At a Glance
- Tasks: Conduct hands-on security testing across applications, cloud platforms, and infrastructure.
- Company: Join Allwyn UK, a leading national lottery operator with a mission to change lives.
- Benefits: Enjoy competitive salary, generous leave, wellness allowance, and flexible benefits.
- Other info: Be part of a diverse team dedicated to innovation and positive change.
- Why this job: Make a real impact on security while supporting good causes through the National Lottery.
- Qualifications: Experience in security testing and knowledge of web applications and cloud environments.
The predicted salary is between 50000 - 60000 € per year.
At the heart of everything we do is our vision to change lives every day, and our mission to grow The National Lottery responsibly and champion its impact. We are Allwyn UK, part of the Allwyn Entertainment Group – a multi-national lottery operator with a market-leading presence across the USA and Europe.
This role provides hands-on security testing across Allwyn's applications, cloud platforms and infrastructure. The main purpose of the role is to improve day-to-day testing coverage across web applications, APIs, backend services, cloud-hosted workloads, internal infrastructure and network-facing services, while supporting findings validation, remediation and retesting.
This is an exciting opportunity to work within the national lottery and gain exposure to not just security testing across our technology stack but exposure to supporting both delivery and cyber defence.
What you’ll be doing
- Security testing delivery
- Deliver security testing across web applications, REST APIs, backend services, cloud-hosted workloads, internal infrastructure and network-facing services.
- Support testing of AWS and Azure environments, including common configuration weaknesses, access-control issues, exposed services and baseline cloud security concerns.
- Carry out testing across network and infrastructure layers, including host, service and exposure weaknesses where they affect enterprise risk.
- Support application-focused testing across web applications, APIs and backend services, including common issues around authentication, authorisation, input validation, session handling and data exposure.
- Use common security testing and validation tools to support manual testing, verification and basic assessment activity.
- Findings, remediation and incident support
- Investigate reported vulnerability findings where testing support is needed, help validate whether an issue is genuine, support teams with remediation advice, and retest fixes to confirm they are effective.
- Support security incidents where testing input is required, including helping assess technical impact, validate weaknesses and support follow-up testing.
- Produce clear, practical findings and support teams with remediation guidance that can be acted on.
- Support retesting, evidence collection, findings validation and tracking so that issues can be properly closed out.
What experience we’re looking for
- Essential
- Hands-on experience in security testing across a mix of application, cloud, infrastructure or network environments.
- Working knowledge of web application testing, API testing and common backend-service security issues.
- Working knowledge of common application security frameworks and methodologies, including OWASP Top 10, OWASP API Security Top 10, secure authentication and authorisation patterns, and practical remediation approaches for common web and API weaknesses.
- Understanding of broader security testing approaches across applications, cloud and infrastructure, including vulnerability assessment, manual verification, configuration review and risk-based testing methods.
- Working knowledge of AWS and / or Azure, including common configuration and access-control risks.
- Understanding of network and infrastructure security basics, including exposed services, host weaknesses and common enterprise network risks.
- Ability to use common testing and validation tools and explain findings clearly.
- Ability to work with engineering and platform teams to get findings understood, fixed and retested.
- Familiarity with secure development and review practices, including the ability to support developers with remediation advice and explain issues clearly in the context of software delivery.
- Desirable
- Experience with containerised workloads and cloud-hosted application platforms.
- Exposure to mobile application testing or backend-service testing.
- Experience interpreting SAST or DAST outputs.
- Familiarity with wider application security references and standards such as OWASP ASVS, CWE, secure coding guidance, and common testing checklists used for web, API and cloud-hosted services.
- Exposure to threat modelling inputs or secure design review activity, with the ability to use those outputs to help shape testing scope and coverage.
- Experience in regulated, high-availability or transaction-critical environments.
- Relevant certifications such as CREST, OSCP or equivalent hands-on experience.
Tools and technologies
The role should be comfortable using a practical mix of testing and validation tools across applications, cloud and infrastructure. This is not intended to be a tool-only role, but the person should be able to work effectively with the kinds of tools commonly used for security testing and validation.
- Burp Suite for web and API testing.
- Kali Linux and common Linux-based testing workflows.
- Nmap, Nessus, Wireshark and similar tools for network, service and infrastructure testing.
- Exposure to tools and outputs used in SAST, DAST and IAST-driven testing.
- Familiarity with cloud and container environments, and the ability to work with outputs from posture, vulnerability or configuration tools used in AWS, Azure and supporting platforms.
- Basic scripting or automation capability, for example in Python, would be useful.
About us
At Allwyn, we are dedicated to changing lives and growing the National Lottery responsibly, championing its positive impact on people, places, and the planet.
Benefits
- Company Bonus Scheme
- Matched pension contributions up to 8.5%
- 26 days annual leave + 2 Life Days (and bank holidays)
- Single Private Health Cover
- Complimentary Private Medical Income Protection
- Flexible Benefits – EV Scheme, Money Coach, Will Writing, Mortgage Advice, Dental and Eye Care Schemes.
- Enhanced Family Leave (Maternity, Paternity, Adoption)
- Wellness Allowance £500
- Employee Assistance Programme
- Discounted Health Assessments
- Volunteering Days
- Matched Funding
We are a Disability Confident Leader which means we’ve taken proactive steps to ensure our workplace is accessible and inclusive for disabled and neurodivergent colleagues and candidates.
Security Tester employer: Allwyn UK
Allwyn UK is an exceptional employer that prioritises innovation, inclusion, and employee wellbeing. With a strong commitment to sustainability and community impact, employees enjoy a supportive work culture that fosters personal and professional growth, alongside a comprehensive benefits package including generous leave, health cover, and wellness allowances. Join us in making a meaningful difference while advancing your career in a dynamic environment at the forefront of the national lottery sector.
StudySmarter Expert Advice🤫
We think this is how you could land Security Tester
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can refer you directly.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your security testing projects. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by brushing up on common security testing scenarios. Practice explaining your thought process and how you approach problem-solving. Confidence is key, so be ready to impress!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are genuinely interested in joining our mission at Allwyn.
We think you need these skills to ace Security Tester
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your relevant experience in security testing. We want to see how your skills align with the role, so don’t hold back on showcasing your hands-on experience!
Showcase Your Knowledge:Mention any familiarity you have with security frameworks like OWASP or tools like Burp Suite. We love seeing candidates who are up-to-date with industry standards and can demonstrate their understanding of security testing methodologies.
Be Clear and Concise:When writing your application, keep it straightforward. Use clear language to explain your experience and how it relates to the job. We appreciate a well-structured application that gets straight to the point!
Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. We can’t wait to hear from you!
How to prepare for a job interview at Allwyn UK
✨Know Your Security Basics
Before the interview, brush up on your knowledge of common security frameworks like OWASP Top 10. Be ready to discuss how these apply to web applications and APIs, as well as any hands-on experience you have with security testing tools.
✨Showcase Your Hands-On Experience
Prepare specific examples from your past roles where you conducted security testing across various environments. Highlight your experience with AWS or Azure, and be ready to explain how you identified and remediated vulnerabilities.
✨Communicate Clearly
During the interview, focus on articulating your findings and remediation advice clearly. Use straightforward language to explain complex security issues, as this will demonstrate your ability to work effectively with engineering teams.
✨Stay Updated on Trends
Familiarise yourself with the latest trends in security testing, including containerised workloads and mobile application testing. Showing that you’re proactive about learning can set you apart from other candidates.