About Us
We are champions of rail, inspired to build a greener, more sustainable future of travel. Trainline enables millions of travellers to find and book the best value tickets across carriers, fares, and journey options through our highly rated mobile app, website, and B2B partner channels.
Great journeys start with Trainline đźš„
Now Europe’s number 1 downloaded rail app, with over 125 million monthly visits and £5.9 billion in annual ticket sales, we collaborate with 270+ rail and coach companies in over 40 countries. We want to create a world where travel is as simple, seamless, eco-friendly and affordable as it should be.
Today, we're a FTSE 250 company driven by our incredible team of over 1,000 Trainliners from 50+ nationalities, based across London, Paris, Barcelona, Milan, Edinburgh and Madrid. With our focus on growth in the UK and Europe, now is the perfect time to join us on this high-speed journey.
Introducing Security Operations @ Trainline đź‘‹
We are seeking a highly motivated and detail-oriented Security Operations Engineer to join our dynamic Security Operations Team. As a Security Operations Engineer, you will play a critical role in safeguarding our organization’s assets and data by overseeing the management of Trainline’s SIEM. This is done by ensuring the SIEM is fully operational and that we have the logs and alerts needed to support incident detection and response efforts. Along with this the Security Operations Engineer will support the wider team in monitoring, analysing, and responding to Security events and incidents.
You will ensure that our wider set of Security tools are optimized to their full potential in-line with industry best practice. Create and maintain detailed documentation and provide key insights to management through customized dashboards and reports.
If you are passionate about cybersecurity, eager to stay ahead of emerging threats, and looking to grow within a fast-paced and evolving environment, we’d love to hear from you!
As a Security Analyst at Trainline, you will... đźš„
- Own the management and configuration of our SIEM platform (Splunk), ensuring its fully operational, updated, configured to best practice and providing value for money.
- Drive the creation of new alerts, working with the wider Security Operations team to ensure appropriate enrichment and value, and support the tuning of noisy alerts.
- Identify gaps in our logging and manage the onboarding of these from pre-implementation considerations, through to log availability monitoring.
- Undertake threat hunts to identify gaps in our logging and alerting. Use this along with threat intel to help drive our maturity road map.
- Support day-to-day management and configuration of other key security tools (for example Crowdstrike). Ensure these are configured and used to their full potential and in line with good industry practices.
- Collaborate with SMEs across the business to support and advise on the implementation of security best practice across our tooling and processes.
- Support the wider Security Operations team with the monitoring of our SecOps alert queue. Triage and investigate alerts providing detailed analysis and recommendations on remediation actions.
- Work with our Incident Management Team to respond to Security incidents. Provide Security analysis to validate and size up the problem, along with making recommendations for containment. Follow up after incidents with post incident review (PIR), ensuring any outstanding actions are tracked, and trends are identified.
- Continuously develop and improve the documentation for our Security tooling. Ensuring knowledge is shared with the wider team, and that we have standardised responses for reliability issues.
- Create, maintain, and analyse Security Operations dashboards and reports fed into management and stakeholders across the business. Identify key trends to help inform Trainlines threat landscape and key Security risks.
- (Once established within the team) join the on-call rota, responding to high priority incidents out-of-hours to ensure uninterrupted protection of mission critical systems and data.
- Support the wider Security team in our compliance and accreditation activities (GDRP, PCI, ISO12001).
We'd love to hear from you if you have... 🔍
- Strong technical knowledge, this could be across the domain (Security, Networks, Infrastructure, End User Compute).
- Hands-on experience with SIEM platforms (Splunk, Microsoft Sentinel, Elastic, etc).
- Familiarity with other security tools (EDR, Vulnerability Management, Firewalls, IDS).
- An understanding of cloud platforms (AWS, Azure, GCP) and relevant Security principles.
- A desire to be continuously upskilling your Security knowledge and skills.
- Ability to work under pressure and manage multiple priorities in a dynamic environment.
- Strong analytical and problem-solving skills.
- Clear communication and documentation skills, notably for PIRs and stakeholder updates.
More Information
Enjoy fantastic perks like private healthcare & dental insurance, a generous work from abroad policy, 2-for-1 share purchase plans, an EV Scheme to further reduce carbon emissions, extra festive time off, and excellent family-friendly benefits.
We prioritise career growth with clear career paths, transparent pay bands, personal learning budgets, and regular learning days. Jump on board and supercharge your career from day one!
Our Values Represent The Things That Matter Most To Us And What We Live And Breathe Everyday, In Everything We Do
- đź’ Think Big - We're building the future of rail
- ✔️ Own It - We focus on every customer, partner and journey
- 🤝 Travel Together - We're one team
- ♻️ Do Good - We make a positive impact
We know that having a diverse team makes us better and helps us succeed. And we mean all forms of diversity - gender, ethnicity, sexuality, disability, nationality and diversity of thought. That's why we're committed to creating inclusive places to work, where everyone belongs and differences are valued and celebrated.
Interested in finding out more about what it's like to work at Trainline? Why not check us out on LinkedIn, Instagram and Glassdoor!