At the heart of everything we do is our vision to change lives every day, and our mission to grow The National Lottery responsibly and champion its impact. We are Allwyn UK, part of the Allwyn Entertainment Group - a multi-national lottery operator with a market-leading presence across the USA (Michigan and Illinois) and Europe, including Czech Republic, Austria, Greece, Cyprus and Italy. While the main contribution of The National Lottery to society is through the funds to good causes, at Allwyn we put our purpose and values at the heart of everything we do. Join us as we embark on a once-in-a-lifetime, large-scale transformation journey by creating a National Lottery that delivers more money to good causes. We'll talk a bit more about us further down the page, but for now - let's talk about the role and who we're looking for.
About the Role
Working within Allwyn's Enterprise Security team, you will support the design and delivery of secure solutions across a range of business and technology initiatives. This role is ideal for individuals at an early stage in their security career (including graduates), providing an opportunity to develop practical experience in security architecture. You will work alongside experienced Security Architects and Enterprise Security Leads to support the production of security designs, threat assessments, and security requirements, whilst developing your knowledge of secure‑by‑design principles. You will primarily contribute to lower‑complexity workstreams and structured security activities, supporting the delivery of security outputs at scale while gaining exposure to enterprise‑level programmes and technologies.
Responsibilities
- Support the delivery of security architecture activities as part of project and delivery teams.
- Assist in ensuring security is considered early in the project lifecycle to enable secure‑by‑design outcomes.
- Support the triage of new initiatives and changes, helping identify appropriate security engagement and levels of effort.
- Assist in conducting security risk assessments and basic threat modelling, applying structured approaches under guidance.
- Contribute to the production of security design artefacts, including security requirements, high‑level and low‑level design inputs, and control mappings aligned to standards and patterns.
- Support the identification and documentation of security risks and potential control gaps.
- Assist in communicating findings to stakeholders in a clear and structured manner.
- Support governance processes by updating and maintaining security documentation based on feedback.
- Assist in the preparation of security testing scope (e.g., functional testing and penetration testing).
- Contribute to repeatable and standardised security activities, including the use of templates, patterns, and frameworks.
- Support early‑stage engagement activities (e.g., Security Impact Assessments, triage discussions).
- Continuously develop personal technical and security knowledge through hands‑on experience and structured learning.
Experience We're Looking For
- Must Have (or working towards)
- A degree in Cyber Security, Computer Science, IT, or a related discipline OR equivalent practical experience.
- Basic understanding of information security principles and how they apply to systems and applications.
- Awareness of common security domains such as Identity & Access Management, Network Security, Application Security, Data Protection, Logging & Monitoring, Vulnerability Management.
- Familiarity with structured problem‑solving and analytical thinking.
- Strong communication skills, with the ability to clearly document and explain ideas.
- Willingness to learn and develop in a fast‑paced, delivery‑focused environment.
- Ability to work collaboratively within a team environment.
- Nice to Have
- Exposure to security concepts such as threat modelling (e.g., STRIDE, DREAD).
- Basic understanding of cloud platforms (e.g., AWS, Azure).
- Awareness of security standards or frameworks (e.g., ISO 27001, NIST, CIS).
- Experience (academic or practical) with software development, infrastructure, or IT systems.
- Exposure to Agile or project delivery environments.
- Familiarity with tools such as Jira or Confluence.
- Relevant certifications (or studying towards), such as CompTIA Security+, AWS/Azure Fundamentals, or other entry‑level security certifications.
What We're Looking For
- A strong interest in building a career in security architecture.
- A proactive and curious mindset.
- Ability to learn quickly and apply knowledge in real‑world scenarios.
- Comfort working across both technical and business‑facing activities.
- A desire to contribute to a collaborative, high‑performing security team.
Development Opportunities
- Exposure to enterprise‑scale programmes and technologies.
- Mentoring from experienced Security Architects and Enterprise Security Leads.
- Hands‑on experience across multiple security domains.
- Opportunities to contribute to strategic secur