About the Role
The Security Operations Engineer will monitor, investigate, and respond to security events, while enhancing detection and response capabilities through engineering and automation. This role involves collaborating with Security, Engineering, and Technology teams to improve threat detection, streamline investigations, and strengthen the overall security posture using tools like Splunk and AI.
Responsibilities
- Monitor, triage, and investigate security alerts, leading technical investigations and collaborating with stakeholders for containment, remediation, and learning from incidents.
- Utilize Splunk Search Processing Language (SPL) for security event investigations, identifying malicious activity patterns, and supporting incident response.
- Design, develop, automate, and tune Splunk detection rules to improve alert fidelity, reduce false positives, and expand visibility.
- Build and enhance automation and AI-driven workflows for improved threat detection, investigation, and alert triage.
- Perform proactive threat hunting using threat intelligence and security telemetry to identify emerging threats and shape the Security Operations roadmap.
- Support the administration, configuration, and optimization of the SIEM platform (Splunk).
- Partner with Engineering and Technology teams to embed security best practices and support vulnerability management.
- Participate in the On-Call Rota.
- Produce clear documentation, dashboards, and reports for operational insight and informed security decisions.
- Support compliance and certification activities, including GDPR, PCI DSS, and ISO 27001.
Requirements
- Hands-on experience with Splunk, including developing and tuning detection rules, log management, and investigating security events using SPL.
- Experience designing, automating, and continuously improving threat detection capabilities using automation and AI.
- Experience applying AI to improve threat detection, investigations, or operational efficiency.
- Strong technical knowledge across cybersecurity, infrastructure, networking, or cloud technologies.
- Ability to investigate security events and make informed, risk-based decisions.
- Experience working with security technologies such as Microsoft Defender, EDR solutions, and SIEM platforms.
- Experience working with Web Application Firewalls (WAF), including creating, tuning, and maintaining WAF rules.
- Experience with vulnerability management, including assessing, prioritizing, and responding to critical vulnerabilities and zero-day exploits.
- Experience working within an e-commerce or high-traffic digital environment.
- Understanding of security challenges associated with customer-facing platforms.
- Excellent analytical, communication, and documentation skills.
- Ability to collaborate effectively across teams and explain technical concepts clearly.
- Experience supporting compliance frameworks such as GDPR, PCI DSS, or ISO 27001.
Skills
- Splunk
- Splunk Search Processing Language (SPL)
- Automation
- AI
- Cybersecurity
- Infrastructure
- Networking
- Cloud Technologies
- Microsoft Defender
- Endpoint Detection and Response (EDR)
- SIEM platforms
- Web Application Firewalls (WAF)
- Vulnerability Management
- Threat Hunting
- Threat Intelligence
- GDPR
- PCI DSS
- ISO 27001
Location
- London
- Paris
- Barcelona
- Milan
- Edinburgh
- Madrid
Work Type
- Hybrid
- Remote (Work from Abroad Policy)
Benefits
- Private healthcare & dental insurance
- Generous work from abroad policy
- 2-for-1 share purchase plans
- EV Scheme
- Extra festive time off
- Excellent family-friendly benefits
- Clear career paths
- Transparent pay bands
- Personal learning budgets
- Regular learning days
About the Company
- Trainline is a company focused on building a greener, more sustainable future of travel through rail.
- It is Europe's number 1 downloaded rail app, with over 135 million monthly visits and £6.3 billion in annual ticket sales.
- Trainline collaborates with 270+ rail and coach companies in over 40 countries.
- It is a FTSE 250 company with over 1,000 employees from 50+ nationalities.
- The company has a focus on growth in the UK and Europe.
- Trainline's values are Think Big, Own It, Travel Together, and Do Good.
- The company is committed to creating inclusive workplaces where diversity is valued and celebrated.
Equal Opportunity
- We know that having a diverse team makes us better and helps us succeed. And we mean all forms of diversity - gender, ethnicity, sexuality, disability, nationality and diversity of thought. That's why we're committed to creating inclusive places to work, where everyone belongs and differences are valued and celebrated.
