All Jobs Vacancy

Threat Modelling Engineer

Posted 6 days ago by Damia Group LTD

Key Responsibilities

  • Conduct Threat Modelling using established and documented methodologies.
  • Apply techniques including STRIDE, PASTA, Attack Trees and MITRE ATT&CK to identify and assess threats.
  • Identify vulnerabilities using frameworks such as CWE and OWASP.
  • Define, document and maintain appropriate security controls and mitigations.
  • Manage the life cycle of identified threats and associated controls.
  • Deliver threat models and supporting activities within agreed timelines.
  • Develop automation tools and solutions to improve the threat modelling process.
  • Develop, test and deploy secure and efficient Python-based applications in line with established SDLC processes and quality standards.
  • Contribute to the continuous improvement of existing threat modelling processes and methodologies.
  • Present threat modelling outputs and recommendations to senior stakeholders, technical teams and wider audiences.
  • Support and mentor junior members of the team.
  • Supervise and provide technical guidance to less experienced team members.
  • Take responsibility for elements of the threat modelling service.
  • Work independently with minimal supervision while maintaining a consistently high standard of delivery.
  • Collaborate with engineering, architecture, DevOps and Cyber Security teams.
  • Support or participate in penetration testing activities where required.
  • Design and review technical architectures from a security perspective.

Essential Technical Skills & Experience

You should have 6+ years of overall IT experience, including a minimum of 4 years within Cyber Security/Information Security.

Strong experience in several of the following is required:

  • Threat Modelling - essential, including STRIDE, PASTA, Attack Trees, tooling and MITRE ATT&CK.
  • Professional experience working within a Cyber Security/Information Security role - essential.
  • Identifying vulnerabilities using CWE and OWASP.

Security principles covering:

  • Authentication and authorisation
  • Logging and monitoring
  • Encryption
  • Infrastructure security
  • Network security and segmentation
  • Operating systems and security hardening.
  • Software development concepts including CI/CD, pipelines and SDLC.
  • Scripting and Infrastructure as Code, including Terraform and CloudFormation.
  • Cloud Development Kit (CDK) and GitOps.
  • Experience working within DevOps and Agile environments.
  • Jira or similar ticketing/workflow platforms.
  • Docker, Kubernetes, Serverless and Helm - essential.
  • Cloud security and secure cloud architecture.
  • Technical architecture design and review.
  • Strong programming skills, particularly Python, including asynchronous programming.
  • FastAPI - essential.
  • Pytest/unit testing - essential.
  • Experience developing and maintaining software in line with security standards and SDLC processes.
  • Experience with technologies such as Snowflake, MongoDB, Terraform Cloud, GitHub and Databricks would be advantageous.

Key Attributes

  • Strong analytical skills and exceptional attention to detail.
  • An adversarial mindset and the ability to think like an attacker.
  • A proactive approach to research, particularly using vendor documentation and technical resources.
  • Strong documentation and technical writing skills.
  • Experience working within regulated environments.
  • A genuine interest in emerging technologies, security methodologies and industry developments.
  • Strong problem-solving and critical-thinking skills.
  • Excellent communication and collaboration skills.
  • The ability to build effective relationships across technical and non-technical teams.
  • Confidence presenting technical findings to senior stakeholders.
  • A willingness to mentor, support and develop other members of the team.

This is an opportunity to work on a technically challenging Cyber Security programme where you will have significant responsibility across Threat Modelling, Cloud Security, Secure Development and Cyber Security architecture.

Rate:
£500/day
Location:
London
IR35 Status:
Not specified
Remote Status:
Hybrid
Industry:
Cybersecurity
Seniority Level:
Senior

Take-Home Pay

£7,000 per month

Visit calculators for additional details

Share job