At a Glance
- Tasks: Lead advanced penetration testing and enhance application security across modern systems.
- Company: Join Allwyn UK, a leader in responsible lottery operations with a positive societal impact.
- Benefits: Enjoy competitive pay, generous leave, wellness support, and a focus on work-life balance.
- Other info: Be part of a diverse team committed to sustainability and inclusivity.
- Why this job: Make a real difference while working on innovative security projects that protect communities.
- Qualifications: Strong experience in application penetration testing and knowledge of Java-based systems required.
The predicted salary is between 70000 - 90000 € per year.
At the heart of everything we do is our vision to change lives every day, and our mission to grow The National Lottery responsibly and champion its impact. We are Allwyn UK, part of the Allwyn Entertainment Group – a multi-national lottery operator with a market-leading presence across the USA and Europe. While the main contribution of The National Lottery to society is through the funds to good causes, at Allwyn we put our purpose and values at the heart of everything we do.
This role strengthens the Security Testing function by adding senior hands-on capability across application security testing and targeted offensive security work. The main purpose of the role is to improve the depth, consistency and practical value of security testing across Allwyn systems and services, while building enough internal offensive capability to support purple team activity, adversary led testing and better detection and response outcomes. The role is weighted towards application security.
What you’ll be doing
- Application security testing and assurance, around 70 percent:
- Lead and deliver advanced penetration testing across web applications, RESTful APIs, backend services, mobile connected services and supporting application platforms.
- Assess Java based backend systems, especially Spring Boot services, microservice architectures, API gateways and Backend for Frontend layers.
- Test authentication, authorisation, orchestration, input validation, session handling, token management and data exposure risks across modern digital journeys.
- Carry out security testing across cloud hosted and containerised application environments, ideally on AWS.
- Review outputs from SAST, DAST and related controls, separate noise from genuine risk, and help development teams understand what matters and what should be fixed first.
- Support threat modelling and design review activity by translating design and architecture decisions into sensible testing scope and coverage.
- Support release and project assurance by providing clear views on testing depth, remediation expectations and risk based sign off inputs.
- Help develop practical application security testing standards, playbooks and ways of working that can be applied across BAU and project delivery.
- Offensive security and purple team development, around 30 percent:
- Develop and mature an internal purple team methodology that can be used alongside security testing activity and external red team exercises.
- Support offensive security planning with Security Testing leadership and Cyber Defence.
- Use strong Linux and Windows knowledge to identify realistic exploitation paths across hosts, applications and supporting services.
- Bring practical knowledge of binary exploitation and lower level technical analysis where it adds value to application, platform or software component assessments.
- Apply ATT&CK aligned thinking when shaping offensive scenarios, attack paths and purple team test cases.
- Contribute to selected specialist work, including hardware focused testing or low level technical analysis, where there is a clear business need.
- Work with external offensive security partners and turn outputs into practical lessons, follow up actions and measurable improvements.
- Team contribution and capability building:
- Act as a senior technical point of reference within the Security Testing function.
- Coach others in the team and help raise the standard of testing, reporting and technical analysis.
- Improve internal methods, test approaches and reporting so that the function becomes more consistent and easier to scale.
What experience we’re looking for
Essential:
- Strong hands-on experience in application penetration testing across web applications, APIs and service based architectures.
- Strong understanding of Java based backend systems, especially Spring Boot, RESTful APIs and microservice patterns.
- Experience testing API gateways and Backend for Frontend layers.
- Practical knowledge of cloud hosted applications, ideally on AWS.
- Good understanding of modern web and mobile application patterns.
- Strong practical knowledge of Linux and Windows operating systems.
- Working knowledge of binary exploitation and lower level vulnerability analysis.
- Ability to carry out manual testing beyond automated tooling.
- Ability to explain findings clearly to both technical and non-technical stakeholders.
- Experience shaping testing approach, methodology or standards.
Desirable:
- Experience with mobile application assessment.
- Experience with secure code review or code assisted testing.
