51 to 75 of 289 Threat Modelling Jobs in London

Security Engineer, AWS Security

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
met. Key job responsibilities Security Reviews: Conduct design reviews for new and existing services, evaluating architecture documents and system designs for security risks. Threat Modelling: Identify attack vectors and security weaknesses in application architectures through structured threatmodelling exercises. Penetration Testing: Coordinate penetration testing to validate … testing, mobile security, cryptography, public key infrastructure, forensic security, IP security, SSL/TLS, computer viruses and malware, network security, trusted security, trusted execution, threat intelligence, IoT security implications, or authentication. Experience scripting with Python, Perl, Bash or PowerShell. Experience triaging and developing security alerts and response automation, conducting ...

Cloud Security Consultant

Hiring Organisation
83zero Limited
Location
City of London, London, United Kingdom
Employment Type
Permanent, Work From Home
What You'll Be Doing Design secure architectures across AWS, Azure and hybrid cloud environments Develop cloud security strategies, governance and security standards Conduct threat modelling and security architecture reviews Embed security into cloud deployments through DevSecOps and automation Advise clients on best practice and modern cloud security … Looking For You'll have experience with several of the following: Cloud Security Architecture AWS, Azure and/or GCP Secure by Design & Threat Modelling Zero Trust principles DevSecOps & Infrastructure as Code Cloud Governance & IAM Relevant cloud security certifications (desirable) What's On Offer ...

Senior Application Security Engineer / DevSecOps Engineer

Hiring Organisation
Additional Resources Ltd
Location
London, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £80,000 per annum, Negotiable
security processes through infrastructure-as-code and scripting. Maintaining technical and security documentation. Supporting development teams with security tooling and best practices. Contributing to threat modelling and compliance activities. Applications are welcomed from candidates with the required experience from backgrounds including: Application Security Engineer, DevSecOps Engineer, Product Security … code and secure engineering practices. Familiarity with GitHub and GitHub Actions. Experience with Terraform and Python. Understanding of cloud security governance. Experience with threat modelling in software engineering contexts. Knowledge of ISO 27001 and its relevance to secure engineering. Exposure to Agile working environments and DevSecOps practices Ideally ...

Senior Security Analyst - Product-Based Risk Assessment (PBRA)

Hiring Organisation
Salt
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£517 - £690/day
assessments using recognised methodologies and industry frameworks. Evaluate risks related to infrastructure, software, cloud services, networks, third-party integrations, and information assets. Contribute to threat modelling and attack surface analysis activities. Support technology-focused assessments such as cloud, AI, and emerging technology evaluations. Stakeholder Engagement … understanding of cybersecurity principles, controls, and risk management practices. Knowledge of application security, cloud security, infrastructure security, and network security. Experience conducting security assessments, threat modelling, or risk analyses. Familiarity with industry frameworks and standards such as: NIST Cyber Security Framework ISO 27001 CIS Controls Secure Controls Framework ...

Senior Application Security Engineer

Hiring Organisation
TripAdvisor
Location
London, United Kingdom
Salary
Confidential
permanent contract.What You’ll Do:Lead the design and implementation of advanced application security measures, including encryption, secure APIs, and identity management.Conduct in-depth threat modelling and risk assessments to identify and mitigate potential security risks.Performing manual security assessments including code reviews.Act as a Subject Matter Expert … that the team remains proactive in its approach to security.What You’ll Need:Extensive experience in application security, including expertise in secure coding practices, threat modelling, vulnerability assessments, and incident response.Hands-on experience with security testing tools (SAST, DAST) and their integration into development pipelines.Strong understanding of advanced ...

Senior Application Security Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
What You’ll Do: Lead the design and implementation of advanced application security measures, including encryption, secure APIs, and identity management. Conduct in-depth threat modelling and risk assessments to identify and mitigate potential security risks. Performing manual security assessments including code reviews. Act as a Subject Matter … team remains proactive in its approach to security. What You’ll Need: Extensive experience in application security, including expertise in secure coding practices, threat modelling, vulnerability assessments, and incident response. Hands-on experience with security testing tools (SAST, DAST) and their integration into development pipelines. Strong understanding ...

