Security Architect

Allwyn UK

Warrington

On-site

GBP 90,000 - 120,000

Full time

13 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Company Bonus Scheme
Matched pension up to 8.5%
26 days annual leave + 2 Life Days
Single Private Health Cover
Wellness Allowance £500
Volunteer Days

Job summary

Allwyn UK is seeking an experienced security architect to shape secure designs for customer-facing and enterprise applications across web, mobile, API and cloud services. You will influence architecture, define patterns, and guide security testing while embedding security throughout the software development lifecycle.

This architecture-led role requires practical depth in application security, threat modelling, secure SDLC, and collaboration with engineering, product, and external vendors to

Qualifications

  • Significant experience in application security architecture within an enterprise environment.
  • Security design experience across modern web apps, mobile apps and APIs.
  • Strong knowledge of common web, mobile and API threats and controls.
  • Threat modelling with clear, traceable security requirements.
  • Secure SDLC, DevSecOps, Agile delivery and CI/CD security.

Responsibilities

  • Provide security architecture support to mobile and web application initiatives from discovery through operation.
  • Partner with solution architects, software engineers, product teams and third parties to design security in early.
  • Produce and maintain security designs, requirements, decisions, patterns and assurance evidence.
  • Lead threat modelling using STRIDE and document threats, attack paths and mitigations.
  • Assess web, mobile apps, APIs, microservices, identity flows, cloud services and third-party integrations.
  • Define security requirements for authentication, authorization, session management, secrets, cryptography and data protection.
  • Apply OWASP guidance and secure-by-design principles.
  • Guide teams on secure mobile and web design, including storage, permissions, transport security and controls.
  • Advise on security testing strategy: SAST, DAST, SCA, API and penetration testing.
  • Support integration of security controls and automated testing into CI/CD pipelines.
  • Review findings, prioritize remediation and coordinate actions.
  • Produce penetration test scopes and coordinate testing.
  • Identify and communicate security risks and gaps clearly.
  • Contribute to reusable security patterns and reference architectures.
  • Coach teams on secure design and threat modelling.

Skills

App security architecture
Security engineering
Threat modelling
DevSecOps/CI/CD security
Security testing (SAST/DAST/SSCA)
Identity and access management
Cloud-native security
Data protection
Communication and advisory skills

Tools

Burp Suite
OWASP ZAP
Snyk
SonarQube

Job description

At the heart of everything we do is our vision to change lives every day, and our mission to grow The National Lottery responsibly and champion its impact.

We are Allwyn UK, part of the Allwyn Entertainment Group – a multi-national lottery operator with a market-leading presence across the USA (Michigan and Illinois) and Europe, including Czech Republic, Austria, Greece, Cyprus and Italy.

While the main contribution of The National Lottery to society is through the funds to good causes, at Allwyn we put our purpose and values at the heart of everything we do. Join us as we embark on a once-in-a-lifetime, largescale transformation journey by creating a National Lottery that delivers more money to good causes.

We’ll talk a bit more about us further down the page, but for now – let’s talk about the role and who we’re looking for…

About the role

Working within the Enterprise Security team, you will provide specialist security architecture for customer-facing and enterprise applications across web, mobile, API and supporting cloud services. You will shape secure designs from discovery through delivery, translate risk into proportionate security requirements, and help engineering teams embed security throughout the software development lifecycle.

This is an architecture-led role with practical application security depth. You will not simply identify vulnerabilities: you will influence application and platform design, define reusable patterns, guide security testing, support remediation decisions and provide clear risk advice to technical and business stakeholders.

What you’ll be doing
  • Provide security architecture support to mobile and web application initiatives from discovery and design through build, testing, release and operation.

  • Partner with solution architects, software engineers, product teams, delivery leads and third parties to ensure security is designed in early without losing sight of pace, cost, usability and quality.

  • Produce and maintain high-level and detailed security designs, security requirements, architecture decisions, patterns and supporting assurance evidence.

  • Lead application threat modelling using structured techniques such as STRIDE, documenting threats, attack paths, trust boundaries, mitigations and residual risks.

