Head of Information Security GRC

2 days ago


London, Greater London, United Kingdom Trainline Full time £50,000 - £120,000 per year

About us

We are champions of rail, inspired to build a greener, more sustainable future of travel. Trainline enables millions of travellers to find and book the best value tickets across carriers, fares, and journey options through our highly rated mobile app, website, and B2B partner channels. 

Great journeys start with Trainline  

Now Europe's number 1 downloaded rail app, with over 125 million monthly visits and £5.9 billion in annual ticket sales, we collaborate with 270+ rail and coach companies in over 40 countries. We want to create a world where travel is as simple, seamless, eco-friendly and affordable as it should be. 

Today, we're a FTSE 250 company driven by our incredible team of over 1,000 Trainliners from 50+ nationalities, based across London, Paris, Barcelona, Milan, Edinburgh and Madrid. With our focus on growth in the UK and Europe, now is the perfect time to join us on this high-speed journey. 

Introducing the Information Security Team at Trainline

As Head of Governance, Risk & Compliance (GRC), you'll play a pivotal role in shaping and leading this transformation of our security function. Reporting directly to our CISO, you'll take ownership of how governance, risk, and compliance come together to protect, enable, and future-proof the business. This is about building a cohesive GRC strategy that balances control with creativity, fits Trainline's business context, and drives long-term cultural change.

In this critical role, you will collaborate closely with cross-functional teams including Legal, Engineering, and Procurement to embed risk management into daily operations and strategic initiatives. As a key member of the Security leadership team, your remit will extend beyond risk and compliance to include shaping the security and privacy strategy, enhancing supplier risk processes, and fostering a culture of security awareness across the company. Your leadership and strategic insight will be essential in navigating the evolving regulatory landscape and supporting Trainline's growth ambitions with robust yet pragmatic risk management.

As the Head of Information Security Risk and Compliance at Trainline, you will...

  • Redesign and embed a pragmatic, risk-first GRC framework that integrates governance, risk, and compliance across the business.

  • Assess current maturity and deliver a transformation roadmap that unifies fragmented processes into a single, clear model aligned to Trainline's risk appetite.

  • Maintain key standards such as ISO 27001, ISO 22301, and PCI DSS, while ensuring they add real business value.

  • Manage and develop the Risk and Compliance team, setting clear goals and cultivating an inclusive culture of accountability, continuous learning and collaboration.

  • Develop and deliver concise, data driven risk and compliance reports for senior management and stakeholders, highlighting trends, emerging risks, and mitigation strategies.

  • Act as a trusted advisor to executive stakeholders, providing actionable insight and guidance to support risk-aware decision-making.

  • Partner with Legal, Privacy, Engineering, Procurement, and other functions to embed security, governance, and compliance into products, systems, and processes.

  • Oversee and mature the end-to-end third-party risk management process, focusing on tiering, assurance automation, and stronger alignment with procurement and legal teams.

  • Champion and scale security awareness and governance training programs to build a strong, security-first culture across Trainline.

  • Own the development, communication, and maintenance of information security policies, ensuring alignment with evolving threats and compliance needs.

We would love to hear from you if you have...

  • Experience transforming or scaling GRC or risk management functions within dynamic, high-growth or complex businesses.

  • Proven ability to balance control and creativity — tailoring governance frameworks that fit the business.

  • A proven record of leading and developing high-performing teams, setting clear goals and cultivating accountability and continuous improvement.

  • Deep understanding of enterprise and cyber risk frameworks (ISO 27005, ISO 31000, NIST CSF) and how to communicate risk appetite in business terms.

  • Excellent communication skills, with the ability to present complex risk and compliance information clearly to senior leadership and stakeholders.

  • Strong analytical and critical thinking skills, capable of identifying risks, evaluating controls, and recommending effective mitigation strategies.

  • Experience integrating risk management processes into business operations, including supplier and third-party risk assessments.

  • A collaborative, solutions focussed approach and the ability to work cross-functionally with security, engineering, procurement, and business teams to embed security and compliance requirements.

  • Track record of delivering actionable risk reporting and advisory support to executive teams, influencing strategic decision-making.

More information:

Enjoy fantastic perks like private healthcare & dental insurance, a generous work from abroad policy, 2-for-1 share purchase plans, an EV Scheme to further reduce carbon emissions, extra festive time off, and excellent family-friendly benefits. 

We prioritise career growth with clear career paths, transparent pay bands, personal learning budgets, and regular learning days. Jump on board and supercharge your career from day one 

We're operate a hybrid model to work and ask that Trainliners work from the office a minimum of 60% of their time over a 12-week period. We also have a 28-day Work from Abroad policy.

