Skip to main content
AfterDuty

Senior Security Incident Response Engineer

Checkout.com · London, Greater London

Type
Full-time
Posted
8 days ago

Overview

Your incident command and investigative discipline under pressure transfer directly to leading security incident response.

About this role

Company Description

We’re Checkout.com. You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we’re behind many of the digital experiences you use every day.

We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers.

Whether you want to book a holiday, order food, renew a subscription, or check out online, there’s a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale.

If you want to do career-defining work, you’ve come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact.

With 20 offices across six continents and London as our HQ, we’re shaping the future of fintech – and we’re just getting started.

The role

This role exists to ensure security incidents are rare, contained, and unsurprising.

You will own the technical direction of security incident response and response readiness across the company. When a serious incident occurs, you lead from the front — investigating, containing, and driving resolution with calm authority. When incidents are not happening, you are actively eliminating the conditions that would cause the next one.

This is not a role for someone who waits for alerts. It is for someone who constantly asks “what will break next, and why?” — and then fixes that problem before an attacker finds it.

You will operate across endpoint, identity, cloud, and SaaS environments, working closely with Security Operations, IT, and Engineering to reduce real risk, not theoretical risk.

What You’ll Be Responsible For

Incident Response & Technical Leadership

  • Leading the end-to-end technical response to high-severity security incidents
  • Owning investigation, containment, eradication, and recovery activities
  • Acting as the senior technical authority during live incidents
  • Providing clear, decisive guidance to Security Operations under pressure
  • Coordinating response across endpoint, identity, cloud, and SaaS platforms
  • Supplying executives, legal, and risk stakeholders with accurate technical context and impact assessments
  • Ensuring incidents are driven to resolution, not just stabilised

Response Readiness & Proactive Risk Reduction

  • Designing, maintaining, and continuously improving incident response playbooks and runbooks
  • Identifying systemic weaknesses that increase incident likelihood or blast radius, including:
  • Unpatched or inconsistently patched systems
  • Exposed services and misconfigurations
  • Degraded or ineffective controls
  • Using SIEM and security tooling to prioritise patching and vulnerability risk based on real exposure and exploitability, not CVSS scores alone
  • Partnering with IT, Cloud, and Engineering teams to drive remediation based on business risk
  • Tracking remediation through to completion and validating effectiveness post-fix

Learning, Detection, and Maturity

  • Turning incidents, near-misses, and exposure findings into:
  • Improved detections
  • Stronger preventative controls
  • Faster and less disruptive response
  • Driving readiness through simulations, tabletop exercises, and scenario testing
  • Raising the overall maturity of the Cyber Security function by pushing advanced response and exposure management practices into BAU operations

What We’re Looking For

  • Proven, hands-on experience leading response to real security incidents
  • Strong investigation capability across endpoint, identity, and cloud environments
  • Demonstrated experience prioritising vulnerability or patching risk in large, complex estates
  • Ability to remain decisive and effective during incidents, and analytical between them
  • Clear communicator who can influence outcomes without needing direct ownership of every fix
  • Pragmatic mindset: reduce risk first, optimise later
  • DFIR, forensics, or malware analysis experience
  • Proven ability to correlate vulnerability data with runtime telemetry and attacker behaviour to drive actionable risk reduction
  • Cloud-first incident response or exposure management experience
  • Exposure to compliance-driven security requirements
  • Experience working alongside vulnerability scanning platforms without being constrained by them

Additional Information

Bring all of you to work

We create the conditions for high performers to thrive, through real ownership, fewer blockers, and work that makes a difference from day one.

Here, you’ll move fast, take on meaningful challenges, and be recognized for the impact you deliver. It’s a place where ambition gets met with opportunity, and where your growth is in your hands.

We work as one team, and we back each other to succeed. So whatever your background or identity, if you’re ready to grow and make a difference, you’ll be right at home here.

It’s important we set you up for success and make our process as accessible as possible. So let us know in your application, or tell your recruiter directly, if you need anything to make your experience or working environment more comfortable.

*Life at*Checkout.com

We understand that work is just one part of your life. Our hybrid working model offers flexibility, with three days per week in the office to support collaboration and connection.

Curious about what it’s like to be part of our team? Visit our Careers Page to learn more about our culture, open roles, and what drives us.

For a closer look at daily life at Checkout.com, follow us on LinkedIn and Instagram

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background — match score 65/100

  • Incident command & response
  • Investigative casework
  • Working to legislation & regulation
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • £35,000 – £40,000Estimated

    Your risk assessment and incident management skills from policing are directly applicable to this GRC role.

    Posted 3 days ago

  • Full-time

    Your incident command and multi-agency coordination experience translates directly to operational resilience and third-party oversight.

    Posted 3 days ago

  • Full-time

    Your investigative mindset and evidence-handling discipline from policing transfer directly to digital forensics and incident response.

    Posted 4 days ago

  • GRC Manager - 6 month FTC

    Trayport · London

    Full-time

    Your experience managing risk, policy, and regulatory compliance under frameworks like PACE transfers directly to GRC.

    Posted 6 days ago