Cyber Security Engineer at Checkout.com

  • Company: Checkout.com
  • Location: London
  • Job type: full time
  • Workplace: onsite
  • Posted: 2026-05-26

Apply for this role

Job description

Company Description We’re Checkout.com. You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we’re behind many of the digital experiences you use every day. We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers. Whether you want to book a holiday, order food, renew a subscription, or check out online, there’s a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale. If you want to do career-defining work, you’ve come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact. With 20 offices across six continents and London as our HQ, we’re shaping the future of fintech – and we’re just getting started. The role This role will be responsible for supporting design & implementation of AI-enabled capabilities across Checkout, while ensuring AI technologies are deployed in a safe, governed, and resilient manner. The successful candidate will work closely with Engineering, Data Governance, GRC, and business teams to embed security into AI systems, assess AI-related risks, and help the organisation adopt AI securely at scale. As a Cyber Security Engineer I, you will act as the bridge between cyber security and emerging AI technologies. You will help shape how Checkout secures AI tools, models, data pipelines, and supporting infrastructure, while also identifying opportunities to use AI to strengthen cyber defence capabilities. This is a hands-on role suited to someone who understands modern security engineering and has a strong interest in AI/ML technologies, LLMs, automation, and risk management. What you’ll be responsible for • Design and implement security controls for AI and machine learning solutions, including LLM-based applications, model integrations, and supporting cloud infrastructure. • Assess the security, privacy, and compliance risks associated with AI systems, including model misuse, prompt injection, data leakage, insecure plugins, over-permissioned access, and third-party AI services. • Develop standards, guardrails, and reference architectures for the secure use of AI across the organisation. • Review AI use cases, architectures, and deployments to ensure alignment with cyber security policies, regulatory requirements, and internal governance expectations. • Build and maintain monitoring, detection, and response capabilities for AI-related threats and misuse scenarios. • Identify opportunities to use AI to enhance cyber security operations, such as alert triage, threat analysis, playbook automation, knowledge retrieval, and workflow optimisation. • Stay current on evolving risks, attack techniques, regulations, and industry practices related to AI security and AI governance (inline with EU AI Act, ISO42001) What we’re looking for • Experience in cyber security engineering, security architecture, or a related security role. • Strong understanding of core security domains such as identity and access management, cloud security, application security, data protection, logging and monitoring, and incident response. • Knowledge of AI/ML and LLM concepts, including model deployment patterns, APIs, embeddings, vector stores, prompt handling, and common AI security risks. • Experience securing cloud environments and modern development workflows in platforms such as AWS, Azure, or GCP. • Familiarity with security risks relevant to AI systems, including prompt injection, data exfiltration, insecure model access, supply chain risks, model poisoning, and sensitive data exposure. • Experience conducting architecture reviews, threat modelling, and security assessments for complex technical solutions. • Ability to translate technical risk into clear, practical guidance for both engineering and non-technical

Cyber Security Engineer on JobPost.