Threat Modelling Engineer
- London
- Contract
- Full time
- £400 - £500 Per Day
Job Description
Threat Modelling Engineer
Location: London
Working Pattern: 4 days onsite / 1 day remote
Contract: Initial 6-month contract
Rate: £400 - £500 per day
Damia Group is supporting a leading organisation in the delivery of a high-profile Cyber Security programme and is looking for an experienced Senior Threat Modelling Engineer to join the team in London.
You will play a key role in identifying and assessing security threats, defining appropriate mitigating controls, and helping to continuously improve the organisation's threat modelling capability.
This is a hands-on position combining Threat Modelling, Cyber Security, Cloud Security and Python development, with responsibility for delivering high-quality threat models while also supporting and mentoring more junior members of the team.
Key Responsibilities
Conduct Threat Modelling using established and documented methodologies. Apply techniques including STRIDE, PASTA, Attack Trees and MITRE ATT&CK to identify and assess threats. Identify vulnerabilities using frameworks such as CWE and OWASP. Define, document and maintain appropriate security controls and mitigations. Manage the lifecycle of identified threats and associated controls. Deliver threat models and supporting activities within agreed timelines. Develop automation tools and solutions to improve the threat modelling process. Develop, test and deploy secure and efficient Python-based applications in line with established SDLC processes and quality standards. Contribute to the continuous improvement of existing threat modelling processes and methodologies. Present threat modelling outputs and recommendations to senior stakeholders, technical teams and wider audiences. Support and mentor junior members of the team. Supervise and provide technical guidance to less experienced team members. Take responsibility for elements of the threat modelling service. Work independently with minimal supervision while maintaining a consistently high standard of delivery. Collaborate with engineering, architecture, DevOps and Cyber Security teams. Support or participate in penetration testing activities where required. Design and review technical architectures from a security perspective.
Essential Technical Skills & Experience
You should have 6+ years of overall IT experience, including a minimum of 4 years within Cyber Security / Information Security.
Strong experience in several of the following is required:
Threat Modelling - essential, including STRIDE, PASTA, Attack Trees, tooling and MITRE ATT&CK. Professional experience working within a Cyber Security / Information Security role - essential. Identifying vulnerabilities using CWE and OWASP. Security principles covering: Authentication and authorisation Logging and monitoring Encryption Infrastructure security Network security and segmentation Operating systems and security hardening. Software development concepts including CI/CD, pipelines and SDLC. Scripting and Infrastructure as Code, including Terraform and CloudFormation. Cloud Development Kit (CDK) and GitOps. Experience working within DevOps and Agile environments. Jira or similar ticketing/workflow platforms. Docker, Kubernetes, Serverless and Helm - essential. Cloud security and secure cloud architecture. Technical architecture design and review. Strong programming skills, particularly Python, including asynchronous programming. FastAPI - essential. Pytest / unit testing - essential. Experience developing and maintaining software in line with security standards and SDLC processes. Experience with technologies such as Snowflake, MongoDB, Terraform Cloud, GitHub and Databricks would be advantageous.
Key Attributes
We're looking for someone who demonstrates:
Strong analytical skills and exceptional attention to detail. An adversarial mindset and the ability to think like an attacker. A proactive approach to research, particularly using vendor documentation and technical resources. Strong documentation and technical writing skills. Experience working within regulated environments. A genuine interest in emerging technologies, security methodologies and industry developments. Strong problem-solving and critical-thinking skills. Excellent communication and collaboration skills. The ability to build effective relationships across technical and non-technical teams. Confidence presenting technical findings to senior stakeholders. A willingness to mentor, support and develop other members of the team.
This is an opportunity to work on a technically challenging Cyber Security programme where you will have significant responsibility across Threat Modelling, Cloud Security, Secure Development and Cyber Security architecture.
Damia Group Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept our Data Protection Policy which can be found on our website.
Please note that no terminology in this advert is intended to discriminate on the grounds of a person's gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and ability to perform the duties of the job.
Should the role require the successful candidate to undergo and be eligible for UK Security Vetting. Clearance sponsorship will be provided where required. Due to the nature of the work, candidates should meet the relevant residency requirements. If applicable, Reserved Post nationality restrictions will be confirmed by the client. Damia is committed to inclusive recruitment and welcomes applicants from all backgrounds.
Damia Group is acting as an Employment Business in relation to this vacancy and in accordance to Conduct Regulations 2003


