Company: Allwyn UK
Location:
Posted: May 2nd, 2026
At the heart of everything we do is our vision to change lives every day, and our mission to grow The National Lottery responsibly and champion its impact.
We are Allwyn UK, part of the Allwyn Entertainment Group – a multi‑national lottery operator with a market‑leading presence across the USA (Michigan and Illinois) and Europe, including Czech Republic, Austria, Greece, Cyprus and Italy.
While the main contribution of The National Lottery to society is through the funds to good causes, at Allwyn we put our purpose and values at the heart of everything we do. Join us as we embark on a once‑in‑a‑lifetime, large‑scale transformation journey by creating a National Lottery that delivers more money to good causes.
This role will be key to our approach to Cyber Defence at Allwyn, managing the toolsets, processes and capabilities required to effectively deliver a world class security operations centre. Responsibilities will include managing security engineering toolset.
The role will be focused on developing and maintaining the technology and capabilities we have deployed.
You will be joining an exciting and growing area and will be instrumental in supporting and advancing the operational security capabilities of the Cyber Security Team. There will be opportunity to work on and establish new Security Projects, as well as provide an advisory role to other elements of the business on best practice.
The role will require establishing relationships with key stakeholders in Risk, Technology and Operations, as well as establishing yourself as a SME for cyber security within the organisation.
Run advanced and predictive analyses and perform assessments based on the Mitre ATT&CK framework. Will also be required to do validation, and enhancement activities, using predictive analytics software tools and functionalities as well as the correlating testing activities to ensure quality of the use cases. Correlation monitoring using multiple SIEM technologies will be required to ensure that the SOC achieves its objective of being a threat led organisation. Will be required to gather forensic data and physical equipment to perform forensic investigation when necessary. You will be required to act as incident responder for potential incidents identified and where necessary lead the incident responder.
Works independently and provides guidance and training to others on analysing data trends for use in security use cases to guide the development of the Security toolset. Improve data and analytics systems and platforms, contribute and continuously improve and refine the data and analytics security strategy. Conduct security assessments regularly to identify vulnerabilities and performing risk analysis. Analyse breaches to reach the root cause. Generate reports for IT administrators, business managers, and security leaders. These reports serve as an input to evaluate the efficacy of the security controls. Perform forensic analysis and gather evidence for correlation monitoring using multiple SIEM technologies.
Create artificial intelligence algorithms that identify potential patterns or indicators of compromise in security logs, to be used in the defense of the environment. Ensure the proactive development of all new machine learning activities are in alignment to identified threats by using your extensive knowledge of the threat landscape.
Have expert knowledge of both AWS and Azure security controls and be able to design, implement and maintain all security controls required by the business including knowledge of but not limited to (Azure – AIP; Defender; Azure AD; key vaults; log shipping etc. AWS – Guard duty; security hub; trusted advisor; config; cloudtrail; cloudwatch; inspector etc.)
Be the subject matter expert on all Azure security tooling.
Implementation and design of required security measures such as firewalls or message encryption.
Uses comprehensive knowledge and skills to work independently while providing guidance and training to others on planning, organising, prioritising, and managing activities to efficiently meet business objectives. Lead on updating Protective Monitoring/SOC documentation, processes and procedures and ensure consistency.
At Allwyn, we are dedicated to changing lives and growing the National Lottery responsibly, championing its positive impact on people, places, and the planet.
We are a Disability Confident Leader which means we’ve taken proactive steps to ensure our workplace is accessible and inclusive for disabled and neurodivergent colleagues and candidates. As part of this we offer an interview to disabled applicants who meet the essential requirements of the job.
If you need any assistance or adjustments to this job description or in the application process, please contact a member of the talent team at careers@allwyn.co.uk and we’ll be happy to help.
#J-18808-Ljbffr