Senior Security Engineer

Hiring Organisation
Flagstone
Location
London, United Kingdom
Salary
£ 80 K
Defender - triage, escalate, or contain as appropriateSupport incident response activities including containment, evidence gathering, and post-incident reviewParticipate in security risk assessments and threat modelling exercises across new and existing systemsCoordinate penetration test engagements (scope, logistics, findings review) and work with engineering teams to prioritise remediationWhat … Azure networking, and cloud security posture managementExperience writing infrastructure-as-code using Terraform or Bicep in a security engineering contextAbility to contribute to threat modelling and communicate security risk clearly to engineering and product audiencesExperience supporting or coordinating penetration testing programmes, including managing remediation cyclesFamiliarity with AI security ...

Information Security Review, Threat Modelling Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Information Security or Information Technology. Strong experience reviewing infrastructure security. Hands‐on cloud security experience across AWS and/or GCP. Demonstrated expertise in Threat Modelling methodologies such as STRIDE, PASTA or MITRE ATT&CK/ATLAS. Strong understanding of authentication, authorisation, encryption, logging & monitoring, infrastructure security ...

Security Engineer

Hiring Organisation
Tiro Partners Limited
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£60,000 - £90,000 per annum
Develop security and policy-as-code capabilities using tools such as OPA. Help secure cloud and data platforms, including Databricks, Dagster and Snowflake. Support threat modelling and ISO 27001 activities. Operate and improve application security services and tooling. Work directly with developers to identify and remediate vulnerabilities. About … with KQL advantageous. Experience securing GitHub/GitHub Actions, Kubernetes and APIs. Strong knowledge of application security testing and vulnerability management. Experience with DevSecOps, threat modelling and security automation. Knowledge of ISO 27001. Strong cloud security knowledge Azure (Preferred) If you’re looking for a role where ...

Senior Security Engineer Crypto

Hiring Organisation
Teya Solutions
Location
London, United Kingdom
Salary
£ 80 K
into platforms other teams operate against.ResponsibilitiesDesign, implement, and continuously improve a Secure SDLC integrated from design through productionEmbed security into planning and delivery via threat modelling, security requirements, and automated controlsLead application security reviews for new systems, major features, and high-risk changes across web, API, mobile … lifecycle management, PCI PIN and PCI-DSS scope experience is required.Application security at scale. SAST/DAST/SCA toolchain design and rollout. Threat modelling as a routine practice, not an event. Familiarity with modern AppSec tooling (Snyk, Wiz, Veracode, Checkmarx, Semgrep, GitHub Advanced Security or equivalents).Cloud ...

Cybersecurity consultant

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
hands-on implementation. About the role. You'll advise enterprise clients across banking, insurance, and public sector on security posture - from architecture review and threat modelling through to hands-on implementation of identity, segmentation, and detection controls. Our clients don't need another slide deck telling them they … their platform teams and get zero-trust principles actually implemented, on their timeline, without breaking the systems that run their business. Lead architecture reviews, threat modelling sessions, and control gap assessments against frameworks like NIST, ISO 27001, and industry-specific regulation. Translate risk into a roadmap Turn assessment ...

Application Security Engineering Manager Synthesia Europe, UK

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
earn their trust and enable their best work, you'll need to be genuinely close to the craft — able to engage at depth on threat modelling, agentic security tooling, SDLC design, and application risk. You'll also own AppSec strategy and be accountable for how the function scales … context into a clear, prioritised programme of work with measurable outcomes. Be a credible technical partner to your team — able to engage substantively on threat models, security architecture, agentic tooling design, and risk decisions, and willing to get into the details when it matters. Define and maintain the team ...

