Trainline

Trainline

London

SecOps Engineer

Full-Time£65,000 - 105,000 per year2 days agoUnited Kingdom
IT

Job Description

Salary: £65,000 - 105,000 per year

Requirements:
  • Hands-on experience with Splunk, including developing and tuning detection rules, log management, and investigating security events using Splunk Search Processing Language (SPL).
  • Experience designing, automating, and continuously improving threat detection capabilities using automation and AI to enhance Security Operations.
  • Experience applying AI, whether through vendor-provided capabilities or custom workflows, to improve threat detection, investigations, or operational efficiency would be highly beneficial.
  • Strong technical knowledge across cybersecurity, infrastructure, networking, or cloud technologies, with the ability to investigate security events and make informed, risk-based decisions.
  • Experience working with security technologies such as Microsoft Defender, endpoint detection and response (EDR) solutions, and SIEM platforms.
  • Experience working with Web Application Firewalls (WAF), including creating, tuning, and maintaining WAF rules to protect internet-facing applications, would be highly beneficial.
  • Experience with vulnerability management, including assessing, prioritising, and responding to critical vulnerabilities and zero-day exploits, would be beneficial.
  • Experience working within an e-commerce or high-traffic digital environment would be highly beneficial, with an understanding of the unique security challenges associated with customer-facing platforms.
  • Excellent analytical, communication, and documentation skills, with the ability to collaborate effectively across teams and explain technical concepts clearly to both technical and non-technical stakeholders.
  • Experience supporting compliance frameworks such as GDPR, PCI DSS, or ISO 27001 would be helpful but isnt essential.
Responsibilities:
  • Monitor, triage, and investigate security alerts, leading technical investigations and working with stakeholders to contain, remediate, and learn from security incidents.
  • Use Splunk Search Processing Language (SPL) to investigate security events, identify patterns of malicious activity, and support incident response.
  • Design, develop, automate, and continuously tune Splunk detection rules, improving alert fidelity, reducing false positives, and expanding visibility across our technology estate.
  • Build and enhance automation and AI-driven workflows to improve threat detection, investigation, and alert triage, enabling the team to respond more effectively and efficiently at scale.
  • Perform proactive threat hunting using threat intelligence and security telemetry to identify emerging threats, improve detection capabilities, and help shape our Security Operations roadmap.
  • Support the administration, configuration, and continuous optimisation of our SIEM platform (Splunk), ensuring it remains resilient, up to date, cost effective, and aligned with industry best practice.
  • Partner with Engineering and Technology teams to embed security best practices into systems, tooling, and operational processes, while supporting vulnerability management activities, including the assessment and response to critical and zero-day vulnerabilities.
  • Participate in the on-call rota with the team.
  • Produce clear documentation, dashboards, and reporting that provide operational insight, support knowledge sharing, and enable stakeholders to make informed security decisions.
  • Contribute to the wider Security function by supporting compliance and certification activities, including GDPR, PCI DSS, and ISO 27001.
Technologies:
  • AI
  • Cloud
  • Support
  • Mobile
  • Security
  • Splunk
  • WAF
  • Web

More:

We are Trainline, champions of rail, building a greener, more sustainable future of travel. We enable millions of travellers to find and book the best value tickets across carriers, fares, and journey options through our mobile app, website, and B2B partner channels. As Europes number 1 downloaded rail app, we handle over 135 million monthly visits and 6.3 billion in annual ticket sales, working with 270+ rail and coach companies across more than 40 countries. We are a FTSE 250 company with a team of over 1,000 Trainliners from 50+ nationalities, based across London, Paris, Barcelona, Milan, Edinburgh, and Madrid. This Security Operations Engineer role sits within our Security Operations team in Technology and Information Security, working in a hybrid model with a minimum of 60% office time over a 12-week period and a 28-day Work from Abroad policy. We offer private healthcare and dental insurance, a generous work from abroad policy, a 2-for-1 share purchase plan, an EV Scheme, extra festive time off, excellent family-friendly benefits, clear career paths, transparent pay bands, personal learning budgets, and regular learning days. Our salary range is 55K to 65K. We value Think Big, Own It, Travel Together, and Do Good, and we are committed to building an inclusive workplace where everyone belongs.

last updated 34 week of 2026

Interested in this role?

Submit your application now

How to Apply

Ready to apply for this position? Here's what you need:

  • An updated resume highlighting relevant experience
  • A compelling cover letter (if required)
  • Portfolio or work samples (for relevant positions)

About Trainline

Trainline

Trainline

London

IT

Skills & Technologies

GoGitAIUI

Inferred from job description

Salary Insight

£85,000

This role

£60,000

UK median

This salary is 42% above the UK median for Software Engineers60,000/yr).

Based on 2024–2025 UK technology sector benchmarks

Explore More UK Opportunities

Thousands of tech jobs across the United Kingdom