Senior Security Engineer (AppSec & Offensive)

1 day, 8 hours ago
Full-time
Senior
Cybersecurity
The Mill Adventure

The Mill Adventure

The Mill Adventure is a leading provider of a comprehensive gaming platform in the iGaming industry. They offer licenses, operations, and support for quick and successful deployment, allowing partners to focus on engaging their audience. With a commitm...

Hotels, Restaurants & Leisure
11-50
Founded 2019

Description

  • Drive the application security lifecycle, including architecture reviews, threat modeling, and secure design guidance.
  • Perform targeted internal penetration tests and secure code reviews to identify and demonstrate application vulnerabilities.
  • Architect and integrate security tooling (SAST, DAST, SCA, secrets detection) into CI/CD pipelines to automate detection and reduce developer friction.
  • Tune security tooling to ensure high-signal alerts and seamless developer workflows.
  • Triage, validate, and prioritize application-level vulnerabilities based on business context and risk, and guide engineering teams through pragmatic remediation.
  • Support cloud and core IT security efforts by applying AWS security knowledge and foundational IT controls (IAM, endpoint, zero-trust).
  • Act as a senior technical mentor for developers and a highly collaborative peer to the security team, spreading security awareness and best practices.
  • Champion a culture of security ownership and work proactively with product and engineering teams to enable secure paths to production.
  • Measure and continuously improve AppSec and DevSecOps processes to reduce risk and accelerate delivery.

Requirements

  • 7+ years of Security Engineering experience with deep expertise in Application Security, DevSecOps, and Offensive Security.
  • Proven track record of proactive ownership, mentorship, and driving security initiatives across engineering teams.
  • Hands-on offensive and defensive mindset: able to develop exploit proof-of-concepts and translate findings into secure coding guidance.
  • Deep proficiency in at least one modern programming language (specifically JavaScript/TypeScript is highlighted) for code review and automation.
  • Experience architecting and integrating security tooling such as SAST, DAST, SCA, and secrets detection into CI/CD pipelines.
  • Solid general knowledge of Cloud Security (AWS) and foundational corporate IT security principles (IAM, endpoints, zero-trust).
  • Experience with vulnerability management, threat modeling, penetration testing, and secure code review methodologies.
  • Exceptional communication skills with the ability to translate technical vulnerabilities into clear business impact and influence stakeholders.
  • iGaming experience is a strong plus; experience in similarly regulated/complex sectors (fintech, SaaS, payments) is also valuable.
  • Alignment with company values: high integrity, ownership, transparency, and continuous improvement.

Benefits

  • Flexible working environment (remote, office-based, or mixed)
  • Work equipment of your choice
  • Private health insurance
  • Learning budget for professional development
  • Fitness benefit
  • Parking, transport, or co‑working allowance
  • Company-wide and team get-togethers
  • Opportunity to work with and learn from a highly skilled, tight-knit team within a transparent, accountable culture

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Network Security Engineer

e.l.f. Beauty 251-1K Consumer Goods

Network Security Engineer at e.l.f. Beauty responsible for designing, implementing, and maintaining the organization's network security infrastructure to protect systems and ensure data confidentiality, integrity, and availability.

AWS Azure Cisco Juniper Palo Alto
22 minutes ago

Security Architect - Middle East

ChainGPT 11-50 Internet Software & Services

Security Architect at ChainGPT to lead the end-to-end security strategy and implementation for its blockchain-based AI platform, ensuring enterprise-grade security, compliance, and resilience across infrastructure, applications, data, and operations.

AWS Azure Docker Encryption GCP Go Grafana Kubernetes Penetration Testing Prometheus Python Rust Secrets Management
22 minutes ago

DevSecOps Engineer

Odd. 1-10 Consumer Goods

DevSecOps Engineer at Oddball supporting the CMS BDAMAX program to embed and operate security controls across cloud infrastructure, CI/CD pipelines, and AI platforms to maintain compliance and protect Medicare-related systems.

Agile AWS CI/CD Docker Jenkins Kubernetes PostgreSQL Secrets Management Terraform
1 hour, 7 minutes ago

Senior Security Engineer - Blue Team (Remote)

Insider Internet Software & Services

Senior Security Engineer (Blue Team) at Insider One, working remotely to strengthen and company's platform security by operating detection systems, responding to incidents, and improving defensive controls across the infrastructure.

AWS HTTP Machine Learning Python SIEM Splunk Unix
1 hour, 22 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers