Key Notes
Product-security ownership across web, mobile and APIs is the work of this Trainline engineer. You’ll set the security roadmap, manage vulnerabilities and embed threat modelling and secure development into engineering workflows. Significant application-security experience, mobile and API protection and hands-on SAST or DAST are required, including penetration-test coordination and security automation. The full-time London role pays £90,000–£100,000 and requires at least 60% office attendance over twelve weeks.
What You'll Work On
- Own the product-security roadmap and vulnerability process, tracking severity, remediation times and test coverage to communicate risk to engineering leadership.
- Threat-model web, mobile and API services, assess code and deployed applications and coordinate third-party penetration tests and corrective action.
- Strengthen iOS, Android and API authentication, authorisation, storage and abuse protection, embedding security tools and automation into CI/CD workflows.
- Develop secure-coding knowledge and security champions, aligning engineering practices with OWASP, NIST, PCI DSS, ISO 27001 and GDPR requirements.
What They Are Looking For
- Experience: Significant application risk assessment, mitigation and vulnerability-management experience, including product-security roadmap delivery.
- Technical: Mobile and API security, including iOS or Android testing and OAuth 2.0 or OpenID Connect.
- Technical: SAST, DAST, scanning, threat modelling, security reviews and third-party penetration-test management.
- Technical: Secure development and CI/CD automation, ideally in cloud-native, container and infrastructure-as-code environments.
- Domain: OWASP, PCI DSS, ISO 27001 and GDPR familiarity.
- Preferred: Security-champions development, risk assessments or regulatory-compliance knowledge are advantageous.