Head of Information Security GRC in London
Head of Information Security GRC

Head of Information Security GRC in London

London Full-Time 48000 - 72000 £ / year (est.) Home office (partial)
T

At a Glance

  • Tasks: Lead the transformation of our security function and shape GRC strategy.
  • Company: Join Trainline, Europe's number 1 downloaded rail app, focused on sustainable travel.
  • Benefits: Enjoy private healthcare, generous work-from-abroad policy, and excellent career growth opportunities.
  • Why this job: Make a real impact in a dynamic environment while promoting a culture of security.
  • Qualifications: Experience in GRC or risk management and strong leadership skills required.
  • Other info: Diverse and inclusive workplace with a focus on collaboration and innovation.

The predicted salary is between 48000 - 72000 £ per year.

About us

We are champions of rail, inspired to build a greener, more sustainable future of travel. Trainline enables millions of travellers to find and book the best value tickets across carriers, fares, and journey options through our highly rated mobile app, website, and B2B partner channels. Great journeys start with Trainline. Now Europe’s number 1 downloaded rail app, with over 125 million monthly visits and £5.9 billion in annual ticket sales, we collaborate with 270+ rail and coach companies in over 40 countries. We want to create a world where travel is as simple, seamless, eco-friendly and affordable as it should be. Today, we’re a FTSE 250 company driven by our incredible team of over 1,000 Trainliners from 50+ nationalities, based across London, Paris, Barcelona, Milan, Edinburgh and Madrid. With our focus on growth in the UK and Europe, now is the perfect time to join us on this high-speed journey.

Introducing the Information Security Team at Trainline. As Head of Governance, Risk & Compliance (GRC), you’ll play a pivotal role in shaping and leading this transformation of our security function. Reporting directly to our CISO, you’ll take ownership of how governance, risk, and compliance come together to protect, enable, and future-proof the business. This is about building a cohesive GRC strategy that balances control with creativity, fits Trainline’s business context, and drives long-term cultural change.

In this critical role, you will collaborate closely with cross-functional teams including Legal, Engineering, and Procurement to embed risk management into daily operations and strategic initiatives. As a key member of the Security leadership team, your remit will extend beyond risk and compliance to include shaping the security and privacy strategy, enhancing supplier risk processes, and fostering a culture of security awareness across the company. Your leadership and strategic insight will be essential in navigating the evolving regulatory landscape and supporting Trainline’s growth ambitions with robust yet pragmatic risk management.

As the Head of Information Security Risk and Compliance at Trainline, you will:

  • Redesign and embed a pragmatic, risk-first GRC framework that integrates governance, risk, and compliance across the business.
  • Assess current maturity and deliver a transformation roadmap that unifies fragmented processes into a single, clear model aligned to Trainline’s risk appetite.
  • Maintain key standards such as ISO 27001, ISO 22301, and PCI DSS, while ensuring they add real business value.
  • Manage and develop the Risk and Compliance team, setting clear goals and cultivating an inclusive culture of accountability, continuous learning and collaboration.
  • Develop and deliver concise, data driven risk and compliance reports for senior management and stakeholders, highlighting trends, emerging risks, and mitigation strategies.
  • Act as a trusted advisor to executive stakeholders, providing actionable insight and guidance to support risk-aware decision-making.
  • Partner with Legal, Privacy, Engineering, Procurement, and other functions to embed security, governance, and compliance into products, systems, and processes.
  • Oversee and mature the end-to-end third-party risk management process, focusing on tiering, assurance automation, and stronger alignment with procurement and legal teams.
  • Champion and scale security awareness and governance training programs to build a strong, security-first culture across Trainline.
  • Own the development, communication, and maintenance of information security policies, ensuring alignment with evolving threats and compliance needs.

We would love to hear from you if you have:

  • Experience transforming or scaling GRC or risk management functions within dynamic, high-growth or complex businesses.
  • Proven ability to balance control and creativity — tailoring governance frameworks that fit the business.
  • A proven record of leading and developing high-performing teams, setting clear goals and cultivating accountability and continuous improvement.
  • Deep understanding of enterprise and cyber risk frameworks (ISO 27005, ISO 31000, NIST CSF) and how to communicate risk appetite in business terms.
  • Excellent communication skills, with the ability to present complex risk and compliance information clearly to senior leadership and stakeholders.
  • Strong analytical and critical thinking skills, capable of identifying risks, evaluating controls, and recommending effective mitigation strategies.
  • Experience integrating risk management processes into business operations, including supplier and third-party risk assessments.
  • A collaborative, solutions focussed approach and the ability to work cross-functionally with security, engineering, procurement, and business teams to embed security and compliance requirements.
  • Track record of delivering actionable risk reporting and advisory support to executive teams, influencing strategic decision-making.

