# Senior Product Security Engineer

[Trainline](https://gurify.com/jobs?q=Trainline) · London · Posted today

Contract

Senior

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/trainline/efd536cb-c784-453e-af57-1577b4e9150f)

## Job description

### About us

At Trainline, our purpose is to empower greener travel choices, connecting people and places. https://www.thetrainline.com/terms/sustainability-faqs Trainline enables millions of travellers to find and book the best value tickets across carriers, fares, and journey options through our highly rated mobile app, website, and B2B partner channels.

### Great journeys start with Trainline 🚄

We’re Europe’s leading independent rail platform, helping millions of travellers find and book the best-value rail and coach journeys across our app, website and partner channels.

Our job is to make the green travel choice the best choice. By building a better train travel experience, we help more people choose rail - creating a positive impact for customers, our business and the planet.

We’re a team of more than 1,000 Trainliners from over 50 nationalities, working across London, Paris, Barcelona, Milan, Edinburgh and Madrid. Now is a brilliant time to join us and help shape the future of travel.

### Introducing the Trainline Security Team 👋

Our Security team is dedicated to designing, implementing and monitoring the controls that keep Trainline resilient in a fast-evolving threat landscape. As part of our ongoing mission to mature Trainline's security capabilities, you'll help protect the digital channels that power billions of pounds in annual ticket sales, keeping our systems secure, resilient and ready for what's next.

As a Senior Product Security Engineer, you'll take ownership of product security across the development lifecycle, working closely with teams such as SRE and Platform Engineering to embed the latest tools and best practices into everything we build. You'll act as a trusted bridge between security, engineering and the wider business, helping to shape a culture where secure by design is second nature.

In this role as the Senior Product Security Engineer, you will... 🚄

- Define and own the product security roadmap, aligning priorities with business goals and influencing engineering leadership to embed security into how we design, build and deploy products

- Establish and own the application security vulnerability management process, from triage and prioritisation through to remediation tracking, setting and reporting metrics such as mean time to remediate (MTTR) by severity and security testing coverage to give leadership clear visibility of risk

- Work with teams across the business to carry out threat modelling for our web, mobile and API services, identifying risks and putting effective countermeasures in place

- Assess the security posture of our applications and APIs through code reviews and static and dynamic security testing (SAST/DAST), and manage third-party penetration tests, from scoping with engineering teams and architects through to tracking remediation

- Strengthen the security of our iOS and Android apps and the APIs that power them, covering areas such as authentication and authorisation, secure data storage, API gateway controls and protection against abuse and automated attacks

- Implement, maintain and automate the security tools that support safe development and operations, from vulnerability scanning through to application security posture management (ASPM), and partner with engineering teams to fix vulnerabilities in ways that prevent them recurring

- Build secure coding and deployment knowledge across the organisation through training and mentoring, including helping to establish and grow a security champions programme within our engineering teams

- Ensure our product security practices align with relevant frameworks and standards, such as OWASP, NIST, ISO 27001, GDPR and PCI DSS, supporting compliance and audit efforts while monitoring emerging threats and finding ways to strengthen our resilience

We'd love to hear from you if you have... 🔍

- Significant experience identifying, assessing and mitigating security risks across application design, code and deployed products, including setting up and running application security vulnerability management processes and reporting

- Experience shaping and delivering a product or application security roadmap, with the confidence to influence engineering leaders and use metrics to demonstrate progress and risk reduction

- Experience securing mobile applications and APIs, including testing iOS and Android apps and applying secure approaches to authentication and authorisation, such as OAuth 2.0 and OpenID Connect

- Hands-on experience with security testing tools such as SAST, DAST and vulnerability scanning solutions, ideally including mobile app security testing and API security testing tools

- Practical experience with threat modelling and security reviews, as well as scoping and managing third-party penetration tests in partnership with engineering teams and architects

- A strong grasp of secure coding practices and experience embedding security into software development workflows, including implementing technical controls and driving automation within CI/CD pipelines, ideally across cloud-native, containerised and infrastructure as code (IaC) environments

- Familiarity with industry standards and frameworks such as OWASP (ideally including the Mobile Application Security Verification Standard and API Security Top 10), PCI DSS, ISO 27001 and GDPR

- It would also be helpful if you have experience setting up or growing a security champions programme, running risk assessments, or a working knowledge of regulatory compliance standards

### More information:

Enjoy fantastic perks like private healthcare & dental insurance, a generous work from abroad policy, 2-for-1 share purchase plans, an EV Scheme to further reduce carbon emissions, extra festive time off, and excellent family-friendly benefits.

We prioritise career growth with clear career paths, transparent pay bands, personal learning budgets, and regular learning days. Jump on board and supercharge your career from day one!