AI Security Architect

Hiring Organisation
Additional Resources
Location
London, United Kingdom
Employment Type
Contract
secure operating models that enable the safe deployment and use of AI solutions across complex business environments. This role focuses on AI security assessments, threat modelling, governance frameworks, security controls, secure integrations and identifying AI-specific security risks. Please only apply if you have the right to work … visa sponsorship is not available. You will be responsible for Conducting security assessments of AI solutions, including threat modelling. Developing governance frameworks, security standards and best practice for AI adoption. Designing controls for identity, access management, auditability and human oversight. Supporting the implementation of security guardrails for AI, generative ...

AI Security Architect

Hiring Organisation
Additional Resources Ltd
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
operating models that enable the safe deployment and use of AI solutions across complex business environments. . This role focuses on AI security assessments, threat modelling, governance frameworks, security controls, secure integrations and identifying AI-specific security risks . Please only apply if you have the right … work in the UK, as visa sponsorship is not available. You will be responsible for Conducting security assessments of AI solutions, including threat modelling. Developing governance frameworks, security standards and best practice for AI adoption. Designing controls for identity, access management, auditability and human oversight. Supporting the implementation ...

Staff Engineer

Hiring Organisation
Flagstone
Location
London, United Kingdom
Salary
£ 80 K
applications.Resilience & Performance: Design solution-wide UI resilience (graceful degradation, back-pressure, retry strategies) and own performance standards across web and mobile.Quality, Security & Compliance: Own threat modelling and security hardening for tribe front-end products; maintain high standards through code review, secure coding practices, and risk management.External Representation: Represent … graceful degradation, zero-downtime deployments, observability, performance budgets).Experience with Azure development and cloud-based infrastructure, including CI/CD and pipeline observability.Experience owning threat modelling and security hardening for front-end products; strong grasp of OWASP and secure coding practices.Track record of originating and shepherding cross-team ...

Staff Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Performance: Design solution‐wide UI resilience (graceful degradation, back‐pressure, retry strategies) and own performance standards across web and mobile. Quality, Security & Compliance: Own threat modelling and security hardening for tribe front‐end products; maintain high standards through code review, secure coding practices, and risk management. External Representation … zero‐downtime deployments, observability, performance budgets). Experience with Azure development and cloud‐based infrastructure , including CI/CD and pipeline observability. Experience owning threat modelling and security hardening for front‐end products; strong grasp of OWASP and secure coding practices. Track record of originating and shepherding cross ...

Founding Security Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
they’re effectively configured, maintained, and scaled as the business grows Embed secure-by-design practices into the development lifecycle — from secure coding and threat modelling to design reviews and CI/CD hardening Monitor systems for irregular behaviour and proactively design detection and prevention mechanisms Ensure infrastructure … like OWASP and AWS Well-Architected to real-world scenarios Have experience reviewing and improving product and infrastructure security, including secure SDLC practices (e.g. threat modelling, secure code review, CI/CD hardening) Are familiar with compliance frameworks like ISO 27001 or SOC 2 , and can translate technical ...

Senior Mobile Security Technical Specialist

Hiring Organisation
Lloyds Banking Group
Location
London, United Kingdom
Salary
£ 80 K
across Lloyds Bank, Halifax, Bank of Scotland and Scottish Widows. You’ll help design, build and enhance a world-class mobile security framework, leading threat modelling, security assessments, penetration testing capabilities and security tooling across Android and iOS platforms. Working within agile teams, you’ll drive continuous improvements … impact and do the best work of your career, you’ve just found itWhat we’re looking for Experience of mobile platform security, threat modelling and mitigation techniquesStrong hands-on experience conducting reviews of mobile application security postureExperience developing and maintaining penetration testing tools, scripts, policies and proceduresIn ...

Security Consultant - H&PS

Hiring Organisation
Accenture
Location
London, United Kingdom
Salary
£ 80 K
cyber risk within technology projects by ensuring appropriate security requirements, controls, monitoring, and assurance activities are identified, specified, and evidenced throughout the project lifecycle.Conduct threat modelling activities, including alignment with frameworks such as MITRE ATT&CK, to identify credible threats and define proportionate security controls.Define monitoring and logging … looking for experience in the following skills:Strong technical knowledge in at least one of the following areas:Public cloudApplication securityNetworkingOn-premises infrastructureUnderstanding of threat modelling, security controls, and risk analysis principles.Ability to assess risks and recommend proportionate security controls and monitoring measures, rather than relying solely ...

