Allwyn UK
Allwyn UK
51 – 200 Employees
eCommerceGaming
Allwyn UK operates The UK National Lottery and is part of Allwyn Entertainment Group, an international lottery and gaming business with operations across several European markets. Its work combines technology, digital gaming and large-scale transformation in the betting and gaming sector, with a focus on innovation and responsible play. Through The UK National Lottery, Allwyn UK supports a nationally significant service while pursuing new ways to improve the player experience and create broader social value.

Security Architect, Web and Cloud Applications — Allwyn UK, Warrington Hybrid

Shape security architecture for Allwyn UK’s National Lottery web, mobile, API and cloud platforms. Lead threat modelling, secure design, application testing and DevSecOps enablement.

Description

  • Support security architecture across mobile and web initiatives from discovery and design through delivery, testing, release and live operation
  • Work with architects, engineers, product teams, delivery leads and external partners to build security into delivery while balancing speed, cost, usability and quality
  • Create and maintain detailed security designs, requirements, architecture decisions, reusable patterns and assurance documentation
  • Lead application threat modelling with methods such as STRIDE, recording threats, attack paths, trust boundaries, mitigations and remaining risks
  • Evaluate web and mobile applications, APIs, microservices, identity journeys, cloud services and third-party integrations
  • Set security requirements covering authentication, authorisation, sessions, secrets, cryptography, data protection, API security, logging, monitoring, resilience and secure configuration
  • Use OWASP Top 10, ASVS, MASVS and secure-by-design practices to guide architectural decisions
  • Advise delivery teams on secure web and mobile application design
  • Shape application security testing approaches across SAST, DAST, SCA, secrets detection, API testing, mobile testing, IAST and penetration testing
  • Help embed security controls and automated checks into CI/CD pipelines, including quality gates and exception processes
  • Evaluate security findings, question false positives, prioritise remediation and help teams implement practical fixes
  • Define penetration testing scopes and security test plans, coordinate assessments and review remediation outcomes
  • Communicate security risks, control deficiencies and compliance issues so accountable owners can make informed risk decisions
  • Develop reusable security patterns, standards, guardrails and reference architectures
  • Coach engineering and architecture communities in secure design, threat modelling and secure development

Requirements

  • Substantial enterprise experience in application security architecture, product security or security engineering
  • Background designing security for modern web applications, mobile applications and APIs
  • Strong understanding of common web, mobile and API threats and the controls used to address them
  • Hands-on threat modelling experience, including converting findings into clear, traceable security requirements
  • Solid knowledge of secure SDLC, DevSecOps, Agile delivery and CI/CD security
  • Experience specifying and interpreting application security testing across SAST, DAST, SCA, API, mobile and penetration testing
  • Knowledge of application identity and access management, including authentication, authorisation, federation, tokens and session protection
  • Understanding of cloud-native environments involving containers, serverless services and microservices
  • Experience mapping data flows and establishing protections for sensitive information
  • Clear written and verbal communicator able to give practical, risk-based guidance
  • Knowledge of web and API security topics including HTTP/S, browser controls, CORS, CSP, REST and GraphQL
  • Knowledge of iOS and Android security, including secure storage, permissions, deep links, transport protection and application integrity
  • Experience using application security tools such as Burp Suite, OWASP ZAP, Snyk, SonarQube or comparable products
  • Working knowledge of a widely used programming or scripting language
  • Knowledge of security logging, monitoring and incident response for customer-facing applications
  • Knowledge of OWASP, NIST, ISO 27001, CIS and PCI DSS standards and frameworks
  • Experience protecting high-volume digital services in a regulated setting is desirable
  • Knowledge of app-store delivery, mobile attestation, application shielding or runtime protection is desirable
  • Familiarity with container security, Kubernetes, infrastructure as code or policy as code is desirable
  • Experience creating application security patterns, standards or developer enablement programmes is desirable
  • A relevant certification such as CISSP, CSSLP, SABSA, CREST or OSWE is desirable
  • Experience in lottery, gaming, payments, retail, finance or another regulated industry is desirable

Benefits

  • Company bonus scheme
  • Pension contributions matched up to 8.5%
  • 26 days of annual leave plus two Life Days and bank holidays
  • Single private health cover
  • Complimentary private medical cover
  • Income protection
  • Flexible benefits including an EV scheme, money coaching, will writing, mortgage advice, dental care and eye care
  • Enhanced maternity, paternity and adoption leave
  • £500 wellness allowance
  • Employee assistance programme
  • Discounted health assessments
  • Volunteering days
  • Matched funding
  • Interview opportunity for disabled applicants who meet the essential criteria
  • Assistance and reasonable adjustments available during the application process

Related Jobs

SPERTON - Where Great People Meet

Sales Executive, Elevators and Car Parking Systems

SPERTON - Where Great People Meet
51 – 200 Employees

Drive elevator and car parking system sales across Mumbai’s Western Region. Build client and dealer relationships, and manage deals from initial enquiry through project execution.

Open