FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Security Engineer
The Mill Adventure. Architect and lead the design and implementation of security controls across cloud infrastructure, applications and CI/CD pipelines .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in architecting and implementing security controls across cloud infrastructure, with a strong focus on AWS and Cloudflare. Proficient in vulnerability management, incident response, and integrating security practices within the SDLC.
Highest-signal resume keywords
Cloud Security ArchitectureVulnerability ManagementAWS Security ExperienceSAST, DAST, and SCA IntegrationOffensive Security Knowledge
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security Controls ImplementationPython ProgrammingGo ProgrammingBash ScriptingInfrastructure as CodeSIEM KnowledgeDetection EngineeringIncident ResponseThreat ModellingAI in Security
Soft Skills
Coaching and MentoringAutonomous WorkTechnical Debate
Tools & Technologies
AWSCloudflareSecurity HubGuardDutyWAFSASTDASTSCASIEMAI Tools
Certifications & Qualifications
CISSPAWS Certified SecurityCEH
Industry Keywords
PCI DSSRegulated IndustriesCorporate IT SecuritySecurity FrameworksEvent-Driven Architecture
Tech Stack
Tools & technologiesAWSCloudPythonSDLCTypeScriptGo
About the role
Key responsibilities & impact- Architect and lead the design and implementation of security controls across cloud infrastructure, applications and CI/CD pipelines
- Build security controls directly
- Coach and mentor developers, engineers and architects on secure design, threat modelling and cloud security
- Own vulnerability management and attack surface management, prioritizing by exploitability and driving findings to closure
- Own SDLC security by integrating and tuning SAST, DAST and SCA
- Engineer and maintain cloud security posture in AWS and Cloudflare
- Harden configurations, automate compliance checks and close security gaps
- Own detection and response end to end, including logging, alerting, investigation, remediation and post-incident documentation
- Architect and guide IAM strategy for least-privilege human and machine identities
- Test company systems using offensive techniques against infrastructure, applications and identity flows
- Use AI for triage, code review, detection engineering, evidence collection and toil automation
- Secure AI systems as the company adopts them
- Automate repetitive work
- Provide candid security assessments with an actionable plan and initial pull request
Requirements
What you’ll need- 5+ years hands-on in a technical security engineering role, including accountability for implementing fixes
- Track record of designing and delivering security architecture and controls into production
- Judgement across security engineering, IT security, security operations and offensive security
- Deep AWS security experience: IAM, Organizations and SCPs, Security Hub, GuardDuty, WAF, and Cloudflare
- Production programming experience with Python, Go, Bash; TypeScript is a major plus
- Infrastructure as Code knowledge, including drift, over-permissive modules, secrets in state, and pipeline privilege escalation
- Personally run vulnerability and attack surface management, including driving remediation with other teams
- Solid SIEM and detection engineering knowledge
- Hands-on detection and incident response experience, including investigating real alerts and writing post-incident reviews
- Working offensive security knowledge, including chaining misconfigurations into attack paths
- Practical current use of AI in security work and ability to validate its output
- Current, specific understanding of AI-driven threats
- Experience integrating and tuning SAST, DAST and SCA in the SDLC
- Ability to work autonomously and closely with engineers
- Comfort with open technical debate
- PCI DSS experience, SIEM building/maintenance, serverless and event-driven architecture, regulated industries, corporate IT security, AI or agentic system security, security frameworks, public artifacts, and certifications such as CISSP, AWS Certified Security or CEH are nice to have
- Certifications are welcome, but demonstrated work is weighted more heavily
Benefits
Comp & perks- A lean, focused company, offering a flexible working environment
- The opportunity to work with and learn form a highly skilled, talented team
- A great company culture, where accountability is innate, transparency is key and competency is virtue
- Being part of a tight knit, caring community
- Work equipment of your choice
- Private health insurance
- Learning budget
- Company wide and team based get togethers