Skip to main content
trainline careers
trainline logo

SecOps Engineer

trainlineUKFull Time3w ago
AIMobileSecurityComplianceSalesOperationsSupportGrowthSolutionsEngineeringInfrastructurePlatform

Job description

About us

We are champions of rail, inspired to build a greener, more sustainable https://www.thetrainline.com/terms/sustainability-faqs future of travel. Trainline enables millions of travellers to find and book the best value tickets across carriers, fares, and journey options through our highly rated mobile app, website, and B2B partner channels.

Great journeys start with Trainline ๐Ÿš„

Now Europe's number 1 downloaded rail app, with over 135 million monthly visits and ยฃ6.3 billion in annual ticket sales, we collaborate with 270+ rail and coach companies in over 40 countries. We want to create a world where travel is as simple, seamless, eco-friendly and affordable as it should be.

Today, we're a FTSE 250 company driven by our incredible team of over 1,000 Trainliners from 50+ nationalities, based across London, Paris, Barcelona, Milan, Edinburgh and Madrid. With our focus on growth in the UK and Europe, now is the perfect time to join us on this high-speed journey.

Introducing Security Operations @ Trainline ๐Ÿ‘‹

Our Security Operations team plays a vital role in protecting Trainline's people, platforms and data. As a Security Operations Engineer, you'll primarily working on monitoring, investigating and responding to security events while helping to strengthen our detection and response capabilities through continuous engineering and automation improvements.

Working closely with Security, Engineering and Technology teams, you'll combine operational analysis with hands-on engineering, using Splunk, automation and AI to improve threat detection, streamline investigations and enhance our overall security posture. You'll optimise our security tooling, improve detection capabilities and support incident response across the business through threat hunting, continuous improvement and meaningful reporting that enables informed security decisions. If you're passionate about cybersecurity and enjoy solving complex problems in a collaborative environment, we'd love to hear from you.

In this role as the Security Operations Engineer, you will... ๐Ÿš„

- Monitor, triage and investigate security alerts, leading technical investigations and working with stakeholders to contain, remediate and learn from security incidents.

- Use Splunk Search Processing Language (SPL) to investigate security events, identify patterns of malicious activity and support incident response.

- Design, develop, automate and continuously tune Splunk detection rules, improving alert fidelity, reducing false positives and expanding visibility across our technology estate.

- Build and enhance automation and AI-driven workflows to improve threat detection, investigation and alert triage, enabling the team to respond more effectively and efficiently at scale.

- Perform proactive threat hunting using threat intelligence and security telemetry to identify emerging threats, improve detection capabilities and help shape our Security Operations roadmap.

- Support the administration, configuration and continuous optimisation of our SIEM platform (Splunk), ensuring it remains resilient, up to date, cost effective and aligned with industry best practice.

- Partner with Engineering and Technology teams to embed security best practices into systems, tooling and operational processes, while supporting vulnerability management activities, including the assessment and response to critical and zero-day vulnerabilities.

- Participate in the On-Call Rota with the Team.

- Produce clear documentation, dashboards and reporting that provide operational insight, support knowledge sharing and enable stakeholders to make informed security decisions. You'll also contribute to the wider Security function by participating in the on-call rota (once established in the role) and supporting compliance and certification activities, including GDPR, PCI DSS and ISO 27001.

We'd love to hear from you if you have... ๐Ÿ”

- Hands-on experience with Splunk, including developing and tuning detection rules, log management and investigating security events using Splunk Search Processing Language (SPL).

- Experience designing, automating and continuously improving threat detection capabilities using automation and AI to enhance Security Operations.

- Experience applying AI, whether through vendor-provided capabilities or custom workflows, to improve threat detection, investigations or operational efficiency would be highly beneficial.

- Strong technical knowledge across cybersecurity, infrastructure, networking or cloud technologies, with the ability to investigate security events and make informed, risk-based decisions.

- Experience working with security technologies such as Microsoft Defender, endpoint detection and response (EDR) solutions and SIEM platforms.

- Experience working with Web Application Firewalls (WAF), including creating, tuning and maintaining WAF rules to protect internet-facing applications, would be highly beneficial.

- Exp

Continue with your CV

PDF, Word, or image. Under 10MB.

Apply on company site