Senior Product Security Engineer in London

Senior Product Security Engineer in London

London Full-Time 36000 - 60000 £ / year (est.) On-site
T

At a Glance

  • Tasks: Drive security integration in software development, perform threat analysis, and enhance security practices.
  • Company: Join Trainline, Europe's top rail app, committed to sustainable travel and innovation.
  • Benefits: Enjoy private healthcare, flexible work options, generous leave, and career growth opportunities.
  • Other info: Embrace a culture that values diversity and encourages personal and professional development.
  • Why this job: Be part of a diverse team making a positive impact on travel security and sustainability.
  • Qualifications: Experience in application security, threat modelling, and familiarity with security frameworks required.

The predicted salary is between 36000 - 60000 £ per year.

Overview

As Senior Product Security Engineer, you own the product security across the development lifecycle and partner with SRE and Platform Engineering to embed secure practices. You shape the security roadmap, manage vulnerability processes, and lead risk reduction across web, mobile, and API services. You’ll drive threat modelling, secure coding, and automation to strengthen resilience of Trainline’s digital channels. This role combines hands-on security work with mentoring and cross‑functional influence to foster secure-by-design culture.

Pay / Benefits

  • private healthcare & dental insurance
  • work from abroad policy
  • 2-for-1 share purchase plans
  • EV Scheme to reduce carbon emissions
  • extra festive time off
  • family-friendly benefits

Responsibilities

  • Define and own the product security roadmap aligned to business goals
  • Lead application security vulnerability management from triage to remediation metrics
  • Perform threat modelling for web, mobile, and API services and implement countermeasures
  • Conduct code reviews and SAST/DAST testing; manage third‑party penetration tests
  • Strengthen iOS/Android app and API security including authentication, data storage, and gateway controls
  • Automate and maintain security tools supporting safe development and operations (ASPM, vulnerability scanning)
  • Build secure coding and deployment knowledge via training and grow a security champions programme
  • Ensure practices align with frameworks like OWASP, NIST, ISO 27001, GDPR, PCI DSS
  • Support compliance and audit efforts and monitor emerging threats

Key requirements

  • Significant experience in identifying, assessing and mitigating security risks across applications and deployments
  • Proven track record shaping and delivering a product security roadmap with metrics
  • Experience securing mobile apps and APIs and implementing OAuth2.0 / OpenID Connect
  • Hands-on with SAST, DAST and vulnerability scanning; experience with mobile and API security testing tools
  • Expertise in threat modelling and managing third‑party penetration tests with engineering teams
  • Strong secure coding practices and automation within CI/CD; cloud-native, containerised, IaC environments
  • Familiarity with OWASP (including Mobile App Security Verification Standard and API Security Top 10), PCI DSS, ISO 27001, GDPR
  • Nice-to-have: security champions programmes, risk assessments, regulatory compliance knowledge
  • Influencing engineering leadership
  • Cross-functional collaboration
  • Mentoring and training
  • SAST/DAST
  • Vulnerability scanning
  • Threat modelling

Senior Product Security Engineer in London employer: Trainline

Trainline is an exceptional employer that fosters a dynamic work culture where innovation and collaboration thrive. With a strong focus on employee growth, the company offers numerous opportunities for professional development and engagement in meaningful projects that drive organisational transformation. Located in a vibrant environment, Trainline supports a healthy work-life balance and encourages its employees to embrace new ways of working, making it an attractive place for those seeking rewarding careers.

T

Contact Details:

Trainline Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Product Security Engineer in London

✨Tip Number 1

Familiarise yourself with Trainline's mission and values. Understanding their commitment to sustainability and customer experience will help you align your answers during interviews, showcasing how your personal values resonate with theirs.

✨Tip Number 2

Network with current or former employees on platforms like LinkedIn. Engaging in conversations about their experiences can provide valuable insights into the company culture and expectations for the Senior Product Security Engineer role.

✨Tip Number 3

Stay updated on the latest trends in application security and relevant frameworks such as OWASP and NIST. Being able to discuss recent developments or case studies during your interview can demonstrate your expertise and passion for the field.

✨Tip Number 4

Prepare to discuss specific examples of how you've integrated security into the Software Development Lifecycle in your previous roles. Highlighting your hands-on experience with tools like SAST and DAST will show that you're ready to hit the ground running.

We think you need these skills to ace Senior Product Security Engineer in London

Application Security Expertise
Threat Modelling
Security Testing Tools (SAST, DAST)
Secure Coding Practices
Software Development Lifecycle (SDLC) Integration
Cloud-Native Architecture Security
Containerization Technologies

Some tips for your application 🫡

Tailor Your CV:Make sure your CV highlights relevant experience in application security, threat modelling, and secure coding practices. Use keywords from the job description to demonstrate your fit for the role.

Craft a Compelling Cover Letter:In your cover letter, express your passion for security and how your skills align with Trainline's mission. Mention specific experiences that showcase your ability to integrate security into the Software Development Lifecycle.

Showcase Technical Skills:Detail your experience with security testing tools like SAST and DAST, as well as your familiarity with compliance standards such as OWASP and ISO 27001. This will help illustrate your technical expertise.

Highlight Collaboration Experience:Since the role involves working with cross-functional teams, include examples of past collaborations. Emphasise your ability to communicate security concepts effectively to non-technical stakeholders.

How to prepare for a job interview at Trainline

✨Showcase Your Application Security Expertise

Be prepared to discuss your deep understanding of application security. Highlight specific experiences where you've identified and mitigated security risks in application designs or code, and be ready to explain how you integrated security into the Software Development Lifecycle.

✨Demonstrate Technical Knowledge

Familiarise yourself with the latest security frameworks and standards like OWASP and ISO 27001. During the interview, share examples of your direct experience with threat modelling, security reviews, and penetration testing to showcase your technical prowess.

✨Emphasise Collaboration Skills

Trainline values teamwork, so be ready to discuss how you've collaborated with cross-functional teams in the past. Provide examples of how you’ve communicated security initiatives effectively and fostered a culture of security awareness within your previous roles.

✨Stay Updated on Emerging Threats

Show your commitment to continuous improvement by discussing how you keep up with emerging threats and vulnerabilities. Mention any recent trends or tools you've explored that could enhance security processes, demonstrating your proactive approach to security.