SecOps Engineer

Trainline

United States

Hybrid

USD 110,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Private healthcare
Dental insurance
Work from abroad policy
2-for-1 share purchase plans
EV scheme
Festive time off
Family-friendly benefits

Job summary

Trainline is seeking a Security Operations Engineer to monitor, investigate and respond to security events, strengthening detection and automation across our platforms and data.

You will work with engineering and technology teams to embed security into systems, develop AI-driven workflows, and support incident response and governance across GDPR, PCI DSS and ISO 27001 initiatives.

Qualifications

  • Hands-on Splunk development and tuning of detection rules.
  • Experience designing, automating and improving threat detection using automation/AI.
  • Experience applying AI to improve detection or efficiency.
  • Strong knowledge across cybersecurity, infra, networking or cloud tech.
  • Experience with Defender, EDR, and SIEM platforms.

Responsibilities

  • Monitor, triage and investigate security alerts, leading technical investigations and working with stakeholders to contain, remediate and learn from incidents.
  • Design, develop, automate and tune Splunk detection rules, improving alert fidelity and visibility.
  • Build automation and AI-driven workflows to enhance threat detection and incident response at scale.
  • Perform proactive threat hunting using intelligence and telemetry to shape security roadmap.
  • Manage the SIEM platform (Splunk) configuration and optimization.

Skills

Splunk SPL
Threat detection
Automation & AI
Security operations
Vulnerability management
WAF expertise
EDR
Team collaboration
Analytical skills

Tools

Splunk
Microsoft Defender
EDR solutions
WAF
SIEM platforms
Threat intelligence

Job description

About us

We are champions of rail, inspired to build a greener, more sustainable future of travel. Trainline enables millions of travellers to find and book the best value tickets across carriers, fares, and journey options through our highly rated mobile app, website, and B2B partner channels.

Great journeys start with Trainline

Now Europe’s number 1 downloaded rail app, with over 135 million monthly visits and £6.3 billion in annual ticket sales, we collaborate with 270+ rail and coach companies in over 40 countries. We want to create a world where travel is as simple, seamless, eco-friendly and affordable as it should be.

Today, we’re a FTSE 250 company driven by our incredible team of over 1,000 Trainliners from 50+ nationalities, based across London, Paris, Barcelona, Milan, Edinburgh and Madrid. With our focus on growth in the UK and Europe, now is the perfect time to join us on this high-speed journey.

Introducing Security Operations @ Trainline

Our Security Operations team plays a vital role in protecting Trainline’s people, platforms and data. As a Security Operations Engineer, you’ll primarily be working on monitoring, investigating and responding to security events while helping to strengthen our detection and response capabilities through continuous engineering and automation improvements.

Working closely with Security, Engineering and Technology teams, you’ll combine operational analysis with hands‑on engineering, using Splunk, automation and AI to improve threat detection, streamline investigations and enhance our overall security posture. You’ll optimise our security tooling, improve detection capabilities and support incident response across the business through threat hunting, continuous improvement and meaningful reporting that enables informed security decisions. If you’re passionate about cybersecurity and enjoy solving complex problems in a collaborative environment, we’d love to hear from you.

In this role as the Security Operations Engineer, you will
  • Monitor, triage and investigate security alerts, leading technical investigations and working with stakeholders to contain, remediate and learn from security incidents.
  • Use Splunk Search Processing Language (SPL) to investigate security events, identify patterns of malicious activity and support incident response.
  • Design, develop, automate and continuously tune Splunk detection rules, improving alert fidelity, reducing false positives and expanding visibility across our technology estate.
  • Build and enhance automation and AI‑driven workflows to improve threat detection, investigation and alert triage, enabling the team to respond more effectively and efficiently at scale.
  • Perform proactive threat hunting using threat intelligence and security telemetry to identify emerging threats, improve detection capabilities and help shape our Security Operations roadmap.
  • Support the administration, configuration and continuous optimisation of our SIEM platform (Splunk), ensuring it remains resilient, up to date, cost effective and aligned with industry best practice.
  • Partner with Engineering and Technology teams to embed security best practices into systems, tooling and operational processes, while supporting vulnerability management activities, including the assessment and response to critical and zero‑day vulnerabilities.
  • Participate in the On‑Call Rota with the Team.
  • Produce clear documentation, dashboards and reporting that provide operational insight, support knowledge sharing and enable stakeholders to make informed security decisions. You’ll also contribute to the wider Security function by supporting compliance and certification activities, including GDPR, PCI DSS and ISO 27001.
We’d love to hear from you if you have
  • Hands‑on experience with Splunk, including developing and tuning detection rules, log management and investigating security events using Splunk Search Processing Language (SPL).
  • Experience designing, automating and continuously improving threat detection capabilities using automation and AI to enhance Security Operations.
  • Experience applying AI, whether through vendor‑provided capabilities or custom workflows, to improve threat detection, investigations or operational efficiency.
  • Strong technical knowledge across cybersecurity, infrastructure, networking or cloud technologies, with the ability to investigate security events and make informed, risk‑based decisions.
  • Experience working with security technologies such as Microsoft Defender, endpoint detection and response (EDR) solutions and SIEM platforms.
  • Experience working with Web Application Firewalls (WAF), including creating, tuning and maintaining WAF rules to protect internet‑facing applications.
  • Experience with vulnerability management, including assessing, prioritising and responding to critical vulnerabilities and zero‑day exploits.
  • Experience working within an e‑commerce or high‑traffic digital environment, with an understanding of the unique security challenges associated with customer‑facing platforms.
  • Excellent analytical, communication and documentation skills, with the ability to collaborate effectively across teams and explain technical concepts clearly to both technical and non‑technical stakeholders. Experience supporting compliance frameworks such as GDPR, PCI DSS or ISO 27001 would be helpful but isn’t essential.
More information