We're operating a hybrid model and ask that Trainliners work from the office a minimum of 60% of their time over a 12-week period. We also have a 28-day Work from Abroad policy.

Our values represent the things that matter most to us and what we live and breathe everyday, in everything we do:

- 💭 Think Big - We're building the future of rail

- ✔️ Own It - We focus on every customer, partner and journey

- 🤝 Travel Together - We're one team

- ♻️ Do Good - We make a positive impact

We know that having a diverse team makes us better and helps us succeed. And we mean all forms of diversity - gender, ethnicity, sexuality, disability, nationality and diversity of thought. That's why we're committed to creating inclusive places to work, where everyone belongs and differences are valued and celebrated.

Interested in finding out more about what it's like to work at Trainline? Why not check us out on LinkedIn https://www.linkedin.com/company/trainline/, Instagram https://www.instagram.com/lifeattrainline/ and Glassdoor https://www.glassdoor.co.uk/Overview/Working-at-Trainline-EI_IE249203.11,20.htm!

**Live in Trainline’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- WR [Security engineer, application security (UK)](https://gurify.com/job/security-engineer-application-security-uk-at-writer-5099130c9e15) Writer · London, United Kingdom · last week
- DO [Cyber Security Engineer - dojo.careers](https://gurify.com/job/cyber-security-engineer-dojo-careers-0961a5dd9c92) Dojo · London · last week
- WR [Security engineer, detection and response (UK)](https://gurify.com/job/security-engineer-detection-and-response-uk-at-writer-9cb21b626cf6) Writer · London, United Kingdom · last week
- MA [Security Engineer](https://gurify.com/job/security-engineer-at-marex-a383676e7e6e) Marex · London, United Kingdom · last week
- IN [Senior Infrastructure and Cloud Security Engineer (m/f/d)](https://gurify.com/job/senior-infrastructure-and-cloud-security-engineer-m-f-d-at-3f7722b49cef) Internationalcopyrightenterpriseservices · London · 2 weeks ago
- TI [Head of Product and Identity Security](https://gurify.com/job/head-of-product-and-identity-security-at-tide-c0d4e51fea7d) Tide · United Kingdom · 2 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Senior Product Security Engineer","description":"\u003Ch3\u003EAbout us\u003C/h3\u003E\u003Cp\u003EAt Trainline, our purpose is to empower greener travel choices, connecting people and places. https://www.thetrainline.com/terms/sustainability-faqs Trainline enables millions of travellers to find and book the best value tickets across carriers, fares, and journey options through our highly rated mobile app, website, and B2B partner channels.\u003C/p\u003E\u003Ch3\u003EGreat journeys start with Trainline \u0026#128644;\u003C/h3\u003E\u003Cp\u003EWe\u2019re Europe\u2019s leading independent rail platform, helping millions of travellers find and book the best-value rail and coach journeys across our app, website and partner channels.\u003C/p\u003E\u003Cp\u003EOur job is to make the green travel choice the best choice. By building a better train travel experience, we help more people choose rail - creating a positive impact for customers, our business and the planet.\u003C/p\u003E\u003Cp\u003EWe\u2019re a team of more than 1,000 Trainliners from over 50 nationalities, working across London, Paris, Barcelona, Milan, Edinburgh and Madrid. Now is a brilliant time to join us and help shape the future of travel.\u003C/p\u003E\u003Ch3\u003EIntroducing the Trainline Security Team \u0026#128075;\u003C/h3\u003E\u003Cp\u003EOur Security team is dedicated to designing, implementing and monitoring the controls that keep Trainline resilient in a fast-evolving threat landscape. As part of our ongoing mission to mature Trainline\u0026#39;s security capabilities, you\u0026#39;ll help protect the digital channels that power billions of pounds in annual ticket sales, keeping our systems secure, resilient and ready for what\u0026#39;s next.\u003C/p\u003E\u003Cp\u003EAs a Senior Product Security Engineer, you\u0026#39;ll take ownership of product security across the development lifecycle, working closely with teams such as SRE and Platform Engineering to embed the latest tools and best practices into everything we build. You\u0026#39;ll act as a trusted bridge between security, engineering and the wider business, helping to shape a culture where secure by design is second nature.\u003C/p\u003E\u003Cp\u003EIn this role as the Senior Product Security Engineer, you will... \u0026#128644;\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EDefine and own the product security roadmap, aligning priorities with business goals and influencing engineering leadership to embed security into how we design, build and deploy products\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEstablish and own the application security vulnerability management process, from triage and prioritisation through to remediation tracking, setting and reporting metrics such as mean time to remediate (MTTR) by severity and security testing coverage to give leadership clear visibility of risk\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWork with teams across the business to carry out threat modelling for our web, mobile and API services, identifying risks and putting effective countermeasures in place\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAssess the security posture of our applications and APIs through code reviews and static and dynamic security testing (SAST/DAST), and manage third-party penetration tests, from scoping with engineering teams and architects through to tracking remediation\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrengthen the security of our iOS and Android apps and the APIs that power them, covering areas such as authentication and authorisation, secure data storage, API gateway controls and protection against abuse