Junior Product Security Engineer in London

Junior Product Security Engineer in London

London Entry level 30000 - 40000 £ / year (est.) Home office (partial)
T

At a Glance

  • Tasks: Support secure development and integrate security practices into product lifecycles.
  • Company: Join Trainline, Europe's number 1 downloaded rail app, focused on sustainable travel.
  • Benefits: Enjoy private healthcare, generous leave, learning budgets, and a supportive work environment.
  • Other info: Collaborate with diverse teams and grow your career in a dynamic environment.
  • Why this job: Make a real impact on security for millions of travellers across Europe.
  • Qualifications: Relevant education or experience in cyber security or software development.

The predicted salary is between 30000 - 40000 £ per year.

We are champions of rail, inspired to build a greener, more sustainable future of travel. Trainline enables millions of travellers to find and book the best value tickets across carriers, fares, and journey options through our highly rated mobile app, website, and B2B partner channels. Now Europe’s number 1 downloaded rail app, with over 135 million monthly visits and £6.3 billion in annual ticket sales, we collaborate with 270+ rail and coach companies in over 40 countries. We want to create a world where travel is as simple, seamless, eco‑friendly and affordable as it should be. Today, we’re a FTSE 250 company driven by our incredible team of over 1,000 Trainliners from 50+ nationalities, based across London, Paris, Barcelona, Milan, Edinburgh and Madrid. With our focus on growth in the UK and Europe, now is the perfect time to join us on this high‑speed journey.

Join our dynamic team, where we focus on designing, implementing, and monitoring security controls to ensure a robust security posture in a fast‑evolving environment. As part of our mission to continuously improve and mature Trainline’s security capabilities, we work closely with cross‑functional teams, including Cloud Engineering, SRE, Platform Engineering, and more, to integrate the latest technologies and best practices into our products.

As a Product Security Engineer Analyst, you’ll contribute to the product security function by helping to embed security into our product development lifecycle, assist with vulnerability management, and work with cross‑functional teams to improve security practices across Trainline’s digital products.

What You’ll Do

  • Support Secure Development
    • Support the integration of security practices across the product development lifecycle, helping teams design and build secure services and features.
    • Work with teams to promote secure‑by‑default and a shift‑left approach, ensuring security considerations are addressed early to reduce the risk and cost of fixing issues later.
    • Help integrate security checks (e.g., SAST, SCA, secret scanning) into CI/CD workflows to identify risks during development.
    • Assist in triaging and analysing findings from automated tooling, validating results, false positives, and partnering with engineering teams to prioritise and remediate security risks.
  • Vulnerability Triage & Tracking
    • Review and triage incoming security issues from scans and bug reports.
    • Record, prioritise and help track remediation with developers and platform teams.
    • Contribute to vulnerability monitoring dashboards and reports.
  • Learning & Threat Awareness
    • Participate in threat modelling sessions and documentation efforts.
    • Stay updated on common application vulnerabilities and security best practices.
    • Shadow senior engineers in code reviews and security design discussions.
  • Security Advocacy
    • Help promote secure coding principles across teams by sharing guidance and resources.
    • Help improve developer adoption of security tools and best practices.
    • Support delivery of internal training sessions and documentation updates.
  • Compliance and Standards
    • Assist with aligning product security practices with relevant security frameworks and standards (e.g., OWASP, NIST, ISO 27001, GDPR, PCI DSS).
    • Support regulatory compliance efforts and maintain evidence to meet audit requirements.

Who You Are

You are curious about how systems work and how they can be secured; bringing an aware consumer mindset that considers the intersection of technology, security, and product design.

Must Have

  • Relevant education, training, or practical experience in cyber/information security or software engineering/development.
  • Understanding of common security risks affecting applications, APIs, and distributed systems.
  • Familiarity with secure coding principles, the software development lifecycle (SDLC) and threat modelling concepts.
  • Exposure to security testing approaches such as SAST, DAST, or dependency scanning.
  • Basic programming or scripting ability (e.g., Python, JavaScript, or similar) to support automation, analysis, or tooling.
  • Interest in building or improving security tooling, automation, or developer workflows to help scale security across engineering teams.
  • Strong analytical and problem‑solving skills, with the ability to analyse and assess security risks in application designs, code, or deployed systems.
  • Ability to collaborate effectively with engineers and communicate security concerns clearly.

Nice to Have

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or a related technical field.
  • Experience using security tooling such as Burp Suite, OWASP ZAP, Semgrep, Checkmarx, OxSecurity, or Snyk.
  • Exposure to security reviews, threat modelling, penetration testing concepts, or risk assessments.
  • Familiarity with security frameworks and standards such as OWASP, ISO 27001, PCI DSS, or GDPR.
  • Familiarity with modern development environments, including AWS, CI/CD security checks, and API security testing.
  • Scripting experience (Python/Bash) and exposure to AI or martech ecosystems is a plus.
  • Experience gained through security coursework, certifications, personal projects, security research, CTF competitions, bug bounty programs, or open‑source contributions is highly valued.

Candidates with software, data or platform engineering backgrounds with an interest in security are also encouraged to apply.

