Information Security Analyst Information security London

Information Security Analyst Information security London

London Full-Time 49500 - 60500 £ / year (est.) Home office (partial)
Checkout Ltd

At a Glance

  • Tasks: Join us as an Information Security Analyst and protect digital experiences for global brands.
  • Company: Checkout.com, a leading fintech powering payments for eBay, Spotify, and more.
  • Benefits: Competitive salary, flexible working, and opportunities for professional growth.
  • Other info: Collaborative culture with excellent career advancement opportunities.
  • Why this job: Make a real impact in the fast-paced world of information security.
  • Qualifications: 1-2 years in information security or related fields; familiarity with compliance frameworks.

The predicted salary is between 49500 - 60500 £ per year.

Company Description

We're Checkout. com.

You might not know our name, but companies like e Bay, Spotify, Klarna, Uber, and Sony do, because we’re behind many of the digital experiences you use every day.

We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers.

Whether you want to book a holiday, order food, renew a subscription, or check out online, there’s a good chance our tech powers the payments behind the scenes.

Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale.

If you want to do career-defining work, you’ve come to the right place.

We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact.

With 20 offices across six continents and London as our HQ, we’re shaping the future of fintech – and we’re just getting started.

The Role

As an Information Security Analyst at Checkout. com, you will work across the full breadth of the information security function, spanning Governance, Risk and Compliance (GRC), AI Governance, Application Security (App Sec), Technology Risk, and Data Governance.

This is a role for someone who has built a solid foundation in information security and is ready to move from guided execution to genuine ownership of tasks and smaller workstreams.

Security at Checkout operates at scale and at pace.

We are a global payments business, regulated across multiple jurisdictions, building infrastructure that processes billions of transactions.

Our security function needs analysts who understand how different domains fit together, communicate clearly with technical and non-technical colleagues, and take accountability for the quality of their work.

At L2 you will implement security controls, respond to security incidents, identify risks, and support compliance activities across multiple domains.

You work independently for extended periods and are developing the cross-domain knowledge and stakeholder skills that will prepare you for programme ownership at L3 and beyond.

  • How You'll Make Impact
  • Governance, Risk and Compliance
  • Support workstreams within Checkout's GRC programme, including ISO 27001, SOC 2, PCI DSS, and applicable regulatory obligations across our global licensed entities.
  • Assist with control evidence collection activities, coordinating with internal teams to gather accurate and timely evidence in support of audit readiness.
  • Maintain GRC documentation including policies, standards, procedures, and control matrices under the guidance of senior colleagues.
  • Support monitoring of the risk register, tracking remediation activity against agreed timelines and escalating where commitments are at risk.
  • Assist in conducting third‑party risk assessments, evaluating supplier security controls in line with Checkout's TPRM framework.
  • Develop working knowledge of regulatory obligations across Checkout's operating markets, including FCA/PRA requirements, payment scheme rules, and DORA.
  • AI Governance
  • Support the operationalisation of Checkout's AI governance framework, aligned to ISO 42001, the EU AI Act, and NIST AI RMF.
  • Assist in conducting AI risk assessments for internal AI and ML systems and third‑party AI tools, under the guidance of more senior analysts.
  • Help maintain an inventory of AI use cases and associated risk classifications, working with product and engineering teams as directed.
  • Develop awareness of the evolving regulatory landscape for AI in financial services and contribute to policy and control documentation.
  • Contribute to the development and communication of responsible AI usage guidance for staff, helping teams across the business understand acceptable use boundaries, data handling expectations, and the risks associated with AI tools in a regulated environment.
  • Application Security
  • Contribute to Checkout's application security programme, including support for secure code review processes, SDLC integration, and developer security guidance.
  • Support threat modelling activities for new and existing products, identifying security requirements under the guidance of senior colleagues.
  • Assist in managing vulnerability findings from penetration tests, bug bounty programmes, and automated tooling, tracking remediation and validating fixes.
  • Apply knowledge of the OWASP Top 10 and secure development frameworks to practical security reviews and guidance activities.
  • Technology Risk
  • Support technology risk assessments across infrastructure, cloud environments, and third‑party systems, contributing to outputs with actionable treatment recommendations.
  • Assist with control assurance activities including vulnerability scanning coordination, access control assessments, and firewall and configuration reviews.
  • Develop an understanding of Checkout's technology risk landscape, identifying emerging threats and contributing inputs to the risk register.
  • Support DORA‑related ICT risk management activities under the direction of senior analysts.
  • Data Governance
  • Support Checkout's data governance programme, including data classification activities, data flow mapping, and enforcement of data handling standards.
  • Assist with data loss prevention (DLP) controls and tooling, contributing to activities that ensure sensitive data is protected throughout its lifecycle.
  • Help maintain records of processing activities (Ro PA) and support data protection impact assessments (DPIAs) for new systems.
  • Develop working knowledge of GDPR, UK GDPR, and applicable regional data protection requirements as they affect Checkout's operations.
  • Cross‑domain Collaboration
  • Work with Engineering, Product, Legal, Procurement, Finance, and Compliance teams to support the embedding of security requirements into processes, systems, and projects.
  • Respond to security due diligence requests from merchants, partners, and regulators with accuracy and within agreed SLAs, escalating complex queries appropriately.
  • Communicate clearly with internal stakeholders on security requirements, keeping teams updated on changes and project progress.
  • Contribute to security awareness initiatives, promoting a security‑conscious culture across Checkout.

