Senior Cloud Security Engineer

Checkout.comApplyPublished 2 days agoFirst seen 2 hours ago
Apply

Company Description

We’re Checkout.com. You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we’re behind many of the digital experiences you use every day.

We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers.

Whether you want to book a holiday, order food, renew a subscription, or check out online, there’s a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale.

If you want to do career-defining work, you’ve come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact.

With 20 offices across six continents and London as our HQ, we’re shaping the future of fintech – and we’re just getting started.

The role

Checkout.com is scaling a multi-cloud environment at pace, and security architecture is central to how we do it safely.

As Senior Cloud Security Engineer, you'll work closely with Engineering, GRC, Technology Risk, and Security Operations to embed security into every design decision and to make sure we can see what's happening across the estate once it's live.

You'll help embed security within the design phase and ongoing operations of our multi-cloud posture, define guardrails and policy-as-code standards, and support the strengthening of our SIEM and detection capability. You'll take on the most complex and ambiguous cloud security challenges in the business, and hold engineers to best practices.

This isn't a tool-monitoring role. You're here to lead security-by-design, set best-practice standards, and raise the bar.

What You'll Be Doing

  • Develop and enforce reference security architectures, patterns, and blueprints for secure cloud adoption across AWS, Azure, and GCP.
  • Conduct security assessments for new cloud services, defining preventative and detective controls (via security guardrails) to maintain secure posture and detect drift.
  • Partner with Engineering teams to embed security guardrails early in design, ensuring compliance and resilience without adding friction.
  • Evaluate engineering and platform architecture proposals, identifying security gaps and seeing remediation through to completion.
  • Document and uphold secure-by-design principles and architecture governance, and enforce policy-as-code frameworks aligned with NIST, CIS, and PCI DSS.
  • Set the monitoring scope and priorities for CNAPP/CSPM tooling (e.g. Wiz or equivalent), defining which misconfigurations and vulnerabilities matter most against CIS, NIST, and PCI DSS benchmarks, and holding engineering teams accountable to remediation outcomes.
  • Work with Security Operations to shape cloud logging and detection requirements, ensuring our SIEM has the right visibility across the estate.
  • Collaborate with senior stakeholders to articulate security risks and mitigations in terms that support business decision-making.

Skills and Experience We're Looking For

We're looking for someone with strong technical expertise and a genuine passion for security. Here's what we need:

  • Risk-based decision-making and adherence to regulatory and internal security standards (PCI DSS, NIST, SOC 2, ISO 27001, CIS).
  • Broad knowledge across security domains and their capabilities within AWS, Azure, and GCP, with 6+ years' hands-on experience and SME depth in at least one platform.
  • Kubernetes (EKS/AKS/GKE), API security, and IaC security (e.g. Terraform, CloudFormation, ARM templates).
  • Securing user and non-user access at scale, including Azure Policy and cloud-native IAM controls.
  • Demonstrated ability to provide clear, security-focused guidance, combined with excellent communication and senior-stakeholder engagement skills, and experience mentoring other engineers.

Nice to Have

  • CISSP, CCSP, or equivalent certifications.
  • AZ-500, AWS Certified Security, Google Professional Cloud Security Engineer, or equivalent cloud security certification.
  • Microsoft Certified: Azure Solutions Architect Expert, or Google Professional Cloud Architect.
  • Experience integrating ATT&CK Navigator into SOC workflows.

Additional Information

Bring all of you to work

We create the conditions for high performers to thrive, through real ownership, fewer blockers, and work that makes a difference from day one.

Here, you’ll move fast, take on meaningful challenges, and be recognized for the impact you deliver. It’s a place where ambition gets met with opportunity, and where your growth is in your hands.

We work as one team, and we back each other to succeed. So whatever your background or identity, if you’re ready to grow and make a difference, you’ll be right at home here.

It’s important we set you up for success and make our process as accessible as possible. So let us know in your application, or tell your recruiter directly, if you need anything to make your experience or working environment more comfortable.

Life at Checkout.com

We understand that work is just one part of your life. Our hybrid working model offers flexibility, with three days per week in the office to support collaboration and connection.

Curious about what it’s like to be part of our team? Visit our Careers Page to learn more about our culture, open roles, and what drives us.

For a closer look at daily life at Checkout.com, follow us on LinkedIn and Instagram