Principal Penetration Tester (9 Month FTC) in Watford

Principal Penetration Tester (9 Month FTC) in Watford

Watford Full-Time 63000 - 77000 £ / year (est.) No working from home possible
ENGINEERINGUK

At a Glance

  • Tasks: Lead advanced penetration testing and enhance application security across modern systems.
  • Company: Join Allwyn UK, a transformative force in the National Lottery sector.
  • Benefits: Enjoy competitive pay, generous leave, wellness support, and flexible benefits.
  • Other info: Be part of a diverse team dedicated to social value and inclusion.
  • Why this job: Make a real impact on security while contributing to good causes.
  • Qualifications: Strong experience in application penetration testing and cloud security.

The predicted salary is between 63000 - 77000 £ per year.

You will need to login before you can apply for a job.

View more categories View less categories Sector Construction and Building Services Contract Type Permanent Hours Full Time

At the heart of everything we do is our vision to change lives every day, and our mission to grow The National Lottery responsibly and champion its impact.

We are Allwyn UK, part of the Allwyn Entertainment Group - a multi-national lottery operator with a market-leading presence across the USA (Michigan and Illinois) and Europe, including Czech Republic, Austria, Greece, Cyprus and Italy.

While the main contribution of The National Lottery to society is through the funds to good causes, at Allwyn we put our purpose and values at the heart of everything we do.

Join us as we embark on a once-in-a-lifetime, largescale transformation journey by creating a National Lottery that delivers more money to good causes.

We'll talk a bit more about us further down the page, but for now - let's talk about the role and who we're looking for...

A bit about the role

This role strengthens the Security Testing function by adding senior hands on capability across application security testing and targeted offensive security work.

The main purpose of the role is to improve the depth, consistency and practical value of security testing across Allwyn systems and services, while building enough internal offensive capability to support purple team activity, adversary led testing and better detection and response outcomes.

The role is weighted towards application security.

Around 70 percent of the time will be spent on testing and assuring modern applications, APIs, backend services and cloud hosted workloads.

Around 30 percent will be spent on offensive security activity that supports purple team development, adversary informed assessments and selected deeper technical work such as binary analysis, operating system exploitation and ATT&CK aligned testing.

  • What you'll be doing
  • Application security testing and assurance, around 70 percent
  • Lead and deliver advanced penetration testing across web applications, RESTful APIs, backend services, mobile connected services and supporting application platforms.
  • Assess Java based backend systems, especially Spring Boot services, microservice architectures, API gateways and Backend for Frontend layers.
  • Test authentication, authorisation, orchestration, input validation, session handling, token management and data exposure risks across modern digital journeys.
  • Carry out security testing across cloud hosted and containerised application environments, ideally on AWS, where platform or configuration weaknesses affect application risk.
  • Review outputs from SAST, DAST and related controls, separate noise from genuine risk, and help development teams understand what matters and what should be fixed first.
  • Support threat modelling and design review activity by translating design and architecture decisions into sensible testing scope and coverage.
  • Support release and project assurance by providing clear views on testing depth, remediation expectations and risk based sign off inputs.
  • Help develop practical application security testing standards, playbooks and ways of working that can be applied across BAU and project delivery.
  • Offensive security and purple team development, around 30 percent
  • Develop and mature an internal purple team methodology that can be used alongside security testing activity and external red team exercises.
  • Support offensive security planning with Security Testing leadership and Cyber Defence so that simulations and adversary led assessments are tied to the maturity of defensive controls and operational priorities.
  • Use strong Linux and Windows knowledge to identify realistic exploitation paths across hosts, applications and supporting services.
  • Bring practical knowledge of binary exploitation and lower level technical analysis where it adds value to application, platform or software component assessments.
  • Apply ATT&CK aligned thinking when shaping offensive scenarios, attack paths and purple team test cases.
  • Use knowledge of exploit chaining, post exploitation tradecraft, EDR and AV evasion concepts, and other offensive security techniques where they improve the realism and value of testing.
  • Draft for internal review
  • Contribute to selected specialist work, including hardware focused testing or low level technical analysis, where there is a clear business need and the activity supports the wider security testing plan.
  • Work with external offensive security partners and turn outputs into practical lessons, follow up actions and measurable improvements.
  • Team contribution and capability building
  • Act as a senior technical point of reference within the Security Testing function.
  • Coach others in the team and help raise the standard of testing, reporting and technical analysis.
  • Improve internal methods, test approaches and reporting so that the function becomes more consistent and easier to scale
  • What experience we're looking for

Essential

  • Strong hands on experience in application penetration testing across web applications, APIs and service based architectures.
  • Strong understanding of Java based backend systems, especially Spring Boot, RESTful APIs and microservice patterns.
  • Experience testing API gateways and Backend for Frontend layers, including authentication, authorisation, orchestration and data validation.
  • Practical knowledge of cloud hosted applications, ideally on AWS, including containerised services and common platform security controls.
  • Good understanding of modern web and mobile application patterns, enough to assess API consumption, session handling, trust boundaries and data exposure risk.
  • Strong practical knowledge of Linux and Windows operating systems, including privilege escalation paths, host weaknesses, credential handling risks and exploitation approaches relevant to application environments.
  • Working knowledge of binary exploitation and lower level vulnerability analysis where relevant to application, runtime or platform risk.
  • Ability to carry out manual testing beyond automated tooling, including business logic weakness, exploit chaining and cross layer issues.
  • Ability to explain findings clearly to both technical and non technical stakeholders and provide practical remediation advice.
  • Experience shaping testing approach, methodology or standards rather than only delivering assessments.