What We're Looking for

Experience

  • 1 to 2 years of experience in information security, IT audit, or a closely related function, ideally within payments, financial services, or fintech.
  • Working knowledge of at least one of the following domains: GRC, App Sec, technology risk, or data governance.
  • Practical familiarity with at least one compliance framework: PCI DSS, ISO 27001, SOC 2, NIST CSF, or equivalent.
  • Some exposure to external audits, risk assessments, or security assurance activities.
  • Ability to manage tasks independently and deliver on commitments reliably.

Skills and Approach

  • Clear written and verbal communication. You can translate security concepts for technical and non‑technical audiences.
  • Detail‑oriented and methodical. You approach your work carefully and follow through consistently.
  • Curious and proactive. You ask questions, flag issues early, and look for root causes rather than surface fixes.
  • Collaborative and adaptable. You work effectively across teams and adjust your approach as priorities shift.
  • Receptive to feedback and committed to developing your information security skills across multiple domains.
  • Preferred
  • Pursuing or holding a relevant certification: Comp TIA Security+, CISA (in progress), ISO 27001 Foundation, or equivalent.
  • Familiarity with cloud environments (AWS, Azure, GCP) from a security or compliance perspective.
  • Exposure to security or GRC tooling such as Wiz, Qualys, Microsoft Sentinel, Service Now GRC, or similar.
  • Awareness of AI governance frameworks or the OWASP LLM Top 10.
  • Some scripting or automation experience (Python, etc.) is a plus.
  • #J-18808-Ljbffr

Information Security Analyst Information security London employer: Checkout Ltd

Checkout Ltd is an exceptional employer that fosters a dynamic and inclusive work culture, where collaboration and innovation thrive. With a strong focus on employee growth, the company offers ample opportunities for professional development while embracing a hybrid working model that promotes flexibility. Located in London, employees benefit from a vibrant city atmosphere, making it an ideal place for those seeking meaningful and rewarding careers in the legal field.

Checkout Ltd

Contact Details:

Checkout Ltd Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Analyst Information security London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Checkout Ltd, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Checkout Ltd

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Checkout Ltd. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Information Security Analyst Information security London

Information Security
Governance, Risk and Compliance (GRC)
AI Governance
Application Security (AppSec)
Technology Risk
Data Governance
ISO 27001

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Checkout Ltd insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Checkout Ltd that you’re committed to staying ahead in the game.

How to prepare for a job interview at Checkout Ltd

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Checkout Ltd to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Checkout Ltd.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.