Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Application Security Engineer image - Rise Careers
Job details

Senior Application Security Engineer

Allwyn Lottery Solutions is a subsidiary of Allwyn Entertainment Group – a leading multi-national lottery operator with a market-leading presence in Austria, the Czech Republic, Greece, Cyprus, and Italy. We, in Allwyn LS, build better lotteries that return more to good causes by focusing on innovation, technology, efficiency, and safety across a growing casual gaming entertainment portfolio.

Our purpose is to make play better for all and our mission is to be a trusted and proactive guardian of all that is good in lotteries and casual gaming entertainment.  We believe in changing lives…a little or a lot…but always for the better. 

Allwyn Lottery Solutions is the global leader in designing and delivering captivating digital gaming solutions for lotteries worldwide. With our extensive industry experience, vast knowledge base, and diverse talent, we empower lotteries to create winners and support communities. Our collective expertise enables our clients to reach new players, expand brand engagement, and achieve long-term growth through sustainable and impactful technical solutions. Our differentiating factor lies in our ability to seamlessly engineer technical solutions that align with our client's visions.  Our vision is to be a leading global lottery-led entertainment platform by making gaming better for all, starting from the foundations and enabling our team to blaze new trails and serve as the ground for empowering our clients to achieve sustainable, long-term growth.        

What makes this role exciting and challenging:

The role of Application Security is part of Information Security and plays a crucial role, as the security engineer creates and executes cybersecurity solutions to protect an organisation’s digital information.

As part of your everyday responsibilities, you will:

  • Triage vulnerabilities and review security reports coming from application security tools and pentests.
  • Lead triaging sessions to determine the impact and risk associated with identified vulnerabilities, develop and supervise remediation actions. 
  • Consult with the different teams to build security into their platforms and projects as an SME.
  • Collaborate with development teams to incorporate security into the software development lifecycle through the implementation of secure coding practices and timely addressing of application security vulnerabilities by prioritising them.
  • Conduct/help with security reviews of code to improve the overall security of our applications.
  • Contribute in the implementation and automation of new application security products.
  • Support, develop and continually improve security automation and orchestration capabilities.
  • Create, update and maintain security documentation, tools and integrations that automate or advance team's security objectives.
  • Act as an evangelist by promoting security awareness, and staying up-to-date on current development methodologies.
  • Supporting and enhancing vulnerability management strategy to identify, assess and prioritise software vulnerabilities across the organisation.
  • Update and maintain an accurate inventory of all applications, pipelines, integrations, and other application security assets.
  • Computer Science Degree or equivalent (BSc or higher) 
  • 2+ years in enterprise software development or engineering with 2 years of experience in an application security-focused role is required
  • In-depth knowledge of web application security and secure coding practices. Basic knowledge of  network security, cloud security and cryptography
  • Experience with at least one JVM language (e.g. Java) and one more programming language (e.g. JavaScript, nodeJS, Python) as well as related frameworks such as Spring or J2EE
  • Experience in mobile application development or security.
  • Understanding of web, mobile and cloud applications and architectures, relational and non-relational databases, and containerization
  • Experience with at least one DAST, SAST and SCA security scanning tools configuration or automation
  • Experience with security reports reviews produced by security scanning tools.
  • Knowledge of application security frameworks such as OWASP, ASVS
  • Knowledge of Unix based OS or/and scripting (e.g. Bash, Shell)
  • Excellent communication skills in English (written and verbal)
  • Ability to lead online meetings
  • Organise and prioritise work effectively, able to adjust in a changing environment
  • A desire to learn new skills and develop your existing skillset
  • Ability to give and receive constructive feedback in a positive/professional manner
  • Enjoy working collaboratively
  • Positive attitude and a good sense of humour
  • Mentoring and coaching of junior members of the team

It would be highly advantageous if you had:

  • Experience with any of Checkmarx products or GitHub automation
  • Experience leading triaging calls and process
  • Good experience with DAST or API scanning tooling and automation
  • Any threat modelling skills

(In case we have “nice to have” requirements)

  • Some knowledge of AWS would be a plus, but is not required
  • Familiarity with Jira, Confluence and Assets

Unlock the Benefits-Discover What's in for you:

