Key Responsibilities
- Conduct Threat Modelling using established and documented methodologies.
- Apply techniques including STRIDE, PASTA, Attack Trees and MITRE ATT&CK to identify and assess threats.
- Identify vulnerabilities using frameworks such as CWE and OWASP.
- Define, document and maintain appropriate security controls and mitigations.
- Manage the life cycle of identified threats and associated controls.
- Deliver threat models and supporting activities within agreed timelines.
- Develop automation tools and solutions to improve the threat modelling process.
- Develop, test and deploy secure and efficient Python-based applications in line with established SDLC processes and quality standards.
- Contribute to the continuous improvement of existing threat modelling processes and methodologies.
- Present threat modelling outputs and recommendations to senior stakeholders, technical teams and wider audiences.
- Support and mentor junior members of the team.
- Supervise and provide technical guidance to less experienced team members.
- Take responsibility for elements of the threat modelling service.
- Work independently with minimal supervision while maintaining a consistently high standard of delivery.
- Collaborate with engineering, architecture, DevOps and Cyber Security teams.
- Support or participate in penetration testing activities where required.
- Design and review technical architectures from a security perspective.
Essential Technical Skills & Experience
You should have 6+ years of overall IT experience, including a minimum of 4 years within Cyber Security/Information Security.
Strong experience in several of the following is required:
- Threat Modelling - essential, including STRIDE, PASTA, Attack Trees, tooling and MITRE ATT&CK.
- Professional experience working within a Cyber Security/Information Security role - essential.
- Identifying vulnerabilities using CWE and OWASP.
Security principles covering:
- Authentication and authorisation
- Logging and monitoring
- Encryption
- Infrastructure security
- Network security and segmentation
- Operating systems and security hardening.
- Software development concepts including CI/CD, pipelines and SDLC.
- Scripting and Infrastructure as Code, including Terraform and CloudFormation.
- Cloud Development Kit (CDK) and GitOps.
- Experience working within DevOps and Agile environments.
- Jira or similar ticketing/workflow platforms.
- Docker, Kubernetes, Serverless and Helm - essential.
- Cloud security and secure cloud architecture.
- Technical architecture design and review.
- Strong programming skills, particularly Python, including asynchronous programming.
- FastAPI - essential.
- Pytest/unit testing - essential.
- Experience developing and maintaining software in line with security standards and SDLC processes.
- Experience with technologies such as Snowflake, MongoDB, Terraform Cloud, GitHub and Databricks would be advantageous.
Key Attributes
- Strong analytical skills and exceptional attention to detail.
- An adversarial mindset and the ability to think like an attacker.
- A proactive approach to research, particularly using vendor documentation and technical resources.
- Strong documentation and technical writing skills.
- Experience working within regulated environments.
- A genuine interest in emerging technologies, security methodologies and industry developments.
- Strong problem-solving and critical-thinking skills.
- Excellent communication and collaboration skills.
- The ability to build effective relationships across technical and non-technical teams.
- Confidence presenting technical findings to senior stakeholders.
- A willingness to mentor, support and develop other members of the team.
This is an opportunity to work on a technically challenging Cyber Security programme where you will have significant responsibility across Threat Modelling, Cloud Security, Secure Development and Cyber Security architecture.