The Mill Adventure is a scale-up with the ultimate mission of building awesome products that will change the way the iGaming industry operates. We started our journey in 2019 with the vision of building a technology-driven organisation and creating a team consisting of the best of the best specialists in their respective fields.
Today, we provide a complete gaming platform for rapid deployment and success in iGaming. Our team of 100+ technology and iGaming experts is guided by a passion for invention, operational excellence and commitment to improving the inefficient.
We trust and value our team and strive to accommodate the right working conditions for each individual in remote, office-based or mixed models. We see the strength in being different and embracing the cultural diversity existing in our group.
One of our key strengths is our modern, event-driven, serverless technology stack, which allows us to innovate and move fast. We work in a collaborative environment that values both teamwork and autonomy.
As a Senior Security Engineer, you will be the cornerstone of our product and cloud security posture. You will own security across the code, the cloud, the pipelines, the corporate estate, and the response when an alert comes in.
This is a hands-on role with real architectural ownership. You will design our security controls and then build them — our security team is small, and you will be one of three people, so there is nobody to hand a design to. That cuts both ways: almost nothing stands between a good idea and it being live, and there is nowhere to hide if it doesn't get delivered. If your recent work has been mostly programme management, vendor oversight or reviewing other people's designs, this won't be the right fit.
Much of the work will also happen through other people. Security can't do everything alone, so you will spend real time with developers and architects — reviewing designs, threat modelling, coaching on secure practices — and your impact will be measured as much by what they build securely as by what you build yourself.
The role spans security engineering, IT security, security operations and a degree of offensive security. Breadth matters less as a checklist than as judgement: knowing which risks are real, which findings are noise, what to fix first, and — most importantly — what to automate so it stays fixed without anyone watching it.
You will be doing this in 2026, which means AI sits on both sides of the board. Attackers move faster and cheaper than they did two years ago, and the only realistic way for three people to cover this surface is to build AI into how the team works. You should already be doing this, not planning to.
On how we work: we review each other's work openly, and designs get challenged on their merits. We think that produces better security, and we'd expect you to challenge ours in the same way.
Tasks
- Architect and lead the design and implementation of security controls across our cloud infrastructure, applications and CI/CD pipelines — and build them yourself
- Coach and mentor developers, engineers and architects on secure design, threat modelling and cloud security, so that security scales beyond the security team and becomes part of how we build
- Own vulnerability management and our attack surface: know what is exposed, prioritise by real exploitability rather than scanner severity, and drive findings to closure with the teams that own them
- Own the security of the SDLC by integrating and tuning SAST, DAST and SCA so that developers keep them enabled because the signal is worth the friction
- Engineer and maintain our cloud security posture, primarily in AWS and Cloudflare — hardening configurations, automating compliance checks, and closing gaps before they are found for you
- Own detection and response end to end: shape what we log and alert on, tune out the noise, investigate what is real, remediate it, and write up what happened
- Architect and guide our IAM strategy, working with engineering to deliver least-privilege access for human and machine identities that teams don't route around
- Test our own systems. Use offensive techniques against our infrastructure, applications and identity flows to validate that controls work and to decide what actually gets fixed first
- Use AI as a force multiplier for a team that is small relative to its surface — agentic tooling for triage, code review, detection engineering, evidence collection and the automation of toil. You will also be the person who secures AI systems as we adopt them
- Automate everything. If you would otherwise do it twice, automate it
- Bring us the uncomfortable assessments — with a plan and a first PR attached
Requirements
- 5+ years hands-on in a technical security engineering role, including time where you were the person accountable for the fix, not the person who raised the ticket. Expect to be asked what you built, what it prevented, and how you knew it worked
- You design and you deliver. You can produce an architecture that survives review, and you have a track record of the things you designed actually going live
- Judgement across security engineering, IT security, security operations and offensive security. We are not looking for equal depth in all four — we are looking for someone who can tell a real risk from a noisy one across all of them, and who automates the response rather than handling it manually each time
- Deep AWS security: IAM, Organizations and SCPs, Security Hub, GuardDuty, WAF, plus Cloudflare. You can walk through how you would detect and contain a compromised role, not just describe what each service does
- You write code that runs in production and that other people depend on — Python, Go, Bash, with TypeScript a major plus
- Infrastructure as Code and its real failure modes: drift, over-permissive modules, secrets in state, pipeline privilege escalation
- Vulnerability and attack surface management you have personally run — including the harder half, which is getting other teams to close things
- Solid understanding of SIEM and detection engineering: what to collect, how to turn it into detections that fire on real activity, and how to keep false positives from burying the team
- Detection and response you have personally done. You have investigated real alerts and written the post-incident review
- Working offensive knowledge. You need not be a pentester, but you should be able to chain misconfigurations into a real attack path and explain why one finding matters more than fifty from a scanner
- Practical use of AI in your security work today, not curiosity about it. Tell us what you have built or automated with it, where it failed you, and how you validate what it produces
- A current, specific view on AI-driven threats — what has actually changed for defenders, and what you would do about it here
- SDLC security: SAST, DAST and SCA that you have integrated and, more importantly, tuned well enough that developers didn't turn them off
- The ability to work autonomously without going dark, and to work closely with engineers without friction. Both, not one
- Comfort with open technical debate. You can have a design challenged in review, make your case, and move forward either way
Nice to have:
- Hands-on experience with PCI DSS — scoping, control implementation and evidence — as something you have engineered towards, not only been audited against.
- Experience building and maintaining a SIEM: pipelines, parsing, cost control, detection-as-code.
- Serverless and event-driven architecture at scale.
- iGaming, fintech or another regulated, high-value-target industry.
- Corporate IT security: SSO and identity providers, MDM, SaaS security posture, third-party and vendor access.
- Experience securing AI or agentic systems.
- Security frameworks (NIST CSF, CIS Benchmarks, CSA CCM) used as tools to get work done rather than as the work itself.
- Public artifacts: tools you have released, writeups, CVEs, CTF results, talks.
- Certifications such as CISSP, AWS Certified Security or CEH are welcome, though demonstrated work weighs considerably more in our process
Benefits
- A lean, focused company, offering a flexible working environment
- The opportunity to work with and learn form a highly skilled, talented team
- A great company culture, where accountability is innate, transparency is key and competency is virtue
- Being part of a tight knit, caring community
- Work equipment of your choice
- Private health insurance
- Learning budget
- Company wide and team based get togethers