabling over 10 billion transactions daily for more than one billion global shoppers. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale.
The role involves evolving Checkout.com's security posture across our multi-cloud environments and SIEM platform. This role sits at the intersection of cloud security engineering and detection capability — responsible for both hardening the infrastructure we operate on and ensuring we can see what's happening across it.
You will lead security integration projects, guide cloud engineering teams, and drive continuous improvement across monitoring and detection, including applying AI to accelerate security operations. This is not a tool-monitoring role. You are here to architect secure cloud environments, build and enhance detection logic at scale, and drive measurable improvements to our security baseline across AWS, Azure, and GCP.
You will partner closely with Engineering, GRC, Technology Risk and Security Operations - defining standards, fine tuning the SIEM, and progressively taking on the most complex cloud security and detection engineering challenges across the organisation.
What you’ll be responsible for:
- Cloud Security: Secure and continuously improve our multi-cloud estate (AWS, Azure, GCP) using cloud native tooling to keep our cloud infrastructure hardened and compliant. Partner with Engineering and Security Operation team to make security a natural part of how we design and deliver, automating compliance checks so security scales without friction. Defining and enforcing cloud security architecture standards, guardrails, and policy-as-code inline with industry best practices including NIST, CIS, and PCI DSS. Use Wiz or equivalent CNAPP/CSPM to continuously assess, prioritise, and drive remediation of misconfigurations and vulnerabilities against CIS, NIST, and PCI DSS benchmarks.
- Security Monitoring: Fine tune, and maintain modern SIEM platform (e.g. Sentinel) including KQL detection rules, workbooks, logging pipelines, and AI-assisted alert triage. Map detection coverage against MITRE ATT&CK tactics and techniques. Identify and close visibility gaps across the cloud estate. Maintain alignment to PCI DSS, SOC2, ISO27001 NIST, and CIS frameworks. Produce documentation and evidence to support audit and assurance activities.
- AI Security: Design and implement guardrails for AI/LLM systems, covering data exposure, prompt injection, and model misuse risks. Leverage AI and automation to enhance alert investigation, enrichment, and response workflows. Maintain technical policies and standards for the secure use of AI tools across the organisation.
What we’re looking for:
- 6+ years of hands-on experience securing AWS, Azure, and GCP environments, including Azure Policy, IAM, Infrastructure-as-code (IAC) security or other cloud native tooling.
- Experience with security tools: Microsoft Sentinel, SentinelOne, NetSkope, Flashpoint, Wiz or similar tooling.
- Strong Microsoft Sentinel expertise: KQL, detection rules, workbooks, and logging pipelines.
- Working knowledge of DLP and threat intelligence monitoring.
- Experience applying AI/ML to security workflows - automated triage, behavioural analytics, or LLM-assisted investigation.
- Understanding of AI security risks and frameworks: OWASP LLM Top 10, NIST AI RMF.
- Scripting proficiency in Python, PowerShell, or Bash for security automation.
- Strong grasp of PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud.
Nice to have:
- AZ-500, AWS Certified Security – Specialty, or equivalent cloud security certification.
- Experience integrating ATT&CK Navigator into SOC workflows.
We create the conditions for high performers to thrive, through real ownership, fewer blockers, and work that makes a difference from day one. Here, you’ll move fast, take on meaningful challenges, and be recognized for the impact you deliver. It’s a place where ambition gets met with opportunity, and where your growth is in your hands.
We work as one team, and we back each other to succeed. So whatever your background or identity, if you’re ready to grow and make a difference, you’ll be right at home here.
It’s important we set you up for success and make our process as accessible as possible. So let us know in your application, or tell your recruiter directly, if you need anything to make your experience or working environment more comfortable.
We understand that work is just one part of your life. Our hybrid working model offers flexibility, with three days per week in the office to support collaboration and connection.
Cloud Platform Security Engineer in London employer: Checkout.com
At Checkout.com, we pride ourselves on being an exceptional employer that fosters a culture of innovation and collaboration. Our London headquarters offers a dynamic work environment where you can take ownership of your projects and make a real impact from day one. With a strong focus on employee growth, flexible hybrid working arrangements, and a commitment to diversity and inclusion, we empower our team members to thrive both personally and professionally.
StudySmarter Expert Advice🤫
We think this is how you could land Cloud Platform Security Engineer in London
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can refer you directly.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your cloud security projects. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by brushing up on common cloud security scenarios and challenges. Practice articulating how you've tackled similar issues in the past, and be ready to discuss your experience with AWS, Azure, and GCP.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in being part of our team at Checkout.com.
We think you need these skills to ace Cloud Platform Security Engineer in London
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter for the Cloud Platform Security Engineer role. Highlight your experience with AWS, Azure, and GCP, and show us how your skills align with our needs. We want to see how you can make an impact!
Showcase Your Technical Skills:Don’t hold back on showcasing your technical expertise! Mention your hands-on experience with security tools like Microsoft Sentinel and your scripting skills in Python or PowerShell. We love seeing candidates who can hit the ground running.
Be Clear and Concise:When writing your application, keep it clear and to the point. Use bullet points where possible to make it easy for us to read. We appreciate a well-structured application that gets straight to the good stuff!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, you’ll get to explore more about our culture and values while you’re at it!
How to prepare for a job interview at Checkout.com
✨Know Your Cloud Security Stuff
Make sure you brush up on your knowledge of AWS, Azure, and GCP. Be ready to discuss specific security measures you've implemented in these environments, as well as any tools like Microsoft Sentinel or Wiz that you've used. This will show that you're not just familiar with the theory but have practical experience.
✨Showcase Your Problem-Solving Skills
Prepare to share examples of how you've tackled complex cloud security challenges in the past. Think about times when you had to harden infrastructure or improve detection capabilities. Use the STAR method (Situation, Task, Action, Result) to structure your answers clearly.
✨Get Familiar with Compliance Standards
Since compliance is a big deal for this role, make sure you understand frameworks like PCI DSS, NIST, and CIS. Be ready to discuss how you've ensured compliance in previous roles and how you would approach it at Checkout.com.
✨Ask Insightful Questions
Interviews are a two-way street! Prepare thoughtful questions about Checkout.com's security posture, team dynamics, and future projects. This shows your genuine interest in the role and helps you assess if the company is the right fit for you.