More information: Enjoy fantastic perks like private healthcare & dental insurance, a generous work from abroad policy, 2-for-1 share purchase plans, an EV Scheme to further reduce carbon emissions, extra festive time off, and excellent family-friendly benefits. We prioritise career growth with clear career paths, transparent pay bands, personal learning budgets, and regular learning days. Jump on board and supercharge your career from day one! We operate a hybrid model to work and ask that Trainliners work from the office a minimum of 60% of their time over a 12-week period. We also have a 28-day Work from Abroad policy.

Our values represent the things that matter most to us and what we live and breathe every day, in everything we do:

  • Think Big - We’re building the future of rail
  • Own It - We focus on every customer, partner and journey
  • Travel Together - We’re one team
  • Do Good - We make a positive impact

We know that having a diverse team makes us better and helps us succeed. And we mean all forms of diversity - gender, ethnicity, sexuality, disability, nationality and diversity of thought. That’s why we’re committed to creating inclusive places to work, where everyone belongs and differences are valued and celebrated.

Interested in finding out more about what it’s like to work at Trainline? Why not check us out on LinkedIn, Instagram and Glassdoor!

Head of Information Security GRC in London employer: Trainline

Trainline is an exceptional employer that champions a greener future for travel while fostering a dynamic and inclusive work culture. With a strong focus on employee growth, we offer clear career paths, personal learning budgets, and fantastic benefits such as private healthcare, generous leave policies, and a hybrid working model. Join our diverse team of over 1,000 Trainliners and be part of a company that values creativity, accountability, and making a positive impact in the world of rail travel.
T

Contact Detail:

Trainline Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Head of Information Security GRC in London

✨Tip Number 1

Network like a pro! Reach out to current or former Trainliners on LinkedIn. A friendly chat can give you insider info about the company culture and maybe even a referral.

✨Tip Number 2

Prepare for the interview by understanding Trainline's mission and values. Show us how your experience aligns with our goal of creating a greener, more sustainable future of travel.

✨Tip Number 3

Practice your storytelling skills! Be ready to share specific examples of how you've transformed GRC functions in the past. We love hearing about real-life experiences that demonstrate your impact.

✨Tip Number 4

Don’t forget to ask questions during the interview! This shows your interest and helps you gauge if Trainline is the right fit for you. Think about what you want to know about our security culture and team dynamics.

We think you need these skills to ace Head of Information Security GRC in London

Governance, Risk and Compliance (GRC)
ISO 27001
ISO 22301
PCI DSS
Risk Management
Team Leadership
Analytical Skills
Communication Skills
Data-Driven Reporting
Cyber Risk Frameworks
Collaboration
Problem-Solving Skills
Stakeholder Engagement
Security Awareness Training

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in GRC and risk management. We want to see how your skills align with our mission at Trainline, so don’t hold back on showcasing your relevant achievements!

Showcase Your Leadership Skills: As the Head of GRC, you’ll be leading a team, so it’s crucial to demonstrate your leadership experience. Share examples of how you've developed high-performing teams and fostered a culture of accountability and continuous learning.

Be Clear and Concise: When writing your application, keep it straightforward and to the point. Use clear language to explain complex concepts, especially around risk and compliance, as we need to see that you can communicate effectively with senior stakeholders.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for this exciting opportunity to join our team at Trainline!

How to prepare for a job interview at Trainline

✨Know Your GRC Frameworks

Make sure you’re well-versed in the key governance, risk, and compliance frameworks like ISO 27001 and NIST CSF. Be ready to discuss how you've applied these in previous roles and how they can be tailored to fit Trainline’s unique business context.

✨Showcase Your Leadership Skills

Prepare examples that highlight your experience in leading high-performing teams. Discuss how you’ve set clear goals and fostered a culture of accountability and continuous improvement, as this is crucial for the Head of GRC role.

✨Communicate Clearly

Practice explaining complex risk and compliance concepts in simple terms. You’ll need to present data-driven insights to senior management, so being able to communicate effectively is key to influencing decision-making.

✨Emphasise Collaboration

Trainline values teamwork, so be prepared to share examples of how you’ve successfully worked cross-functionally with different teams. Highlight any experiences where you’ve embedded security and compliance into products or processes, showcasing your collaborative approach.

Head of Information Security GRC in London
Trainline
Location: London

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

T
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>