Security Architect - 12 month FTC
Allwyn UK · Warrington, England, United Kingdom · On-site
Posted Sep 28, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
At the heart of everything we do is our vision to change lives every day, and our mission to grow The National Lottery responsibly and champion its impact.
We are Allwyn UK, part of the Allwyn Entertainment Group – a multi-national lottery operator with a market-leading presence across the USA (Michigan and Illinois) and Europe, including Czech Republic, Austria, Greece, Cyprus and Italy.
While the main contribution of The National Lottery to society is through the funds to good causes, at Allwyn we put our purpose and values at the heart of everything we do. Join us as we embark on a once-in-a-lifetime, largescale transformation journey by creating a National Lottery that delivers more money to good causes.
We’ll talk a bit more about us further down the page, but for now – let’s talk about the role and who we’re looking for…
Security Architect - 12 month FTC
About the role
Working within the Enterprise Security team, you will provide specialist security architecture for customer-facing and enterprise applications across web, mobile, API and supporting cloud services. You will shape secure designs from discovery through delivery, translate risk into proportionate security requirements, and help engineering teams embed security throughout the software development lifecycle.
This is an architecture-led role with practical application security depth. You will not simply identify vulnerabilities: you will influence application and platform design, define reusable patterns, guide security testing, support remediation decisions and provide clear risk advice to technical and business stakeholders.
What you’ll be doing
Provide security architecture support to mobile and web application initiatives from discovery and design through build, testing, release and operation.
Partner with solution architects, software engineers, product teams, delivery leads and third parties to ensure security is designed in early without losing sight of pace, cost, usability and quality.
Produce and maintain high-level and detailed security designs, security requirements, architecture decisions, patterns and supporting assurance evidence.
Lead application threat modelling using structured techniques such as STRIDE, documenting threats, attack paths, trust boundaries, mitigations and residual risks.
Assess web applications, native and cross-platform mobile applications, APIs, microservices, identity flows, cloud services and third-party integrations.
Define security requirements for authentication, authorisation, session management, secrets, cryptography, data protection, API security, logging, monitoring, resilience and secure configuration.
Apply recognised application security guidance, including OWASP Top 10, OWASP ASVS, OWASP MASVS and relevant secure-by-design principles.
Guide teams on secure mobile design, including secure storage, platform permissions, transport security, certificate handling, local data…