and automated attacks\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EImplement, maintain and automate the security tools that support safe development and operations, from vulnerability scanning through to application security posture management (ASPM), and partner with engineering teams to fix vulnerabilities in ways that prevent them recurring\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild secure coding and deployment knowledge across the organisation through training and mentoring, including helping to establish and grow a security champions programme within our engineering teams\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEnsure our product security practices align with relevant frameworks and standards, such as OWASP, NIST, ISO 27001, GDPR and PCI DSS, supporting compliance and audit efforts while monitoring emerging threats and finding ways to strengthen our resilience\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EWe\u0026#39;d love to hear from you if you have... \u0026#128269;\u003C/p\u003E\u003Cul\u003E\u003Cli\u003ESignificant experience identifying, assessing and mitigating security risks across application design, code and deployed products, including setting up and running application security vulnerability management processes and reporting\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience shaping and delivering a product or application security roadmap, with the confidence to influence engineering leaders and use metrics to demonstrate progress and risk reduction\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience securing mobile applications and APIs, including testing iOS and Android apps and applying secure approaches to authentication and authorisation, such as OAuth 2.0 and OpenID Connect\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHands-on experience with security testing tools such as SAST, DAST and vulnerability scanning solutions, ideally including mobile app security testing and API security testing tools\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPractical experience with threat modelling and security reviews, as well as scoping and managing third-party penetration tests in partnership with engineering teams and architects\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EA strong grasp of secure coding practices and experience embedding security into software development workflows, including implementing technical controls and driving automation within CI/CD pipelines, ideally across cloud-native, containerised and infrastructure as code (IaC) environments\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with industry standards and frameworks such as OWASP (ideally including the Mobile Application Security Verification Standard and API Security Top 10), PCI DSS, ISO 27001 and GDPR\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIt would also be helpful if you have experience setting up or growing a security champions programme, running risk assessments, or a working knowledge of regulatory compliance standards\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EMore information:\u003C/h3\u003E\u003Cp\u003EEnjoy fantastic perks like private healthcare \u0026amp; dental insurance, a generous work from abroad policy, 2-for-1 share purchase plans, an EV Scheme to further reduce carbon emissions, extra festive time off, and excellent family-friendly benefits.\u003C/p\u003E\u003Cp\u003EWe prioritise career growth with clear career paths, transparent pay bands, personal learning budgets, and regular learning days. Jump on board and supercharge your career from day one!\u003C/p\u003E\u003Cp\u003EWe\u0026#39;re operating a hybrid model and ask that Trainliners work from the office a minimum of 60% of their time over a 12-week period. We also have a 28-day Work from Abroad policy.\u003C/p\u003E\u003Cp\u003EOur values represent the things that matter most to us and what we live and breathe everyday, in everything we do:\u003C/p\u003E\u003Cul\u003E\u003Cli\u003E\u0026#128173; Think Big - We\u0026#39;re building the future of rail\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E\u2714\uFE0F Own It - We focus on every customer, partner and journey\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E\u0026#129309;\u0026#160; Travel Together - We\u0026#39;re one team\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E\u267B\uFE0F Do Good - We make a positive impact\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EWe know that having a diverse team makes us better and helps us succeed. And we mean all forms of diversity - gender, ethnicity, sexuality, disability, nationality and diversity of thought. That\u0026#39;s why we\u0026#39;re committed to creating inclusive places to work, where everyone belongs and differences are valued and celebrated.\u003C/p\u003E\u003Cp\u003EInterested in finding out more about what it\u0026#39;s like to work at Trainline? Why not check us out on LinkedIn https://www.linkedin.com/company/trainline/, Instagram https://www.instagram.com/lifeattrainline/ and Glassdoor https://www.glassdoor.co.uk/Overview/Working-at-Trainline-EI_IE249203.11,20.htm!\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"senior-product-security-engineer-at-trainline-40f1783e34dd"},"url":"https://gurify.com/job/senior-product-security-engineer-at-trainline-40f1783e34dd","datePosted":"2026-10-02","validThrough":"2026-11-16T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Trainline","sameAs":"https://jobs.ashbyhq.com/trainline"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"GB","addressLocality":"London"}},"employmentType":"CONTRACTOR"}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United Kingdom","item":"https://gurify.com/jobs/united-kingdom"},{"@type":"ListItem","position":3,"name":"Senior Product Security Engineer","item":"https://gurify.com/job/senior-product-security-engineer-at-trainline-40f1783e34dd"}]}
```
