Cyber Security Analyst
Threat Modelling Engineer
Location: London
Working Pattern: 4 days onsite / 1 day remote
Contract: Initial 6-month contract
Rate: £400 - £500 per day
Damia Group is supporting a leading organisation in the delivery of a high-profile Cyber Security programme and is looking for an experienced Senior Threat Modelling Engineer to join the team in London.
You will play a key role in identifying and assessing security threats, defining appropriate mitigating controls, and helping to continuously improve the organisation's threat modelling capability.
This is a hands-on position combining Threat Modelling, Cyber Security, Cloud Security and Python development, with responsibility for delivering high-quality threat models while also supporting and mentoring more junior members of the team.
Key Responsibilities
- Conduct Threat Modelling using established and documented methodologies.
- Apply techniques including STRIDE, PASTA, Attack Trees and MITRE ATT&CK to identify and assess threats.
- Identify vulnerabilities using frameworks such as CWE and OWASP.
- Define, document and maintain appropriate security controls and mitigations.
- Manage the lifecycle of identified threats and associated controls.
- Deliver threat models and supporting activities within agreed timelines.
- Develop automation tools and solutions to improve the threat modelling process.
- Develop, test and deploy secure and efficient Python-based applications in line with established SDLC processes and quality standards.
- Contribute to the continuous improvement of existing threat modelling processes and methodologies.
- Present threat modelling outputs and recommendations to senior stakeholders, technical teams and wider audiences.
- Support and mentor junior members of the team.
- Supervise and provide technical guidance to less experienced team members.
- Take responsibility for elements of the threat modelling service.
- Work independently with minimal supervision while maintaining a consistently high standard of delivery.
- Collaborate with engineering, architecture, DevOps and Cyber Security teams.
- Support or participate in penetration testing activities where required.
- Design and review technical architectures from a security perspective.
Essential Technical Skills & Experience
You should have 6 + years of overall IT experience, including a minimum of 4 years within Cyber Security / Information Security.
Strong experience in several of the following is required:
- Threat Modelling – essential, including STRIDE, PASTA, Attack Trees, tooling and MITRE ATT&CK.
- Professional experience working within a Cyber Security / Information Security role – essential.
- Identifying vulnerabilities using CWE and OWASP.
- Security principles covering:
- Authentication and authorisation
- Logging and monitoring
- Encryption
- Infrastructure security
- Network security and segmentation
- Operating systems and security hardening.
- Software development concepts including CI/CD, pipelines and SDLC.
- Scripting and Infrastructure as Code, including Terraform and CloudFormation.
- Cloud Development Kit (CDK) and GitOps.
- Experience working within DevOps and Agile environments.
- Jira or similar ticketing/workflow platforms.
- Docker, Kubernetes, Serverless and Helm – essential.
- Cloud security and secure cloud architecture.
- Technical architecture design and review.
- Strong programming skills, particularly Python, including asynchronous programming.
- FastAPI – essential.
- Pytest / unit testing – essential.
- Experience developing and maintaining software in line with security standards and SDLC processes.
- Experience with technologies such as Snowflake, MongoDB, Terraform Cloud, GitHub and Databricks would be advantageous.
Key Attributes
We're looking for someone who demonstrates:
- Strong analytical skills and exceptional attention to detail.
- An adversarial mindset and the ability to think like an attacker.
- A proactive approach to research, particularly using vendor documentation and technical resources.
- Strong documentation and technical writing skills.
- Experience working within regulated environments.
- A genuine interest in emerging technologies, security methodologies and industry developments.
- Strong problem-solving and critical-thinking skills.
- Excellent communication and collaboration skills.
- The ability to build effective relationships across technical and non-technical teams.
- Confidence presenting technical findings to senior stakeholders.
- A willingness to mentor, support and develop other members of the team.
This is an opportunity to work on a technically challenging Cyber Security programme where you will have significant responsibility across Threat Modelling, Cloud Security, Secure Development and Cyber Security architecture.