Product Security Engineer ensuring security in cloud-native product development at Trainline. Collaborating with cross-functional teams to improve security practices and safeguard digital channels.
Responsibilities
Support the integration of security practices across the product development lifecycle
Work with teams to promote secure-by-default and a shift-left approach to security
Help integrate security checks into CI/CD workflows
Assist in triaging and analysing findings from automated tooling
Review and triage incoming security issues from scans and bug reports
Record, prioritise and help track remediation with developers and platform teams
Participate in threat modelling sessions and documentation efforts
Help promote secure coding principles across teams
Assist with aligning product security practices with relevant security frameworks and standards
Requirements
Relevant education, training, or practical experience in cyber/information security or software engineering/development
Understanding of common security risks affecting applications, APIs, and distributed systems
Familiarity with secure coding principles, the software development lifecycle (SDLC) and threat modelling concepts
Exposure to security testing approaches such as SAST, DAST, or dependency scanning
Basic programming or scripting ability (e.g. Python, JavaScript, or similar)
Interest in building or improving security tooling, automation, or developer workflows
Strong analytical and problem-solving skills
Ability to collaborate effectively with engineers and communicate security concerns clearly
Junior Consultant working on Cyber Security standards and customer advisory at MKS4U IT - Beratungs GmbH. Engaging in security assessments and developing long - term security strategies.
IT - Security Consultant at Institut für Datenschutz und Datensicherheit guiding IT compliance and security strategies. Engage with clients to enhance IT security practices across Germany.
Business Development Representative creating and managing lead generation pipelines for cybersecurity solutions. Engaging with enterprise clients in Switzerland and Germany in a hybrid work model.
Information Security Officer responsible for developing and implementing security strategies at an IT service provider for the food and beverage industry. Engaging with teams and management on cyber risks and compliance.
Information Security Manager leading CISOaaS or GRC consultants for NVISO in Germany. Enhancing clients’ cybersecurity posture and driving strategic security initiatives.
Técnico de Segurança do Trabalho JR assisting with safety documentation and training for field activities at Arcadis. Focused on sustainable solutions in engineering and consulting.
Senior Security Engineer managing the vulnerability management program and collaborating with engineering teams at Causaly. Focused on cloud security and secure coding practices.
Infra Security Engineer focusing on endpoint security solutions in South Korea's urban mobility services. Collaborating on security architecture and threat detection initiatives.
Compliance Specialist managing documentation and policies for Orro's Information Security Management System. Supporting essential compliance activities across ISO 27001 and IRAP with strong attention to detail.
Senior Cyber Security Consultant supporting client cybersecurity development initiatives. Job focuses on administrative and technical aspects of cybersecurity within a collaborative consulting team setting.