About the job
Trainline connects millions of travelers with rail and coach tickets, offering a range of options through its app, website, and B2B channels. With a focus on making travel simpler and more sustainable, Trainline partners with over 270 transport companies in 40 countries. The company processes more than 135 million visits monthly and handles £6.3 billion in ticket sales each year. Headquartered in London and present in major European cities, Trainline's team includes more than 1,000 people from 50+ nationalities.
The Security team works to strengthen risk management as technology and AI risks change. Collaboration with teams across the business helps keep systems and data secure.
Role overview
The Senior Information Security Risk Analyst, based in London and reporting to the GRC Manager, will play a key role in advancing Trainline’s security risk management program. This position focuses on addressing both established and emerging risks, particularly those related to AI and cloud technologies.
What you will do
- Manage information security risks, including traditional cyber threats and AI-specific risks such as data quality and model bias.
- Align risk management activities with Trainline’s business risk appetite.
- Work with Engineering, Data Science, Legal, and Internal Audit teams to maintain a broad perspective on information, cyber, and AI risks.
- Promote strong risk governance in a cloud-first, AI-driven environment.
- Conduct risk assessments for both existing and new AI use cases.
Collaboration
This role requires frequent interaction with both technical and business teams. The aim is to make sure risk management practices are practical and integrated into daily operations.