What You’ll Get

  • The opportunity to work on large‑scale platforms used by millions of travellers across the UK and Europe, helping secure systems that support billions of pounds in annual ticket sales.
  • Hands‑on experience across modern product security practices, including threat modelling, secure design reviews, software supply chain security, AI security considerations, and security automation within CI/CD pipelines.
  • The chance to collaborate closely with experienced security, platform, and product engineers, gaining exposure to real‑world security challenges in a modern engineering environment.
  • Opportunities to contribute to security research, experimentation, and tooling, helping improve Trainline’s security capabilities and developer security experience.
  • Exposure to broader security initiatives across the organisation, including collaboration with other security functions and engagement with partners or vendors where relevant.
  • A supportive environment focused on mentorship, continuous learning, and career growth, including access to learning budgets, training resources, and professional development opportunities.

Benefits

  • Private healthcare and dental insurance.
  • Generous work‑from‑abroad policy.
  • 2‑for‑1 share purchase plans.
  • EV scheme to reduce carbon emissions.
  • Extra festive time off.
  • Family‑friendly benefits.
  • Learning budgets and professional development resources.

Our hybrid model requires you to work from the office a minimum of 60% of your time over a 12‑week period, and we also have a 28‑day work‑from‑abroad policy. Our values include Think Big, Own It, Travel Together, and Do Good. We believe diversity drives our success and we are committed to creating inclusive workplaces where everyone belongs.

Junior Product Security Engineer in London employer: Trainline International Limited

Trainline is an exceptional employer, offering a dynamic work environment where innovation meets sustainability in the travel sector. With a strong focus on employee growth, we provide extensive learning opportunities, mentorship, and a supportive culture that values diversity and collaboration. Our hybrid working model, generous benefits including private healthcare, and commitment to eco-friendly practices make Trainline an attractive place for those looking to make a meaningful impact in product security.

T

Contact Details:

Trainline International Limited Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Junior Product Security Engineer in London

Get Involved in the Cybersecurity Community

Dive into local and online cybersecurity meetups or forums. Engage with communities on platforms like Reddit or Discord, which often have dedicated channels for job opportunities and entry-level tips. Making yourself visible here can open doors we didn't even know existed!

Show Off Those Skills

Set up a GitHub profile where you can showcase any projects or contributions you’ve made, even if they’re just personal experiments. Potential employers love to see our work in action, and this is a great way to catch the eye of companies like Trainline International Limited while we’re still building our experience.

Leverage Online Courses & Certifications

Consider taking some recognised cybersecurity certifications, like CompTIA Security+ or Certified Ethical Hacker. These badges give us an edge and show our commitment to the field. Plus, many courses have job boards and networking opportunities that can lead to our first gig!

Apply Early and Often

Entry-level roles in cybersecurity can fill up quickly, so keep an eye on our website for open positions at Trainline International Limited. We should be ready to apply as soon as we see a role pop up. Tailor our applications to highlight relevant skills like problem-solving and attention to detail – these can set us apart!

We think you need these skills to ace Junior Product Security Engineer in London

Cybersecurity
Information Security
Software Development Lifecycle (SDLC)
Threat Modelling
Secure Coding Principles
Security Testing Approaches (SAST, DAST)
Basic Programming (Python, JavaScript)

Some tips for your application 🫡

Show off your technical skills:In the cybersecurity field, we love to see your technical know-how right from the get-go. Include any relevant coursework, certifications (like CompTIA Security+ or CEH), and tools you're familiar with. If you've dabbled in security protocols or have any hands-on experience with firewalls or threat analysis, make sure to highlight that!

Demonstrate your passion for cybersecurity:A cover letter is your chance to show your enthusiasm for cybersecurity—don’t hold back! Talk about why you’re excited about this career path, any personal projects you've been involved with, or security challenges you’ve taken on. It’s all about showing Trainline International Limited that you’re eager to learn and contribute.

Include relevant extracurricular activities:In entry-level applications, we appreciate seeing how you’ve engaged with the cybersecurity community. Mention any clubs, competitions (like Capture The Flag), or volunteer work related to cybersecurity. This will give us insight into your dedication to growing your skills beyond academic learning!

Keep it concise and tailored:We get it—writing about yourself can be tough. But for entry-level roles like Junior Product Security Engineer at Trainline International Limited, we're looking for clarity and focus. Tailor your CV and application materials to highlight only what matters for this role. Avoid fluff and get straight to your strengths in the context of cybersecurity!

How to prepare for a job interview at Trainline International Limited

Know Your Cybersecurity Basics

Make sure you’re clued up on the essential concepts of cybersecurity, like encryption, firewalls, and malware. For an entry-level role like Junior Product Security Engineer at Trainline International Limited, they might ask you practical questions to test your understanding of these topics, so brush up on the basics and maybe even run through some scenarios.

Familiarise Yourself with Tools

You’ll likely be working with various cybersecurity tools and platforms, so get comfortable with common ones like Wireshark and Metasploit. Mention any hands-on experience you have with these tools during your interview, as it shows you’ve taken the initiative to learn and apply your knowledge, which is key for an entry-level position.

Show Your Passion for Learning

Since this is an entry-level position, employers at Trainline International Limited will want to see your eagerness to learn. Prepare to discuss any certifications or online courses you've completed, as well as how you stay updated on the latest threats and trends in cybersecurity. This demonstrates your commitment to growing in the field.

Prepare for Scenario-Based Questions

Expect some scenario-based questions during your interview. These might include how you'd respond to a phishing attempt or securing a network. Think through a few examples beforehand, so you can showcase your problem-solving skills and thought process, which are critical in cybersecurity.