- Experience with ATT&CK informed assessments.
- Familiarity with EDR and AV evasion concepts.
- Exposure to hardware, embedded or other specialist low level testing techniques.
- Experience in regulated, high availability or transaction critical environments.
- Relevant certifications such as CREST, OSCP, OSWE, OSEP or equivalent demonstrable experience.
- Experience with WAF technology and implementation.
About us
At Allwyn, we are dedicated to changing lives and growing the National Lottery responsibly, championing its positive impact on people, places, and the planet.
Benefits:
- Company Bonus Scheme
- Matched pension contributions up to 8.5%
- 26 days annual leave + 2 Life Days (and bank holidays)
- Single Private Health Cover
- Complimentary Private Medical Income Protection
- Flexible Benefits – EV Scheme, Money Coach, Will Writing, Mortgage Advice, Dental and Eye Care Schemes.
- Enhanced Family Leave (Maternity, Paternity, Adoption)
- Wellness Allowance £500
- Employee Assistance Programme
- Discounted Health Assessments
- Volunteering Days
- Matched Funding
We are a Disability Confident Leader which means we’ve taken proactive steps to ensure our workplace is accessible and inclusive for disabled and neurodivergent colleagues and candidates.
Principal Penetration Tester in Watford employer: Allwyn UK
Allwyn UK is an exceptional employer that prioritises innovation, inclusion, and employee wellbeing, making it a fantastic place for a Principal Penetration Tester to thrive. With a strong commitment to personal and professional growth, employees benefit from a comprehensive rewards package, including generous leave, matched pension contributions, and wellness allowances, all while contributing to meaningful societal impact through the National Lottery. Located in a dynamic environment, Allwyn fosters a culture of collaboration and empowerment, ensuring every voice is heard and valued.
StudySmarter Expert Advice🤫
We think this is how you could land Principal Penetration Tester in Watford
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with potential colleagues on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your penetration testing projects. This gives you a chance to demonstrate your hands-on experience and technical prowess to potential employers.
✨Tip Number 3
Prepare for interviews by brushing up on common penetration testing scenarios and techniques. Practice explaining your thought process clearly, as being able to communicate effectively is just as important as technical skills.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our mission at Allwyn.
We think you need these skills to ace Principal Penetration Tester in Watford
Some tips for your application 🫡
Show Your Passion:When you're writing your application, let your enthusiasm for security testing shine through! We want to see how much you care about making a difference in the world of application security and how you can contribute to our mission at Allwyn.
Tailor Your Experience:Make sure to highlight your hands-on experience with application penetration testing and any relevant projects you've worked on. We love seeing how your skills align with what we're looking for, so don’t hold back on those details!
Be Clear and Concise:While we appreciate detail, clarity is key! Use straightforward language to explain your experience and skills. This helps us understand your background better and makes it easier for us to see how you fit into our team.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets to the right people and shows that you’re serious about joining us on this exciting journey at Allwyn!
How to prepare for a job interview at Allwyn UK
✨Know Your Stuff
Make sure you brush up on your application penetration testing skills, especially with Java-based backend systems like Spring Boot. Be ready to discuss your hands-on experience with web applications, APIs, and microservices, as this role is heavily focused on those areas.
✨Showcase Your Offensive Security Skills
Since the role involves offensive security activities, be prepared to talk about your experience with purple team methodologies and adversary-led assessments. Highlight any practical knowledge you have of binary exploitation and lower-level technical analysis, as these will be key in demonstrating your fit for the position.
✨Communicate Clearly
You’ll need to explain your findings to both technical and non-technical stakeholders, so practice articulating complex concepts in simple terms. Think about how you can provide practical remediation advice that aligns with the company’s mission to grow responsibly.
✨Align with Company Values
Familiarise yourself with Allwyn's vision and values, especially their commitment to sustainability and giving back. During the interview, express how your personal values align with theirs, and share any relevant experiences that demonstrate your commitment to making a positive impact.