Key Responsibilities
- Conduct Threat Modelling using established and documented methodologies.
- Apply techniques including STRIDE, PASTA, Attack Trees and MITRE ATT&CK to identify and assess threats.
- Identify vulnerabilities using frameworks such as CWE and OWASP.
- Define, document and maintain appropriate security controls and mitigations.
- Manage the lifecycle of identified threats and associated controls.
- Deliver threat models and supporting activities within agreed timelines.
- Develop automation tools and solutions to improve the threat modelling process.
- Develop, test and deploy secure and efficient Python-based applications in line with established SDLC processes and quality standards.
- Contribute to the continuous improvement of existing threat modelling processes and methodologies.
- Present threat modelling outputs and recommendations to senior stakeholders, technical teams and wider audiences.
- Support and mentor junior members of the team.
- Supervise and provide technical guidance to less experienced team members.
- Take responsibility for elements of the threat modelling service.
- Work independently with minimal supervision while maintaining a consistently high standard of delivery.
- Collaborate with engineering, architecture, DevOps and Cyber Security teams.
- Support or participate in penetration testing activities where required.
- Design and review technical architectures from a security perspective.
Essential Technical Skills & Experience
- You should have 6 + years of overall IT experience , including a minimum of 4 years within Cyber Security / Information Security .
- Strong experience in several of the following is required: Threat Modelling – essential , including STRIDE, PASTA, Attack Trees, tooling and MITRE ATT&CK.
- Professional experience working within a Cyber Security / Information Security role – essential .
- Identifying vulnerabilities using CWE and OWASP .
- Security principles covering: Authentication and authorisation, Logging and monitoring, Encryption, Infrastructure security, Network security and segmentation, Operating systems and security hardening.
- Software development concepts including CI/CD, pipelines and SDLC .
- Scripting and Infrastructure as Code, including Terraform and CloudFormation .
- Cloud Development Kit (CDK) and GitOps.
- Experience working within DevOps and Agile environments .
- Jira or similar ticketing/workflow platforms.
- Docker, Kubernetes, Serverless and Helm – essential .
- Cloud security and secure cloud architecture.
- Technical architecture design and review.
- Strong programming skills, particularly Python , including asynchronous programming.
- FastAPI – essential .
- Pytest / unit testing – essential .
- Experience developing and maintaining software in line with security standards and SDLC processes.
- Experience with technologies such as Snowflake, MongoDB, Terraform Cloud, GitHub and Databricks would be advantageous.
Key Attributes
- We're looking for someone who demonstrates: Strong analytical skills and exceptional attention to detail.
- An adversarial mindset and the ability to think like an attacker.
- A proactive approach to research, particularly using vendor documentation and technical resources.
- Strong documentation and technical writing skills.
- Experience working within regulated environments .
- A genuine interest in emerging technologies, security methodologies and industry developments.
- Strong problem-solving and critical-thinking skills.
- Excellent communication and collaboration skills.
- The ability to build effective relationships across technical and non-technical teams.
- Confidence presenting technical findings to senior stakeholders.
- A willingness to mentor, support and develop other members of the team.
This is an opportunity to work on a technically challenging Cyber Security programme where you will have significant responsibility across Threat Modelling, Cloud Security, Secure Development and Cyber Security architecture .