  • Be part of  a dynamic team with  enthusiastic experts that will support your talent and growth
  • Embark on a journey within a diverse environment full of opportunities and challenges
  • Comprehensive onboarding experience designed to facilitate your smooth transition
  • Attractive salary and a bonus plan
  • Health and life insurance for you and your family
  • Well-being allowance
  • Monthly lunch allowance
  • Developmental 360° feedback framework
  • Unlimited Training options and tools
  • Extensive leave plan
  • Employee Assistance Program with specialized Counselors / Licensed Psychologists
  • Enjoyable and stable working environment
  • Flexible working arrangements (fully remote/hybrid)
  • Modern workspace environment
  • Apple equipment and top-notch office technology to support our hybrid working 

Allwyn is an Equal Opportunity Employer which prides itself in being diverse and inclusive. We do not tolerate discrimination, harassment, or victimisation in the workplace. All employment decisions at Allwyn are based on the business needs, the job requirements, and the individual qualifications. Allwyn encourages applications from individuals regardless of age, disability (visible or hidden), sex, gender reassignment, sexual orientation, pregnancy and maternity, race, religion or belief and marriage and civil partnerships.

Privacy Disclaimer

By clicking "Apply" for this Job, you agree that you have read and accepted our Privacy Statement relating to job applicants and that you provide your consent for the processing of your personal data for the purposes described therein.

Average salary estimate

$115000 / YEARLY (est.)
min
max
$100000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Application Security Engineer, Allwyn Lottery Solutions

At Allwyn Lottery Solutions, we’re on the lookout for a dynamic Senior Application Security Engineer to join our innovative team. If you have a passion for cybersecurity and want to make a significant impact on our digital landscape, this is your chance! In this exciting role, you’ll be the first line of defense against potential vulnerabilities, helping to protect our digital information and creating a safer environment for our users. You will collaborate with different teams, guiding them on security best practices throughout the software development lifecycle. From triaging vulnerabilities to conducting code reviews, you'll be ensuring that security is embedded in everything we do. You’ll also have the opportunity to contribute to the development of new security automation tools and frameworks, further enhancing our ability to respond to threats efficiently. As a Senior Application Security Engineer at Allwyn, your insights will be invaluable in fostering a culture of security awareness and driving initiatives that protect our organization’s integrity. Plus, you’ll enjoy a flexible working environment, comprehensive benefits, and a culture that values growth and continuous learning. So if you’re ready to take your career to the next level and help us make play better for all, we want to hear from you!

Frequently Asked Questions (FAQs) for Senior Application Security Engineer Role at Allwyn Lottery Solutions
What are the responsibilities of the Senior Application Security Engineer at Allwyn Lottery Solutions?

The Senior Application Security Engineer at Allwyn Lottery Solutions plays a crucial role in safeguarding our digital information and ensuring robust security measures are integrated into our platforms. Responsibilities include triaging vulnerabilities, conducting security reviews of code, collaborating with development teams to incorporate security best practices during the software development lifecycle, and automating security processes. The engineer will also support and enhance our vulnerability management strategies to identify and prioritize software vulnerabilities, ensuring that our applications maintain high security standards.

Join Rise to see the full answer
What qualifications are needed for the Senior Application Security Engineer position at Allwyn Lottery Solutions?

Candidates for the Senior Application Security Engineer position at Allwyn Lottery Solutions should possess a Computer Science Degree or equivalent, along with at least 2 years of experience in enterprise software development and an application security-focused role. The ideal applicant should have in-depth knowledge of web application security, secure coding practices, and familiarity with programming languages such as Java, JavaScript, or Python. Additionally, experience with security scanning tools and frameworks like OWASP and ASVS is highly beneficial.

Join Rise to see the full answer
How does Allwyn Lottery Solutions support the professional growth of its Senior Application Security Engineers?

Allwyn Lottery Solutions is committed to the professional growth of its Senior Application Security Engineers by providing unlimited training options and tools, comprehensive onboarding, and a 360° feedback framework that fosters continuous development. The collaborative and diverse environment ensures that employees have ample opportunities to learn from enthusiastic experts while pursuing their career goals and honing their skills in application security.

Join Rise to see the full answer
What tools and technologies should a Senior Application Security Engineer be familiar with at Allwyn Lottery Solutions?