Enjoy fantastic perks like private healthcare & dental insurance, a generous work from abroad policy, 2‑for‑1 share purchase plans, an EV Scheme to further reduce carbon emissions, extra festive time off, and excellent family‑friendly benefits.

We prioritise career growth with clear career paths, transparent pay bands, personal learning budgets, and regular learning days. Jump on board and supercharge your career from day one!

We’re operating a hybrid model and ask that Trainliners work from the office a minimum of 60% of their time over a 12‑week period. We also have a 28‑day Work from Abroad policy.

Our values represent the things that matter most to us and what we live and breathe everyday, in everything we do:
  • Think Big – We’re building the future of rail
  • Own It – We focus on every customer, partner and journey
  • Travel Together – We’re one team
  • Do Good – We make a positive impact

We know that having a diverse team makes us better and helps us succeed. And we mean all forms of diversity – gender, ethnicity, sexuality, disability, nationality and diversity of thought. That’s why we’re committed to creating inclusive places to work, where everyone belongs and differences are valued and celebrated.

Interested in finding out more about what it’s like to work at Trainline? Why not check us out on LinkedIn, Instagram and Glassdoor!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Service Desk Engineer
Service Desk Engineer

Trainline • United States

Hybrid
USD 60,000 - 90,000
Private healthcare
Dental insurance
Work from abroad policy
+4
Senior Backend Engineer - .Net
Senior Backend Engineer - .Net

Trainline • United States

On-site
USD 90,000 - 130,000
Private healthcare & dental insurance
Generous work from abroad policy
2-for-1 share purchase plans
+3
Junior Engineer - .NET Backend (London)
Junior Engineer - .NET Backend (London)

Trainline • United States

Hybrid
USD 70,000 - 100,000
Private healthcare
Dental insurance
Work from abroad policy
+1
Engineering Manager (12 Month FTC)
Engineering Manager (12 Month FTC)

Trainline • United States

Hybrid
USD 150,000 - 210,000
Private healthcare
Dental insurance
Work from abroad policy
+4
Engineering Manager - Apps
Engineering Manager - Apps

Trainline • United States

Hybrid
USD 150,000 - 190,000
Private healthcare
Dental insurance
Work from abroad policy
+4
MLOps Engineering Manager
MLOps Engineering Manager

Trainline • United States

Hybrid
USD 120,000 - 190,000
Private healthcare
Dental insurance
Work-from-abroad policy
+3
Senior Organic Search Executive
Senior Organic Search Executive

Trainline • United States

Hybrid
USD 90,000 - 130,000
Private healthcare
Dental insurance
Work from abroad policy
+4
Data Scientist
Data Scientist

Trainline • United States

Hybrid
USD 120,000 - 180,000
Private healthcare
Dental insurance
Work from abroad
+3
Senior Ads Sales Planning & Operations Manager
Senior Ads Sales Planning & Operations Manager

Trainline • United States

Hybrid
USD 90,000 - 140,000
Private healthcare & dental insurance
Work from abroad policy
2-for-1 share purchase plans
+2
Senior Principal Engineer (iOS)
Senior Principal Engineer (iOS)

Trainline • United States

Hybrid
USD 180,000 - 240,000
Private healthcare
Dental insurance
Work from abroad policy
+3