Job Title: Threat Modelling Security Engineer
City: London
State/Province: London
Posting Start Date: 4/14/26
Role Purpose
The purpose of this role is to design the organisation’s computer and network security infrastructure and protect its systems and sensitive information from cyber threats.
Threat Modelling
- Hands‑on experience in security testing.
- Strong experience in threat modelling and security risk assessment.
- Enterprise reference architecture: define threat‑modeling reference patterns for common architectures (microservices, APIs, event‑driven, cloud). Threat‑informed integration: integrate ATT&CK-informed scenarios and control validation into design‑time practices.
- Align threat modelling with broader security architecture (Zero Trust, IAM, monitoring).
- Familiar with common methodologies such as DREAD, STRIDE, PASTA, etc.
- Set up threat‑modelling process.
- On-board client applications for threat modelling.
- Execute threat modelling (identify threat vectors using automated/manual methods, create the threat model and publish to stakeholders).
- Explain results to end‑client developers.
- Remediation support and coordination.
- Cloud security knowledge is a good to have.
- Very good knowledge of OWASP security standards and deep understanding of common security vulnerabilities.
- Very good presentation skills, strong communication and good customer‑handling skill.
- Capable of understanding customer requirements for security testing.
- Capable of providing security solutions to the customer for complex security testing/risk requirement.
- Automation strategy: define tool integrations (repo, CI gates, KB/RAG) and quality controls for scaling.
Key Deliverables
- Enterprise threat‑modelling framework, reference architectures, and multi‑quarter roadmap.
- Control validation and assurance framework with KPIs/KRIs.
- Executive briefings and decision memos.
Mandatory Skills
Threat modelling.
#J-18808-Ljbffr…