At Allwyn Lottery Solutions, a Senior Application Security Engineer should be familiar with various tools and technologies, including DAST, SAST, and SCA security scanning tools. Knowledge of automation tools, application security frameworks like OWASP ASVS, and expertise in programming languages such as Java and Python are vital. Additionally, familiarity with Unix-based operating systems and experience with security reports generated by scanning tools are highly advantageous.

Join Rise to see the full answer
What work environment can a Senior Application Security Engineer expect at Allwyn Lottery Solutions?

As a Senior Application Security Engineer at Allwyn Lottery Solutions, you can expect a dynamic and flexible work environment that supports both remote and hybrid arrangements. The company fosters a stable working atmosphere equipped with modern office technologies, along with a culture that values collaboration, creativity, and innovation. Employees are encouraged to contribute their insights and participate actively in company initiatives while enjoying a wide range of benefits.

Join Rise to see the full answer
Common Interview Questions for Senior Application Security Engineer
Can you describe your experience with application security tools?

When discussing your experience with application security tools, focus on specific tools you've worked with, such as DAST or SAST. Explain how you've configured, utilized, or automated these tools to identify vulnerabilities, and provide examples of how your findings led to actionable security enhancements within applications.

Join Rise to see the full answer
How do you ensure security is integrated throughout the software development lifecycle?

To demonstrate your approach to integrating security into the software development lifecycle, outline your strategies for involving security practices early in the design phase, and how you collaborate with development teams. Mention specific methodologies like DevSecOps and secure coding practices that you advocate to ensure security is a fundamental aspect of development.

Join Rise to see the full answer
What steps do you take to triage vulnerabilities?

When explaining your steps to triage vulnerabilities, highlight your process of assessing the severity and impact of vulnerabilities based on their context. Discuss how you collaborate with various teams to communicate risks and develop remediation plans, ensuring that the vulnerabilities are addressed appropriately based on their urgency.

Join Rise to see the full answer
Can you provide an example of a security challenge you faced and how you resolved it?

In your answer, provide a specific situation where you identified a significant security challenge, detailing the methodologies you used for assessment and remediation. Emphasize both technical skills and teamwork involved in successfully overcoming the challenge, and share the outcome which strengthened the overall security posture.

Join Rise to see the full answer
How do you stay updated on the latest security trends and threats?

To convey your commitment to staying updated on security trends, discuss various methods you engage in, such as attending security conferences, participating in webinars, and following reputable cyber security blogs or forums. Mention specific resources or communities you are part of to demonstrate your proactive approach to continuous learning.

Join Rise to see the full answer
What experience do you have with secure coding practices?

Discuss your hands-on experience with secure coding practices, describing the languages and frameworks you've applied these practices to. Highlight specific examples where you helped colleagues adapt these practices, and the positive impacts this had on reducing vulnerabilities in applications.

Join Rise to see the full answer
Have you mentored junior team members? If so, how?

If you have mentored junior team members, share your experiences by describing your approach to mentoring, whether through direct training, pairing for code reviews, or facilitating discussions around security topics. Highlight the positive changes in their skillsets or the security culture within the team as a result of your mentorship.

Join Rise to see the full answer
What is your experience with security documentation?

When discussing your experience with security documentation, explain the types of documentation you've created, such as security policies, incident response plans, or vulnerability reports. Stress the importance of keeping these documents current and accessible to foster a good security culture within the organization.

Join Rise to see the full answer
How do you handle constructive feedback within a team?

Describe your approach to receiving and incorporating constructive feedback, emphasizing your openness to different perspectives and learning from critiques. Provide an example of a time feedback helped improve your work or team dynamics, showing how this leads to overall project success.

Join Rise to see the full answer
Why do you want to work as a Senior Application Security Engineer at Allwyn Lottery Solutions?

When answering why you want to join Allwyn Lottery Solutions, align your response with the company's mission and values. Express your enthusiasm for being part of a team that focuses on innovation and contributing to secure digital gaming solutions. Mention specific aspects of the company's culture and opportunities that resonate with you.

Join Rise to see the full answer

We are a private investment group that actively seeks projects with hidden investment potential. Our approach allows us to go where others are afraid to take the risk. We regard all investments in a broad context, with a clear and long-term vision...

13 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
January 8, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!