At a Glance
- Tasks: Ensure software security through testing, collaboration, and proactive vulnerability management.
- Company: Join Allwyn UK, a leading lottery operator committed to positive societal impact.
- Benefits: Enjoy competitive salary, generous leave, private health cover, and wellness support.
- Other info: Be part of a diverse team driving positive change and sustainability.
- Why this job: Make a real difference in application security while working with innovative technologies.
- Qualifications: 3-5 years in application security testing and strong knowledge of security tools.
The predicted salary is between 63000 - 77000 £ per year.
At the heart of everything we do is our vision to change lives every day, and our mission to grow The National Lottery responsibly and champion its impact.
We are Allwyn UK, part of the Allwyn Entertainment Group – a multi-national lottery operator with a market-leading presence acrossthe USA (Michigan and Illinois) and Europe, including Czech Republic, Austria, Greece, Cyprusand Italy.
While the main contribution of The National Lottery to society is through the funds togood causes, at Allwynwe put our purpose and values at the heart of everything we do.
Join us as we embark on a once-in-a-lifetime, largescale transformation journey by creating a National Lottery that delivers more money togood causes.
We’lltalk a bit more about us further down the page, but for now –let’stalk about the role and whowe’relooking for…
A bit about the role
The Application Security Engineeris responsible forensuring the security of software applications through rigorous testing and validation.
This role is dedicated to embedding security testing throughout the software development lifecycle (SDLC), identifyingvulnerabilities, and supporting development teams in remediating security issues.
The focus is on proactive, continuous security assessment of applications, both pre- and post-deployment, tomaintainthe highest standards of software security.
- Whatyou’llbe doing
- Collaborate with development teams to create andmaintainapplication threat models (e. g., STRIDE, DREAD).
- Identifyand document application-specific risks; propose effective countermeasures.
- Integrate andoperateapplication vulnerability scanning tools (e. g., Sonar Cloud, Snyk, OWASP ZAP, Burp Suite, Tenable WAS) within CI/CD pipelines.
- Interpret vulnerability reports, prioritise remediation based on risk, and track resolution with development teams.
- Promote awareness of common application vulnerabilities (e. g., SQL injection, XSS, CSRF) and mitigation strategies (OWASP Top 10, ASVS, MASVS).
- Support development teams in adopting secure coding standards, including static analysis tools, code reviews, and automated linting.
- Plan, execute, and manage Static, Dynamic, Mobile, and Interactive Application Security Testing (SAST, DAST, MAST, IAST).
- Embed security testing into CI/CD pipelines for continuous, automated validation.
- Simulate real-world attack scenarios toidentifyweaknesses in application logic and implementation.
- Develop andmaintainscripts, tools, and processes to automate application security testing.
- Produce clear, actionable security testing reports for technical and non-technical stakeholders.
- Maintain comprehensive documentation of testing methodologies, findings, and remediation guidance.
- Work closely with software engineers, QA, and product teams to embed security best practices.
- Deliver training and awareness sessions on application security testing techniques and secure development.
- What experiencewe’relooking for
Must have
- 3-5+ years of hands-on experience in application security testing
- Strong knowledge of SAST, DAST, MAST, and IAST tools and methodologies.
- Familiarity with secure SDLC and Application Dev Sec Opspractices.
- Experience integratingapplicationsecurity testing into CI/CD pipelines.
- Good understanding of common application vulnerabilities and mitigation strategies (OWASP Top 10, ASVS, MASVS).
- Proficiencyin at least one programming or scripting language (e. g., Python, Java Script, C#).
- Strong analytical, problem-solving, and troubleshooting skills.
- Excellent communication and teamwork abilities.
- Experience in producing clear, concise technical documentation and security reports.
- Commitment to continuous learning and keeping up with evolving application security threats and technologies.
Nice to have
- CRESTCertified Web Application Tester
- Bachelor’s degree in Software Engineering
Key Measures of Success
- Proactive identification and remediation of application vulnerabilities.
- Effective integration ofapplicationsecurity testing into development workflows.
- Demonstrated improvement in application security posture over time.
- Positive feedback from development teamsregardingsecurity testing support.
- Ability to communicate complex security concepts to technical and non-technical stakeholders
About us
At Allwyn, we are dedicated to changing lives and growing the National Lottery responsibly, championing its positive impact on people, places, and the planet.
- Innovation -We pride ourselves on it!We’reconstantly looking for new ways to excite our customers, bringing new products to market toenjoywhich is all supported by our responsible play values and making them accessible to all.
- Giving back –Did you know that playing the lottery generates around £30m a week for charities andgood causesin the UK?
Our aim is to have doubled this number by the end of the first 10-year license.
- Sustainability –Our aim is to become a net zero national lottery.
We have 2030 targets to decarbonise our operations and energy.
We’vealready transitioned to renewable energy providers, made our London and Watford offices zero gas, and ensured our fleet consists of low-emission vehicles.
In addition, we’reworking with our value chain partners to develop a net zero target date.
- Empowering every voice– We believe in creating a culture where everyone feels they belong, can be themselves, has access to opportunities and can thrive for the benefit of good causes.
Our diverse teams are working hard to make all parts of The National Lottery inclusive – whether people play a game in a store or online, because when everyone can play, everyonewins..
An inclusive reward offering with wellbeing at the centre
At Allwyn, inclusion is built into how we care for our people.
Our benefits and policies support colleaguesand their familiesat every stage of life and career.
By prioritising wellbeing and belonging, we create a workplace where everyone feels valued, rewarded, and empowered to succeed.
Our people are more than colleagues -they’rewinners, driving positive change and making a real difference in communities.
Benefits
- Company Bonus Scheme
- Matched pension contributions up to 8.5%
- 26 days annual leave + 2 Life Days (and bank holidays)
- Single Private Health Cover
- Complimentary Private Medical
- Income Protection
- Flexible Benefits – EV Scheme, Money Coach, Will Writing, Mortgage Advice, Dental and Eye Care Schemes.
- Enhanced Family Leave (Maternity, Paternity, Adoption)
- Wellness Allowance£500
- Employee Assistance Programme
- Discounted Health Assessments
- Volunteering Days
- Matched Funding
We are a Disability Confident Leader which meanswe’vetaken proactive steps to ensure our workplace is accessible and inclusive for disabled and neurodivergent colleagues and candidates.
As part of this we offer an interview to disabled applicants who meet the essential requirements of the job.
If you need anyassistanceor adjustments to this job description or in the application process, please contact a member of the talent team at careers@allwyn. co. ukand we’llbe happy to help.
#J-18808-Ljbffr
Application Security Engineer in Watford employer: Allwynuk
At Allwyn UK, we are committed to fostering a vibrant and inclusive work culture that empowers our employees to thrive. As a Technical Content Manager, you will benefit from a comprehensive rewards package, including generous annual leave, matched pension contributions, and a focus on wellbeing through various support initiatives. Join us in our mission to transform the National Lottery while enjoying opportunities for personal and professional growth in a dynamic, agile environment.
StudySmarter Expert Advice🤫
We think this is how you could land Application Security Engineer in Watford
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Allwynuk, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Allwynuk
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Allwynuk. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Application Security Engineer in Watford
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Allwynuk insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Allwynuk that you’re committed to staying ahead in the game.
How to prepare for a job interview at Allwynuk
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Allwynuk to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Allwynuk.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.