At a Glance
- Tasks: Join us to secure cloud platforms and enhance our gaming services.
- Company: Allwyn UK, a leading multi-national lottery operator with a purpose-driven mission.
- Benefits: Competitive salary, generous leave, health cover, and wellness support.
- Other info: Inclusive culture with opportunities for growth and community impact.
- Why this job: Make a real impact on security while transforming the National Lottery.
- Qualifications: 3-5 years in DevOps with strong cloud security and automation skills.
The predicted salary is between 55000 - 65000 € per year.
At the heart of everything we do is our vision to change lives every day, and our mission to grow The National Lottery responsibly and champion its impact. We are Allwyn UK, part of the Allwyn Entertainment Group – a multi-national lottery operator with a market-leading presence across Europe which includes: Czech Republic, Austria, Greece, Cyprus & Italy, and the US. While the main contribution of The National Lottery to society is through the funds to good causes, at Allwyn we put our purpose and values at the heart of everything we do.
As Allwyn transitions most of its technology services from on premise into a multi-cloud environment, Cloud Security becomes critically important to ensure our core services and gaming platforms are safe. The DevOps engineer is the dedicated DevOps specialist focused on prioritising and resolving security defects and vulnerabilities across cloud platforms and application pipelines. The role acts as the technical bridge between Cloud Engineering and the Security Operation Centre (SOC), Enterprise Security and Cyber Defence teams. The DevOps Engineer ensures that cloud infrastructure and delivery pipelines in AWS and Azure are Secure by Design, automating remediation where possible and embedding security controls into infrastructure as code (IaC) and CI/CD pipelines. You will champion secure engineering practices ensuring both speed of delivery and robust security posture across all environments.
What you’ll be doing:
- Monitor, triage and remediate vulnerabilities across applications, cloud workloads, containers, CI/CD pipelines and IaC repositories.
- Work closely with SOC, Enterprise Security and Cyber Defence teams to respond to active and emerging threats ensuring rapid technical remediation.
- Integrate security tooling into CI/CD pipelines including container scanning and secret scanning.
- Maintain and improve IaC security posture using Terraform and ensure compliance with security baselines and guardrails.
- Automate security checks and enforcement using policy as code, security scanners and cloud native services.
- Support threat modelling and secure solution design with engineering teams.
- Own vulnerability management workflows and ensure timely remediation in line with risk and audit expectations.
- Implement and maintain cloud security configurations (IAM, key management, WAF security groups, logging and monitoring).
- Produce technical documentation, runbooks and remediation guidance for engineering teams.
- Work with product and engineering teams to embed security into development standards.
- Create and enforce governance policies.
What experience we’re looking for:
- 3-5+ years hands-on experience in DevOps, platform engineering or DevSecOps role.
- Strong development background with the ability to build automation and tooling for security remediation.
- Strong infrastructure as code experience using Terraform across AWS and Azure.
- Deep understanding of cloud security principles, identity and access controls, network security and container security in AWS and Azure.
- Experience integrating and managing security controls.
- Solid understanding of CI/CD pipelines including GitHub Actions.
- Practical experience with vulnerability management, threat remediation and working with the Security Operating Centre and Cyber teams.
- Strong understanding of modern application architectures.
Key Measures of Success:
- Reduction in critical and high-risk vulnerabilities within agreed SLAs, cloud and application environments.
- Improved security posture as measured by cloud security benchmarks, IaC scanning results and automated policy compliance.
- Effective collaboration and faster incident response with SOC, Enterprise Security and Cyber Defence teams.
- Automation coverage increased, reducing manual remediation effort and improving consistency.
- Secure pipelines, evidenced by adoption of scanning tools and zero high or critical findings reaching production.
- Positive feedback from engineering teams regarding clarity, support and quality of security guidance.
- Audit and compliance targets met with no major findings related to DevOps or Cloud security practices.
At Allwyn, we are dedicated to changing lives and growing the National Lottery responsibly, championing its positive impact on people, places, and the planet.
Benefits:
- Company Bonus Scheme.
- Matched pension contributions up to 8.5%.
- 26 days annual leave + 2 Life Days (and bank holidays).
- Single Private Health Cover.
- Complimentary Private Medical.
- Income Protection.
- Flexible Benefits – EV Scheme, Money Coach, Will Writing, Mortgage Advice, Dental and Eye Care Schemes.
- Enhanced Family Leave (Maternity, Paternity, Adoption).
- Wellness Allowance £500.
- Employee Assistance Programme.
- Discounted Health Assessments.
- Volunteering Days.
- Matched Funding.
DevOps Engineer (Security focus) in Watford employer: Allwyn UK
At Allwyn UK, we are committed to fostering a dynamic and inclusive work environment where innovation thrives and every voice is heard. As a DevOps Engineer with a focus on security, you will play a pivotal role in our transformative journey, supported by comprehensive benefits including a generous pension scheme, enhanced family leave, and a wellness allowance. Our culture prioritises employee growth and wellbeing, ensuring that you not only contribute to meaningful projects but also develop your career in a supportive and rewarding atmosphere.
StudySmarter Expert Advice🤫
We think this is how you could land DevOps Engineer (Security focus) in Watford
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to cloud security and DevOps. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by brushing up on common DevOps and security questions. Practice explaining your past experiences and how they relate to the role at Allwyn. Confidence is key, so get comfortable talking about your expertise!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re genuinely interested in joining the Allwyn team and contributing to our mission.
We think you need these skills to ace DevOps Engineer (Security focus) in Watford
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the DevOps Engineer role with a security focus. Highlight your relevant experience, especially in cloud security and automation, to show us you’re the perfect fit for our team.
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you’re passionate about security in DevOps and how your skills align with our mission at Allwyn. Keep it engaging and personal!
Showcase Your Projects:If you've worked on any projects related to cloud security or automation, don’t forget to mention them! We love seeing practical examples of your work that demonstrate your expertise and creativity.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it’s super easy!
How to prepare for a job interview at Allwyn UK
✨Know Your Cloud Security Basics
Before the interview, brush up on your cloud security principles, especially in AWS and Azure. Be ready to discuss identity and access controls, network security, and container security. This will show that you understand the core responsibilities of the role and can hit the ground running.
✨Showcase Your Automation Skills
Prepare examples of how you've built automation and tooling for security remediation in past roles. Highlight your experience with Terraform and CI/CD pipelines, particularly GitHub Actions. This will demonstrate your hands-on experience and ability to integrate security into development processes.
✨Understand Vulnerability Management
Familiarise yourself with vulnerability management workflows and be ready to discuss how you've triaged and remediated vulnerabilities in previous positions. Mention any specific tools or methodologies you've used, as this will illustrate your practical experience in a critical area of the job.
✨Emphasise Collaboration
Since the role involves working closely with various teams like SOC and Cyber Defence, prepare to talk about your experience collaborating across departments. Share specific examples of how you've facilitated communication and cooperation to enhance security measures, which is key to success in this position.