Senior Detection & Threat Engineer
checkout.com · London
Job description
About the role
You will own and evolve the company’s threat detection and threat‑hunting capability. This role defines what “good” looks like for detection and increasingly engineers it directly as capability shifts into Cyber Security. It is not an alert‑triage role; you will understand attacker behaviour, convert it into high‑fidelity detection logic, and raise the security baseline for the entire organisation.
Key responsibilities
- Engineer high‑fidelity threat detections across endpoint, identity, cloud, and SaaS environments.
- Define detection standards, principles, and quality thresholds for Security Operations.
- Conduct proactive threat hunting based on attacker behaviour rather than vendor alerts.
- Translate threat intelligence and incident learnings into durable, reusable detections.
- Map detections to MITRE ATT&CK and real‑world attack paths.
- Reduce alert fatigue through logic refinement, correlation, and contextual enrichment.
- Advise and support during high‑severity security incidents and contribute to runbooks and escalation playbooks.
- Drive the transition of advanced detection capability into Cyber Security ownership.
Required profile
- Proven experience in detection engineering, threat hunting, or advanced SOC roles.
- Deep understanding of modern attacker tradecraft and intrusion techniques across the attack lifecycle.
- Hands‑on experience building detection logic in modern SIEM platforms (e.g., Sentinel).
- Proficiency with scripting and programming (e.g., Python, KQL) to build detection pipelines and automation.
- Willingness to challenge weak detections, vanity metrics, and prioritize precision and impact.
- Experience operating beyond traditional SOC or MSSP models, including cloud detection (identity, control plane, SaaS).
- Familiarity with threat intelligence platforms and frameworks such as PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud.
Required skills
- SIEM platforms (Sentinel)
- Python programming
- KQL query language
- Cloud detection (identity, control plane, SaaS)
- MITRE ATT&CK framework
- PCI DSS compliance
- NIST Cybersecurity Framework
- SOC 2 standards
- ISO 27001 certification
- CIS Benchmarks
- Threat intelligence platforms
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the United Kingdom.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 2 hours ago
Expires 1 month from now
3 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
checkout.com
London