Application Security Engineer
Allwyn UK
| Company | Allwyn UK |
| Category | Engineering |
| Location | Watford |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 18 Jun 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (workable) |
Description
At the heart of everything we do is our vision to change lives every day, and our mission to grow The National Lottery responsibly and champion its impact. We are Allwyn UK, part of the Allwyn Entertainment Group – a multi-national lottery operator with a market-leading presence across the USA (Michigan and Illinois) and Europe, including Czech Republic, Austria, Greece, Cyprus and Italy. While the main contribution of The National Lottery to society is through the funds to good causes, at Allwyn we put our purpose and values at the heart of everything we do. Join us as we embark on a once-in-a-lifetime, largescale transformation journey by creating a National Lottery that delivers more money to good causes. We’ll talk a bit more about us further down the page, but for now – let’s talk about the role and who we’re looking for… A bit about the role The Application Security Engineer is responsible for ensuring the security of software applications through rigorous testing and validation. This role is dedicated to embedding security testing throughout the software development lifecycle (SDLC), identifying vulnerabilities, and supporting development teams in remediating security issues. The focus is on proactive, continuous security assessment of applications, both pre- and post-deployment, to maintain the highest standards of software security. What you’ll be doing Collaborate with development teams to create and maintain application threat models (e.g., STRIDE, DREAD). Identify and document application-specific risks; propose effective countermeasures. Integrate and operate application vulnerability scanning tools (e.g., Sonar Cloud, Snyk, OWASP ZAP, Burp Suite, Tenable WAS) within CI/CD pipelines. Interpret vulnerability reports, prioritise remediation based on risk, and track resolution with development teams. Promote awareness of common application vulnerabilities (e.g., SQL injection, XSS, CSRF) and mitigation strategies (OWASP Top 10, ASVS, MASVS). Support development teams in adopting secure coding standards, including static analysis tools, code reviews, and automated linting. Plan, execute, and manage Static, Dynamic, Mobile, and Interactive Application Security Testing (SAST, DAST, MAST, IAST). Embed security testing into CI/CD pipelines for continuous, automated validation. Simulate real-world attack scenarios to identify weaknesses in application logic and implementation. Develop and maintain scripts, tools, and processes to automate application security testing. Produce clear, actionable security testing reports for technical and non-technical stakeholders. Maintain comprehensive documentation of testing methodologies, findings, and remediation guidance. Work closely with software engineers, QA, and product teams to embed security best practices. Deliver training and awareness sessions on application security testing techniques and secure development. What experience we’re looking for Must have: 3-5+ years of hands-on experience in application security testing Strong knowledge of SAST, DAST, MAST, and IAST tools and methodologies. Familiarity with secure SDLC and Application DevSecOps practices. Experience integrating application security testing into CI/CD pipelines. Good understanding of common application vulnerabilities and mitigation strategies (OWASP Top 10, ASVS, MASVS). Proficiency in at least one programming or scripting language (e.g., Python, JavaScript, C#). Strong analy
986,449 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →