Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Trainline

Senior Product Security Engineer

Trainline

. Define and own the product security roadmap, aligning priorities with business goals .

Posted 10/2/2026full-timeLondon • United KingdomSenior💰 £90,000 - £100,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in application security, including vulnerability management, threat modeling, and secure coding practices. Proficient in aligning security initiatives with business goals and compliance standards such as OWASP, NIST, ISO 27001, GDPR, and PCI DSS.

Highest-signal resume keywords
Application Security Vulnerability ManagementThreat ModellingSAST and DASTSecure Coding PracticesMobile Application Security

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Vulnerability ManagementThreat ModellingSASTDASTSecure CodingApplication SecurityRisk AssessmentCI/CD Security IntegrationCloud-Native SecurityContainer Security
Soft Skills
Influencing Engineering LeadershipTraining and MentoringCollaboration
Tools & Technologies
Vulnerability Scanning ToolsApplication Security Posture Management ToolsPenetration Testing Tools
Industry Keywords
OWASPNISTISO 27001GDPRPCI DSSAuthenticationAuthorizationOAuth 2.0OpenID ConnectSecurity Champions Programme

Tech Stack

Tools & technologies
AndroidCloudiOS

About the role

Key responsibilities & impact
  • Define and own the product security roadmap, aligning priorities with business goals
  • Influence engineering leadership to embed security into product design, development and deployment
  • Establish and own the application security vulnerability management process
  • Triage and prioritise vulnerabilities and track remediation
  • Set and report metrics including MTTR by severity and security testing coverage
  • Conduct threat modelling for web, mobile and API services
  • Assess application and API security through code reviews, SAST and DAST
  • Manage third-party penetration tests from scoping through remediation tracking
  • Strengthen security for iOS and Android applications and their APIs
  • Implement, maintain and automate vulnerability scanning and application security posture management tools
  • Partner with engineering teams to remediate vulnerabilities and prevent recurrence
  • Deliver secure coding and deployment training and mentoring
  • Establish and grow a security champions programme
  • Align product security practices with OWASP, NIST, ISO 27001, GDPR and PCI DSS
  • Support compliance and audit efforts and monitor emerging threats

Requirements

What you’ll need
  • Significant experience identifying, assessing and mitigating security risks across application design, code and deployed products
  • Experience setting up and running application security vulnerability management processes and reporting
  • Experience shaping and delivering a product or application security roadmap
  • Ability to influence engineering leaders and use metrics to demonstrate progress and risk reduction
  • Experience securing mobile applications and APIs, including testing iOS and Android apps
  • Knowledge of authentication and authorisation approaches such as OAuth 2.0 and OpenID Connect
  • Hands-on experience with SAST, DAST and vulnerability scanning solutions
  • Practical experience with threat modelling and security reviews
  • Experience scoping and managing third-party penetration tests
  • Strong grasp of secure coding practices
  • Experience embedding security into software development workflows and CI/CD pipelines
  • Experience with cloud-native, containerised and infrastructure as code environments
  • Familiarity with OWASP, PCI DSS, ISO 27001 and GDPR
  • Experience with or knowledge of security champions programmes, risk assessments or regulatory compliance standards would be helpful

Benefits

Comp & perks
  • Private healthcare and dental insurance
  • Generous work from abroad policy
  • 2-for-1 share purchase plans
  • EV Scheme
  • Extra festive time off
  • Family-friendly benefits
  • Clear career paths
  • Transparent pay bands
  • Personal learning budgets
  • Regular learning days
  • Hybrid working model
  • 28-day Work from Abroad policy