Our values represent the things that matter most to us and what we live and breathe everyday, in everything we do: 

  • Think Big - We're building the future of rail 

  • Own It - We focus on every customer, partner and journey 

  •   Travel Together - We're one team 

  • Do Good - We make a positive impact 

We know that having a diverse team makes us better and helps us succeed. And we mean all forms of diversity - gender, ethnicity, sexuality, disability, nationality and diversity of thought. That's why we're committed to creating inclusive places to work, where everyone belongs and differences are valued and celebrated.

Interested in finding out more about what it's like to work at Trainline? Why not check us out on LinkedIn, Instagram and Glassdoor 



  • London, Greater London, United Kingdom UK National Audit Office Full time £68,000 - £80,000 per year

    • Role: Information Security Specialist: GRC• Type of contract: Full Time, permanent• Location: Hybrid working. On-site, London or Newcastle, minimum 2 days pw• Salary: London c£68,000 Newcastle c£59,000 plus Civil Service employer pension contribution of 28.9%Please note, we are not able to sponsor work visas or accept temporary visas as we are...


  • London, Greater London, United Kingdom British Heart Foundation Full time £60,000 - £80,000 per year

    Are you an Information Security expert looking to work for one of the UK's largest charities? British Heart Foundation (BHF) is undergoing a digital transformation and seeking an Information Security Manager to oversee Governance, Risk, and Compliance (GRC) within the security team and ensure regulatory and policy compliance. Joining a dynamic and growing...


  • London, Greater London, United Kingdom Checkatrade Full time

    Join us as Head of Information Security**Want to do work that really matters?At Checkatrade, we're building the UK's go-to home improvement marketplace. Every day, we help millions of homeowners find therighttradesperson for the job, fast, fair, and without the faff.We're looking for an experienced and highly motivatedHead of Information Security**to join...


  • London, Greater London, United Kingdom Meta Full time £80,000 - £120,000 per year

    Meta is seeking a highly skilled Security GRC Program Lead to join our Risk Organization's Governance, Risk, and Compliance (GRC) pillar. This role is pivotal in providing second-line oversight of Meta's security risk management and compliance across multiple business units, regulatory entities, and governance forums. As a senior individual contributor, you...


  • London, Greater London, United Kingdom Arriva Group Full time £60,000 - £120,000 per year

    Arriva is a leading European passenger transport partner, operating in 11 countries across the UK and Europe. The company employs around 35,000 people, delivering more than 1.5 billion passenger journeys connecting people and communities safely, reliably and sustainably.We have strong roots dating back to 1938, an ambitious growth and sustainability agenda,...


  • London, Greater London, United Kingdom Arriva Group Full time £80,000 - £120,000 per year

    Arriva is a leading European passenger transport partner, operating in 11 countries across the UK and Europe.  The company employs around 35,000 people, delivering more than 1.5 billion passenger journeys connecting people and communities safely, reliably and sustainably. We have strong roots dating back to 1938, an ambitious growth and sustainability...


  • London, Greater London, United Kingdom Robert Walters Full time

    My client, an International bank, based in London, is looking for an Information Security Analyst to join it's team. Three MUST for this role: 1) Three days per week in the office 2) They dont offer sponsorship 3) You must come from banking or financial services background 4) Must have at least 2/3 years experience in your current firmAbout The Information...

  • GRC Analyst

    4 days ago


    London, Greater London, United Kingdom Maxwell Bond Full time £50,000 - £57,000 per year

    GRC Analyst – Cybersecurity ConsultancyLocation: Remote UK (Occasional Office Visits)Salary:£50,000-£57,000 + BenefitsOverviewWe're representing a highly accredited UKcybersecurity consultancythat is seeking aGRC Analystto join its growing governance, risk, and compliance team.This role offers the opportunity to work across a diverse portfolio of...


  • London, Greater London, United Kingdom WiseTech Global Full time £60,000 - £120,000 per year

    The RoleWe're looking for a technically-grounded Senior IS Compliance Analyst who speaks both security operations and compliance language fluently. This role sits at the critical intersection of technical security and governance, requiring someone who can translate complex security architectures into compliance frameworks and vice versa.You'll be...


  • London, Greater London, United Kingdom Barclay Simpson Full time

    We're working with a leading financial services business committed to maintaining the highest standards of data protection and integrity across its cloud environments. They are seeking a dedicated Senior Information Security Analyst to focus on Cloud Security GRC.In this role, you'll lead cloud risk assessments, enforce security policies and standards, and...