Desirable

  • Experience with mobile application assessment.
  • Experience with secure code review or code assisted testing.
  • Experience with ATT&CK informed assessments, adversary emulation support or purple team exercises.
  • Familiarity with EDR and AV evasion concepts, exploit development, vulnerability research or offensive tooling beyond standard application testing.
  • Exposure to hardware, embedded or other specialist low level testing techniques.
  • Experience in regulated, high availability or transaction critical environments.
  • Relevant certifications such as CREST, OSCP, OSWE, OSEP or equivalent demonstrable experience.
  • Experience with WAF technology and implementation

About us

At Allwyn, we are dedicated to changing lives and growing the National Lottery responsibly, championing its positive impact on people, places, and the planet.

• Innovation - We pride ourselves on it!

We're constantly looking for new ways to excite our customers, bringing new products to market to enjoy which is all supported by our responsible play values and making them accessible to all.

  • Giving back - Did you know that playing the lottery generates around £30m a week for charities and good causes in the UK?

Our aim is to have doubled this number by the end of the first 10-year license.

  • Sustainability - Our aim is to become a net zero national lottery.

We have 2030 targets to decarbonise our operations and energy.

We've already transitioned to renewable energy providers, made our London and Watford offices zero gas, and ensured our fleet consists of low-emission vehicles.

In addition, we're working with our value chain partners to develop a net zero target date.

  • Empowering every voice - We believe in creating a culture where everyone feels they belong, can be themselves, has access to opportunities and can thrive for the benefit of good causes.

Our diverse teams are working hard to make all parts of The National Lottery inclusive - whether people play a game in a store or online, because when everyone can play, everyone wins..

An inclusive reward offering with wellbeing at the centre

At Allwyn, inclusion is built into how we care for our people.

Our benefits and policies support colleagues and their families at every stage of life and career.

By prioritising wellbeing and belonging, we create a workplace where everyone feels valued, rewarded, and empowered to succeed.

Our people are more than colleagues - they're winners, driving positive change and making a real difference in communities.

  • Company Bonus Scheme
  • Matched pension contributions up to 8.5%
  • 26 days annual leave + 2 Life Days (and bank holidays)
  • Single Private Health Cover
  • Complimentary Private Medical
  • Income Protection
  • Flexible Benefits - EV Scheme, Money Coach, Will Writing, Mortgage Advice, Dental and Eye Care Schemes.
  • Enhanced Family Leave (Maternity, Paternity, Adoption)
  • Wellness Allowance £500
  • Employee Assistance Programme
  • Discounted Health Assessments
  • Volunteering Days
  • Matched Funding

We are a Disability Confident Leader which means we've taken proactive steps to ensure our workplace is accessible and inclusive for disabled and neurodivergent colleagues and candidates.

As part of this we offer an interview to disabled applicants who meet the essential requirements of the job.

Company

Our vision is to grow the National Lottery responsibly, making it , better and safer for all , with more to good causes.

Bigger because we will significantly increase Good Causes contributions by the end of the Fourth Licence through responsible growth of people playing.

Better because we will modernise technology and operations, refresh games and support shops while improving the use of data and digital.

Safer because participant protection underpins everything we do.

What is unique about us?

Our preparations to transform the National Lottery will be a once-in-a-lifetime type of project in the lottery industry, anywhere in the world.

Join our journey to create a new experience for the National Lottery and help us to power change for the greater good.

Our approach

In Allwyn, the National Lottery will have an operator that has social value at its heart.

We will raise more funding for Good Causes, while running our own business in an environmentally and socially responsible way.

That’s why we have committed to an ambitious Social Value framework, which is woven into the way we do business.

We believe that lotteries must serve everyone across society, not just those who play.

So whether as an employee, a supplier, a retailer or any of the stakeholders that we interact with, we will be powering good across the UK.

Our goal is to create one of the UK’s most inclusive organisations – where people can bring the best of themselves, to do their best work, every day, for the benefit of good causes.

We are working to make the National Lottery truly accessible in a safe way, whether as a player, a retailer or an employee.

We are proud to have been a partner with Purple since 2021 to support our work to embed accessibility into everything we do.

Purple has carried out an accessibility audit on our office in Watford, is working with us to have truly inclusive workplace policies, and we have exciting plans to do so much more to make our games, both in-store and online, safely accessible.

Come and help us shape what the future of the National Lottery could look like.

Media Clips

“I became an amputee in 2021 and I struggled to find my place back in the working world until Allwyn welcomed me with open arms.

They have always focused on what I bring to the table and it is apparent that my disability is not what defines me within the company, but my skill.

Allwyn has a noticeable strong focus on accessibility and inclusion, which makes me feel seen and like I have found a permanent home for my career.” Lorna Jeanes, Transition Co-ordinator.

#J-18808-Ljbffr

Principal Penetration Tester (9 Month FTC) in Watford employer: ENGINEERINGUK

ENGINEERINGUK is an exceptional employer that fosters a collaborative work culture, allowing you to thrive as a Hybrid Brand Executive while contributing to a meaningful charity brand. With generous employee benefits such as 28 days of holiday, enhanced parental leave, and a robust pension scheme, you'll find ample opportunities for personal and professional growth in this dynamic environment.

ENGINEERINGUK

Contact Details:

ENGINEERINGUK Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Principal Penetration Tester (9 Month FTC) in Watford

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including ENGINEERINGUK, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through ENGINEERINGUK

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at ENGINEERINGUK. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Principal Penetration Tester (9 Month FTC) in Watford

Application Penetration Testing
Web Application Security
API Security Testing
Java (Spring Boot)
Microservice Architectures
Cloud Security (AWS)
Container Security

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at ENGINEERINGUK insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to ENGINEERINGUK that you’re committed to staying ahead in the game.

How to prepare for a job interview at ENGINEERINGUK

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at ENGINEERINGUK to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at ENGINEERINGUK.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.