Skip to content

Open nowPosted 25 days ago

Senior Security Engineer

Workable (global search)108,016 open roles

Where
Barcelona, Catalonia, Spain
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security EngineerWorkable (global search) · Barcelona, Catalonia, Spain
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 25 days ago

Workable (global search) median: 7 days open

The posting

The Mill Adventure is a scale-up with the ultimate mission of building awesome products that will change the way the iGaming industry operates. We started our journey in 2019 with the vision of building a technology-driven organisation and creating a team consisting of the best of the best specialists in their respective fields.

Today, we provide a complete gaming platform for rapid deployment and success in iGaming. Our team of 100+ technology and iGaming experts is guided by a passion for invention, operational excellence and commitment to improving the inefficient.

We trust and value our team and strive to accommodate the right working conditions for each individual in remote, office-based or mixed models. We see the strength in being different and embracing the cultural diversity existing in our group.

One of our key strengths is our modern, event-driven, serverless technology stack, which allows us to innovate and move fast. We work in a collaborative environment that values both teamwork and autonomy.

The Role

As a Senior Security Engineer, you will be the cornerstone of our product and cloud security posture. You will own security across the code, the cloud, the pipelines, the corporate estate, and the response when an alert comes in.

This is a hands-on role with real architectural ownership. You will design our security controls and then build them — our security team is small, and you will be one of three people, so there is nobody to hand a design to. That cuts both ways: almost nothing stands between a good idea and it being live, and there is nowhere to hide if it doesn't get delivered. If your recent work has been mostly programme management, vendor oversight or reviewing other people's designs, this won't be the right fit.

Much of the work will also happen through other people. Security can't do everything alone, so you will spend real time with developers and architects — reviewing designs, threat modelling, coaching on secure practices — and your impact will be measured as much by what they build securely as by what you build yourself.

The role spans security engineering, IT security, security operations and a degree of offensive security. Breadth matters less as a checklist than as judgement: knowing which risks are real, which findings are noise, what to fix first, and — most importantly — what to automate so it stays fixed without anyone watching it.

You will be doing this in 2026, which means AI sits on both sides of the board. Attackers move faster and cheaper than they did two years ago, and the only realistic way for three people to cover this surface is to build AI into how the team works. You should already be doing this, not planning to.

On how we work: we review each other's work openly, and designs get challenged on their merits. We think that produces better security, and we'd expect you to challenge ours in the same way.

What You'll Do:

  • Architect and lead the design and implementation of security controls across our cloud infrastructure, applications and CI/CD pipelines — and build them yourself
  • Coach and mentor developers, engineers and architects on secure design, threat modelling and cloud security, so that security scales beyond the security team and becomes part of how we build
  • Own vulnerability management and our attack surface: know what is exposed, prioritise by real exploitability rather than scanner severity, and drive findings to closure with the teams that own them
  • Own the security of the SDLC by integrating and tuning SAST, DAST and SCA so that developers keep them enabled because the signal is worth the friction
  • Engineer and maintain our cloud security posture, primarily in AWS and Cloudflare — hardening configurations, automating compliance checks, and closing gaps before they are found for you
  • Own detection and response end to end: shape what we log and alert on, tune out the noise, investigate what is real, remediate it, and write up what happened
  • Architect and guide our IAM strategy, working with engineering to deliver least-privilege access for human and machine identities that teams don't route around
  • Test our own systems. Use offensive techniques against our infrastructure, applications and identity flows to validate that controls work and to decide what actually gets fixed first
  • Use AI as a force multiplier for a team that is small relative to its surface — agentic tooling for triage, code review, detection engineering, evidence collection and the automation of toil. You will also be the person who secures AI systems as we adopt them
  • Automate everything. If you would otherwise do it twice, automate it
  • Bring us the uncomfortable assessments — with a plan and a first PR attached

Requirements

  • 5+ years hands-on in a technical security engineering role, including time where you were the person accountable for the fix, not the person who raised the ticket. Expect to be asked what you built, what it prevented, and how you knew it worked
  • You design and you deliver. You can produce an architecture that survives review, and you have a track record of the things you designed actually going live
  • Judgement across security engineering, IT security, security operations and offensive security. We are not looking for equal depth in all four — we are looking for someone who can tell a real risk from a noisy one across all of them, and who automates the response rather than handling it manually each time
  • Deep AWS security: IAM, Organizations and SCPs, Security Hub, GuardDuty, WAF, plus Cloudflare. You can walk through how you would detect and contain a compromised role, not just describe what each service does
  • You write code that runs in production and that other people depend on — Python, Go, Bash, with TypeScript a major plus
  • Infrastructure as Code and its real failure modes: drift, over-permissive modules, secrets in state, pipeline privilege escalation
  • Vulnerability and attack surface management you have personally run — including the harder half, which is getting other teams to close things
  • Solid understanding of SIEM and detection engineering: what to collect, how to turn it into detections that fire on real activity, and how to keep false positives from burying the team
  • Detection and response you have personally done. You have investigated real alerts and written the post-incident review
  • Working offensive knowledge. You need not be a pentester, but you should be able to chain misconfigurations into a real attack path and explain why one finding matters more than fifty from a scanner
  • Practical use of AI in your security work today, not curiosity about it. Tell us what you have built or automated with it, where it failed you, and how you validate what it produces
  • A current, specific view on AI-driven threats — what has actually changed for defenders, and what you would do about it here
  • SDLC security: SAST, DAST and SCA that you have integrated and, more importantly, tuned well enough that developers didn't turn them off
  • The ability to work autonomously without going dark, and to work closely with engineers without friction. Both, not one
  • Comfort with open technical debate. You can have a design challenged in review, make your case, and move forward either way

Nice to have:

  • Hands-on experience with PCI DSS — scoping, control implementation and evidence — as something you have engineered towards, not only been audited against.
  • Experience building and maintaining a SIEM: pipelines, parsing, cost control, detection-as-code.
  • Serverless and event-driven architecture at scale.
  • iGaming, fintech or another regulated, high-value-target industry.
  • Corporate IT security: SSO and identity providers, MDM, SaaS security posture, third-party and vendor access.
  • Experience securing AI or agentic systems.
  • Security frameworks (NIST CSF, CIS Benchmarks, CSA CCM) used as tools to get work done rather than as the work itself.
  • Public artifacts: tools you have released, writeups, CVEs, CTF results, talks.
  • Certifications such as CISSP, AWS Certified Security or CEH are welcome, though demonstrated work weighs considerably more in our process

Benefits

  • A lean, focused company, offering a flexible working environment
  • The opportunity to work with and learn form a highly skilled, talented team
  • A great company culture, where accountability is innate, transparency is key and competency is virtue
  • Being part of a tight knit, caring community
  • Work equipment of your choice
  • Private health insurance
  • Learning budget
  • Company wide and team based get togethers
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.