  • Assess web applications, native and cross-platform mobile applications, APIs, microservices, identity flows, cloud services and third-party integrations.

  • Define security requirements for authentication, authorisation, session management, secrets, cryptography, data protection, API security, logging, monitoring, resilience and secure configuration.

  • Apply recognised application security guidance, including OWASP Top 10, OWASP ASVS, OWASP MASVS and relevant secure-by-design principles.

  • Guide teams on secure mobile design, including secure storage, platform permissions, transport security, certificate handling, local data protection, application integrity and mobile backend/API controls.

  • Guide teams on secure web design, including browser security controls, input and output handling, access control, session security, dependency risk and protection against common web attack classes.

  • Advise on application security testing strategy, including SAST, DAST, SCA, secrets scanning, API testing, mobile application testing, IAST and penetration testing.

  • Support the integration of proportionate security controls and automated testing into CI/CD pipelines, including the definition of quality gates and exception routes.

  • Review security findings, challenge false positives where appropriate, prioritise remediation based on risk and support teams in agreeing pragmatic corrective actions.

  • Produce penetration test scopes and security test plans, coordinate internal and external testing, and assess whether findings have been adequately remediated.

  • Identify and communicate security risks, control gaps and non-compliance clearly, supporting accountable owners to reach an informed risk position.

  • Contribute to reusable security patterns, standards, guardrails and reference architectures for mobile, web and API delivery.

  • Coach engineering and architecture communities on secure design, threat modelling and secure development practices.

What experience we’re looking for

Must Have:

  • Significant experience in application security architecture, product security or security engineering within an enterprise environment.

  • Security design experience across modern web applications, mobile applications and APIs.

  • Strong knowledge of common web, mobile and API threats and appropriate security controls.

  • Practical experience of threat modelling and translating findings into clear, traceable security requirements.

  • Good understanding of secure SDLC, DevSecOps, Agile delivery and CI/CD security.

  • Experience defining and interpreting application security testing, including SAST, DAST, SCA, API, mobile and penetration testing.

  • Knowledge of application identity and access management, including authentication, authorisation, federation, tokens and session security.

  • Understanding of cloud-native architecture, including containers, serverless services and microservices.

  • Experience assessing data flows and defining controls for sensitive data.

  • Strong written and verbal communication skills, with the ability to provide clear, pragmatic and risk-based advice

Technical knowledge
  • Web and API security, including HTTP/S, browser controls, CORS, CSP, REST and GraphQL.

  • iOS and Android security, including secure storage, permissions, deep links, transport security and application integrity.

  • Application security tools such as Burp Suite, OWASP ZAP, Snyk, SonarQube or equivalent.

  • Working knowledge of a mainstream programming or scripting language.

  • Security logging, monitoring and incident response for customer-facing applications.

  • Relevant frameworks and standards, including OWASP, NIST, ISO 27001, CIS and PCI DSS.

Nice to Have:
  • Experience securing high-volume digital services in a regulated environment.

  • Knowledge of app-store releases, mobile attestation, application shielding or runtime protection.

  • Familiarity with container security, Kubernetes, infrastructure as code or policy as code.

  • Experience developing application security patterns, standards or developer enablement programmes.

  • A relevant security certification such as CISSP, CSSLP, SABSA, CREST or OSWE.

  • Experience in lottery, gaming, payments, retail, finance or another regulated sector.

About us

At Allwyn, we are dedicated to changing lives and growing the National Lottery responsibly, championing its positive impact on people, places, and the planet.

  • Innovation - We pride ourselves on it! We’re constantly looking for new ways to excite our customers, bringing new products to market to enjoy which is all supported by our responsible play values and making them accessible to all.

  • Giving back – Did you know that playing the lottery generates around £30m a week for charities and good causes in the UK? Our aim is to have doubled this number by the end of the first 10-year license.

  • Sustainability – Our aim is to become a net zero national lottery. We have 2030 targets to decarbonise our operations and energy. We’ve already transitioned to renewable energy providers, made our London and Watford offices zero gas, and ensured our fleet consists of low-emission vehicles. In addition, we’re working with our value chain partners to develop a net zero target date.

  • Empowering every voice – We believe in creating a culture where everyone feels they belong, can be themselves, has access to opportunities and can thrive for the benefit of good causes. Our diverse teams are working hard to make all parts of The National Lottery inclusive – whether people play a game in a store or online, because when everyone can play, everyone wins..

An inclusive reward offering with wellbeing at the centre

At Allwyn, inclusion is built into how we care for our people. Our benefits and policies support colleagues and their families at every stage of life and career. By prioritising wellbeing and belonging, we create a workplace where everyone feels valued, rewarded, and empowered to succeed. Our people are more than colleagues - they’re winners, driving positive change and making a real difference in communities.

Benefits
  • Company Bonus Scheme

  • Matched pension contributions up to 8.5%

  • 26 days annual leave + 2 Life Days (and bank holidays)

  • Single Private Health Cover

  • Complimentary Private Medical

  • Income Protection

  • Flexible Benefits – EV Scheme, Money Coach, Will Writing, Mortgage Advice, Dental and Eye Care Schemes.

  • Enhanced Family Leave (Maternity, Paternity, Adoption)

  • Wellness Allowance £500

  • Employee Assistance Programme

  • Discounted Health Assessments

  • Volunteering Days

  • Matched Funding

We are a Disability Confident Leader which means we’ve taken proactive steps to ensure our workplace is accessible and inclusive for disabled and neurodivergent colleagues and candidates. As part of this we offer an interview to disabled applicants who meet the essential requirements of the job.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DevSecOps Engineer
DevSecOps Engineer

Allwyn UK • Watford

On-site
GBP 65,000 - 90,000
Company Bonus Scheme
Matched pension contributions
26 days annual leave + 2 Life Days
+5
Developer - Python
Developer - Python

Allwyn UK • Watford

On-site
GBP 70,000 - 110,000
Company Bonus Scheme
Matched pension contributions
26 days annual leave + 2 Life Days
+3
Senior Trust Reporting Accountant
Senior Trust Reporting Accountant

Allwyn UK • Watford

On-site
GBP 75,000 - 95,000
Company Bonus Scheme
Matched pension contributions up to 8.
26 days annual leave + 2 Life Days (&
Senior QA Engineer
Senior QA Engineer

Allwyn UK • Watford

On-site
GBP 55,000 - 75,000
Company Bonus Scheme
Matched pension contributions up to 8.
26 days annual leave + 2 Life Days
+2
Data & AI Security Engineer (6 Months FTC)
Data & AI Security Engineer (6 Months FTC)

Allwyn UK • Watford

On-site
GBP 90,000 - 130,000
Company Bonus Scheme
Matched pension contributions up to 8.
26 days annual leave + 2 Life Days
+10
It Systems And Security Operator - 12 Month Ftc
It Systems And Security Operator - 12 Month Ftc

Allwyn Uk • United Kingdom

On-site
GBP 55,000 - 75,000
Company Bonus Scheme
Matched pension contributions up to 8.
26 days annual leave + 2 Life Days
+10
IT Systems and Security Operator
IT Systems and Security Operator

Allwyn UK • Warrington

On-site
GBP 42,000 - 62,000
Company Bonus Scheme
Matched pension contributions up to 8.
26 days annual leave + 2 Life Days (+
+4
Senior Trust Reporting Accountant
Senior Trust Reporting Accountant

Allwyn Uk • Waterford

On-site
GBP 65,000 - 90,000
Company Bonus Scheme
Matched pension contributions
26 days annual leave + 2 Life Days
+3
Portfolio Analytics Manager
Portfolio Analytics Manager

Allwyn UK • Watford

On-site
GBP 65,000 - 90,000
Company Bonus Scheme
Matched pension contributions up to 8.
26 days annual leave + 2 Life Days
+4
Consumer Communications Manager – Brand and Good Causes
Consumer Communications Manager – Brand and Good Causes

Allwyn UK • Greater London

On-site
GBP 55,000 - 75,000
Company Bonus Scheme
Matched Pension contributions
26 days annual leave + 2 Life Days
+4