Senior Product Security Engineer
Trainline LondonEst. Est. GBP 70,000–100,000 / yearSenior
Estimated range based on role, country and industry — not published by the company.
Key requirements
- Compliance
About us
At Trainline, our purpose is to empower greener travel choices, connecting people and places. Trainline enables millions of travellers to find and book the best value tickets across carriers, fares, and journey options through our highly rated mobile app, website, and B2B partner channels.
Great journeys start with Trainline 🚄
We’re Europe’s leading independent rail platform, helping millions of travellers find and book the best-value rail and coach journeys across our app, website and partner channels.
Our job is to make the green travel choice the best choice. By building a better train travel experience, we help more people choose rail - creating a positive impact for customers, our business and the planet.
We’re a team of more than 1,000 Trainliners from over 50 nationalities, working across London, Paris, Barcelona, Milan, Edinburgh and Madrid. Now is a brilliant time to join us and help shape the future of travel.
Introducing the Trainline Security Team 👋
Our Security team is dedicated to designing, implementing and monitoring the controls that keep Trainline resilient in a fast-evolving threat landscape. As part of our ongoing mission to mature Trainline's security capabilities, you'll help protect the digital channels that power billions of pounds in annual ticket sales, keeping our systems secure, resilient and ready for what's next.
As a Senior Product Security Engineer, you'll take ownership of product security across the development lifecycle, working closely with teams such as SRE and Platform Engineering to embed the latest tools and best practices into everything we build. You'll act as a trusted bridge between security, engineering and the wider business, helping to shape a culture where secure by design is second nature.
In this role as the Senior Product Security Engineer, you will... 🚄
Define and own the product security roadmap, aligning priorities with business goals and influencing engineering leadership to embed security into how we design, build and deploy products
Establish and own the application security vulnerability management process, from triage and prioritisation through to remediation tracking, setting and reporting metrics such as mean time to remediate (MTTR) by severity and security testing coverage to give leadership clear visibility of risk
Work with teams across the business to carry out threat modelling for our web, mobile and API services, identifying risks and putting effective countermeasures in place
Assess the security posture of our applications and APIs through code reviews and static and dynamic security testing (SAST/DAST), and manage third-party penetration tests, from scoping with engineering teams and architects through to tracking remediation
Strengthen the security of our iOS and Android apps and the APIs that power them, covering areas such as authentication and authorisation, secure data storage, API gateway controls and protection against abuse and automated attacks
Implement, maintain and automate the security tools that support safe development and operations, from vulnerability scanning through to application security posture management (ASPM), and partner with engineering teams to fix vulnerabilities in ways that prevent them recurring
Build secure coding and deployment knowledge across the organisation through training and mentoring, including helping to establish and grow a security champions programme within our engineering teams
Ensure our product security practices align with relevant frameworks and standards, such as OWASP, NIST, ISO 27001, GDPR and PCI DSS, supporting compliance and audit efforts while monitoring emerging threats and finding ways to strengthen our resilience
We'd love to hear from you if you have... 🔍
Significant experience identifying, assessing and mitigating security risks across application design, code and deployed products, including setting up and running application security vulnerab
See your match score for this role.
Xecodai maps the interview stages and shows what is preventing a 95% match.
