Overview
As Senior Product Security Engineer, you own the product security across the development lifecycle and partner with SRE and Platform Engineering to embed secure practices. You shape the security roadmap, manage vulnerability processes, and lead risk reduction across web, mobile, and API services. You’ll drive threat modelling, secure coding, and automation to strengthen resilience of Trainline’s digital channels. This role combines hands-on security work with mentoring and cross‑functional influence to foster secure-by-design culture.
Pay / Benefits
- private healthcare & dental insurance
- work from abroad policy
- 2-for-1 share purchase plans
- EV Scheme to reduce carbon emissions
- extra festive time off
- family-friendly benefits
Responsibilities
- Define and own the product security roadmap aligned to business goals
- Lead application security vulnerability management from triage to remediation metrics
- Perform threat modelling for web, mobile, and API services and implement countermeasures
- Conduct code reviews and SAST/DAST testing; manage third‑party penetration tests
- Strengthen iOS/Android app and API security including authentication, data storage, and gateway controls
- Automate and maintain security tools supporting safe development and operations (ASPM, vulnerability scanning)
- Build secure coding and deployment knowledge via training and grow a security champions programme
- Ensure practices align with frameworks like OWASP, NIST, ISO 27001, GDPR, PCI DSS
- Support compliance and audit efforts and monitor emerging threats
Key requirements
- Significant experience in identifying, assessing and mitigating security risks across applications and deployments
- Proven track record shaping and delivering a product security roadmap with metrics
- Experience securing mobile apps and APIs and implementing OAuth2.0 / OpenID Connect
- Hands-on with SAST, DAST and vulnerability scanning; experience with mobile and API security testing tools
- Expertise in threat modelling and managing third‑party penetration tests with engineering teams
- Strong secure coding practices and automation within CI/CD; cloud-native, containerised, IaC environments
- Familiarity with OWASP (including Mobile App Security Verification Standard and API Security Top 10), PCI DSS, ISO 27001, GDPR
- Nice-to-have: security champions programmes, risk assessments, regulatory compliance knowledge
- Influencing engineering leadership
- Cross-functional collaboration
- Mentoring and training
- SAST/DAST
- Vulnerability scanning
- Threat modelling
…
