
// Open Role at The Mill Adventure
Architect and lead security for a cutting-edge iGaming platform using event-driven, serverless tech. This hands-on role requires deep AWS expertise, offensive security skills, and a commitment to automating security, even leveraging AI.
The Mill Adventure is a scale-up with the ultimate mission of building awesome products that will change the way the iGaming industry operates. We started our journey in 2019 with the vision of building a technology-driven organisation and creating a team consisting of the best of the best specialists in their respective fields.
Today, we provide a complete gaming platform for rapid deployment and success in iGaming. Our team of 100+ technology and iGaming experts is guided by a passion for invention, operational excellence and commitment to improving the inefficient.
We trust and value our team and strive to accommodate the right working conditions for each individual in remote, office-based or mixed models. We see the strength in being different and embracing the cultural diversity existing in our group.
One of our key strengths is our modern, event-driven, serverless technology stack, which allows us to innovate and move fast. We work in a collaborative environment that values both teamwork and autonomy.
**The Role
**
As a Senior Security Engineer, you will be the cornerstone of our product and cloud security posture. You will own security across the code, the cloud, the pipelines, the corporate estate, and the response when an alert comes in.
This is a hands-on role with real architectural ownership. You will design our security controls and then build them — our security team is small, and you will be one of three people, so there is nobody to hand a design to. That cuts both ways: almost nothing stands between a good idea and it being live, and there is nowhere to hide if it doesn't get delivered. If your recent work has been mostly programme management, vendor oversight or reviewing other people's designs, this won't be the right fit.
Much of the work will also happen through other people. Security can't do everything alone, so you will spend real time with developers and architects — reviewing designs, threat modelling, coaching on secure practices — and your impact will be measured as much by what they build securely as by what you build yourself.
The role spans security engineering, IT security, security operations and a degree of offensive security. Breadth matters less as a checklist than as judgement: knowing which risks are real, which findings are noise, what to fix first, and — most importantly — what to automate so it stays fixed without anyone watching it.
You will be doing this in 2026, which means AI sits on both sides of the board. Attackers move faster and cheaper than they did two years ago, and the only realistic way for three people to cover this surface is to build AI into how the team works. You should already be doing this, not planning to.
On how we work: we review each other's work openly, and designs get challenged on their merits. We think that produces better security, and we'd expect you to challenge ours in the same way.
What You'll Do:
Requirements
Nice to have:
Benefits
5+ years hands-on in a technical security engineering role, accountable for fixes, not just ticket raising. Proven ability to design and deliver architectures into production. Judgement across security engineering, IT security, security operations, and offensive security to identify real risks and automate responses. Deep AWS security expertise (IAM, Organizations, SCPs, Security Hub, GuardDuty, WAF) and Cloudflare. Proficiency in Python, Go, Bash (TypeScript a plus) for writing production code. Experience with Infrastructure as Code failure modes. Personal experience running vulnerability and attack surface management, including driving closure with other teams. Solid understanding of SIEM and detection engineering, creating effective, low-noise detections. Hands-on experience with detection and response, including investigating alerts and writing post-incident reviews. Working offensive security knowledge to chain misconfigurations into attack paths. Practical use of AI in security work today, with specific examples of builds/automations, failures, and validation. Current view on AI-driven threats and mitigation strategies. Experience integrating and tuning SDLC security tools (SAST, DAST, SCA) effectively. Ability to work autonomously yet collaboratively without friction. Comfort with open technical debate and challenging designs.