AI Security Engineer

Hiring Organisation
Huxley Associates
Location
London, United Kingdom
Salary
£ 80 K
Engineer, London/GlasgowThe AI Security Engineer is responsible for securing AI platforms and systems against adversarial threats.The role focuses on technical security controls, threat modelling, red teaming, and continuous monitoring of AI systems.Responsibilities:Design and implement security controls for AI and LLM systemsPerform AI-specific threat modelling and risk analysisLead red team and blue team testing of AI platformsConduct prompt injection and adversarial testingImplement monitoring, logging, and alerting for AI behaviourSecure AI pipelines, APIs, and orchestration layersSupport secure deployment and CI/CD practicesSkills & Experience:Strong background in security engineering and cloud securityHands ...

Software Security Engineer

Hiring Organisation
Fortinet
Location
London, United Kingdom
Salary
£ 80 K
level of security within the product.Key Responsibilities and Technologies Championing security throughout the FortiDLP product. Help maintain up-to-date and vulnerability-free dependencies. Threat modelling, design and code review. Maintaining and tuning automatic vulnerability checks within Continuous Integration systems. Triage findings of scanning tools and ensure prompt … least 3-5 years of software engineering experience. Familiarity with computer science fundamentals and backend development concepts. Experience in Golang. Experience with threat modelling and security concepts. Some familiarity with Checkmarx/Trivy/Kics or similar tools, as well as DAST tooling in general.Communication and CollaborationWe work ...

AI Security Engineer

Hiring Organisation
Experis
Location
London, United Kingdom
Employment Type
Contract
defence to deliver agentic infosec solutions aligned to our target operating model Key Responsibilities * Design security solutions for AI-driven and agentic systems * Conduct threat modelling (AI-specific and traditional) and risk reviews * Support the embedding security across the end-to-end agentic SDLC (design, test, release, governance … information security, ideally with a hands-on background in application or infrastructure security * Solid understanding of core security principles and architectures Experience with: o Threat modelling o Secure system design o Embedding security within the SDLC * Exposure to AI and agentic systems (practical or conceptual), including: o Security ...

Head of Cyber Security (UK based)

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
application architectures in partnership with Engineering, DevOps, Product and Infrastructure teams. Embedding security throughout the software development lifecycle by implementing secure-by-design principles, threat modelling, code security, automated testing and DevSecOps practices. Leading cyber incident response, crisis management, threat intelligence, vulnerability management and continuous security monitoring … software development, DevSecOps and application security, including secure SDLC, CI/CD security, SAST, DAST, Software Composition Analysis (SCA), container security, API security and threat modelling. Strong technical knowledge of Identity and Access Management (IAM), Identity Providers (IdP), Single Sign-On (SSO), Privileged Access Management (PAM), Conditional Access ...

Cyber Security Engineer - Assistant Vice President

Hiring Organisation
Mizuho
Location
Greater London, United Kingdom
Employment Type
Full Time
Profile Summary Seeking security engineer to join our Proactive Security team, this role will focus on the development of security technology stack to ensure threat mitigation is in place through offensive and preventive measures. Duties and Responsibilities Threat Modelling & Risk Analysis: Develop and maintain threat models … tooling integration and orchestration. Develop and implementation of SOAR capabilities that aligns with existing technology stack. Experience with KMS systems and methodologies. Identity based threat detection and prevention. Privileged Access and Session Management SIEM Management: Design, implement, and maintain of workspaces, including data connectors, Logic App, Function App, analytics ...

CLOUD SECURITY ARCHITECT

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
architectures and reusable solution patterns Define and author enterprise‐level security policies, controls frameworks, and governance documentation aligned to industry standards Lead risk assessments, threat modelling exercises, and security posture evaluations for cloud platforms and SaaS products, utilising methodologies such as FAIR Drive compliance programmes covering ...