Open roleExternal
Cyber Security Engineer, Threat Modelling
- london, england, United Kingdom
- Permanent·On-site
- Full time
- £70 - £100 Per Hour
Job Description
Cyber Security Engineer, Threat Modelling
Location: London/ Hybrid - 4 days a week onsite
Duration: 6 months (Initial)
A major organisation is seeking a Cyber Security Engineer to help drive secure-by-design practices across cloud and application environments.
Key Responsibilities
- Conduct threat modelling using STRIDE, PASTA, ATT&CK and Attack Trees.
- Identify vulnerabilities and define mitigating security controls.
- Review technical architectures and support secure SDLC processes.
- Develop security automation tooling and Python-based applications.
- Partner with engineering teams to embed security best practices.
- Track threats and controls through to remediation and closure.
Required Experience
- 6+ years in IT, including 4+ years within Cyber Security.
- Strong threat modelling and application security experience.
- Knowledge of OWASP, CWE, authentication, authorisation, encryption and infrastructure security.
- Experience with Terraform/CloudFormation, CI/CD and Jira.
- Strong Python skills, including FastAPI and Pytest.
- Experience within a regulated environment.
- Docker, Kubernetes, Helm, Serverless, GitOps and CDK.
- Penetration testing exposure.
- Snowflake, MongoDB, Databricks, GitHub and Terraform Cloud.
Certifications
- Associate-level cloud certification (AWS, Azure, GCP or equivalent).
- Cyber security certification such as CySA+, CISA, GSEC, SSCP or Microsoft Security certifications.
What You'll Bring
- Strong analytical and problem-solving skills.
- Excellent communication and stakeholder management.
- An adversarial mindset and passion for continuous learning.
- Ability to work independently and collaboratively across teams.


