1 to 25 of 169 Threat Modelling Jobs in England

Head of Product Security - CISO function - BPL

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Responsibilities Own and drive the shift‐left security programme, ensuring security is integrated into the earliest stages of the software development lifecycle through threat modelling, secure design patterns, and automated tooling. Manage the security champions programme, recruiting, training, and supporting champions across all product squads. Own the developer … publish the security engagement model for product and engineering teams, including trigger points (new service, new integration, pre‐release), SLAs and escalation paths. Oversee threat modelling for new services and major changes, ensuring threat models are completed before development progresses beyond initial design. Own the security sign ...

Security Architect

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
teams by embedding security-by-design principles throughout the software development lifecycle. Define and document security patterns, reference architectures, and reusable security artefacts. Lead threat modelling activities and identify appropriate mitigation strategies. Collaborate with stakeholders across business, product, operations, and engineering teams to drive secure decision-making. Advise … facing and/or consultancy environments. Demonstrated experience designing and implementing enterprise security architectures. Strong understanding of security architecture methodologies and frameworks. Experience conducting threat modelling and security risk assessments. Experience supporting security assurance activities within regulated environments. Proven ability to balance security requirements with operational and business ...

Lead Security Assurance Engineer

Hiring Organisation
Jobleads-UK
Location
Bristol, England, United Kingdom
edge of delivery reviewing outputs. You'll be embedded in multidisciplinary teams, shaping how security assurance is woven into everyday engineering work — from threat modelling at design time to control testing in production. You'll build trusted relationships with client security teams, senior stakeholders, and government security communities … report programme KPIs (MTTR by severity, backlog age, coverage, recurrence rate) to senior stakeholders. Drive security into the team's normal rhythm. Embed threat modelling, secure code review, SAST, SCA, dependency policy, and container scanning into design and delivery cycles — making security a shared engineering responsibility rather than ...

Lead Security Assurance Engineer

Hiring Organisation
Hackajob Ltd
Location
Bristol, Avon, South West, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
Salary
£90,000
edge of delivery reviewing outputs. You'll be embedded in multidisciplinary teams, shaping how security assurance is woven into everyday engineering work - from threat modelling at design time to control testing in production. You'll build trusted relationships with client security teams, senior stakeholders, and government security communities … report programme KPIs (MTTR by severity, backlog age, coverage, recurrence rate) to senior stakeholders. Drive security into the team's normal rhythm. Embed threat modelling, secure code review, SAST, SCA, dependency policy, and container scanning into design and delivery cycles - making security a shared engineering responsibility rather than ...

Cyber Threat Intelligence Analyst

Hiring Organisation
Summer Browning Associates
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£NEG Competitive Inside IR35 Day Rate
Cyber Threat Intelligence Analyst Summer-Browning Associates is supporting our client in the Central Government, who is seeking a Cyber Threat Intelligence Analyst for an initial 12-month assignment, with the possibility of extension. Location: London | Hybrid The ideal candidates will hold an active Security clearance and have … proven background in Cyber Security Threat Intelligence, with the following skills and experience: Experience in risk and threat modelling within high-threat government environments. Experience with cyber threat frameworks, such as MITRE ATT&CK, the Diamond Model, and the Intelligence Cycle. Proficiency in using open ...

Director, Security Engineering & Operations

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
technology teams. Set and direct a secure SDLC strategy that engineers engage with, coaching and mentoring our application security engineer with running our threat modelling program, embedding security in CI/CD, and iteratively improving our vulnerability management processes. Partner with engineering leadership to ensure risk‐driven supply … with our CISO to shape and implement an AI security posture that is embedded in strong security foundations, helping us stay ahead of the threat landscape rather than reacting to it. Detection, Response & SOC Partnership Own the strategic relationship with our 24/7 outsourced SOC holding them ...

AI Security Architect

Hiring Organisation
Hays IT - HTS - Southend
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
GBP Daily
role, between 8:30am-5:30pm Monday to Friday. Shifts: Monday - Friday (37.5 hours per week) The must haves: Extensive hands-on experience with Threat Modelling, SAST, DAST, and web application security, including OWASP Top 10, CWE Top 25, and SANS 25. Hands-on experience with GCP security … solution architectures to ensure appropriate security controls, data protection measures, identity controls, network security, and compliance requirements are incorporated before deployment. Perform AI-focused threat modelling and security assessments, identifying risks such as sensitive data exposure, prompt injection, indirect prompt attacks, model misuse, insecure plugins, excessive permissions ...

Senior Security Engineer Remote/Flexible working

Hiring Organisation
17918
Location
Bristol, Gloucestershire, United Kingdom
Regulations - feeding posture data into governance and risk reporting rather than treating it as a point-in-time exercise. Lead risk assessments and threat-modelling sessions , selecting methodologies (ISO 27005, NIST RMF, STRIDE, MITRE ATT&CK) that are proportionate to system criticality, and ensuring findings feed into programme … structuring reports around the decisions people need to make, not just the controls you've tested. Embed security as a continuous engineering concern , supporting threat modelling and security reviews throughout delivery, challenging designs that create unnecessary risk, and mentoring colleagues on secure-by-default practices. Support and assess ...

Security Solutions Architect

Hiring Organisation
Huxley Associates
Location
City of London, London, United Kingdom
Employment Type
Permanent
Salary
£110000 - £130000/annum + Bonus & Benefits Package
design, scalable, and aligned to business and regulatory requirements. Working closely with architecture, engineering, and delivery teams, you will produce high-level designs, conduct threat modelling and risk assessments, and provide architectural leadership throughout project lifecycles. Key Responsibilities Develop high-level security architecture and solution designs for enterprise … technology initiatives. Evaluate emerging technologies and security tooling, providing recommendations and business justification. Conduct threat modelling, security risk assessments, and secure-by-design reviews. Define security controls, network architectures, and data flow models for internal and external integrations. Provide technical guidance to engineering, testing, and delivery teams during ...

Cyber GRC Consultant (DV Cleared)

Hiring Organisation
Sanderson Government and Defence
Location
South West, United Kingdom
Employment Type
Permanent, Work From Home
cloud infrastructures. Contribute to blogs and research within the business community. Experience Required The successful candidate will possess proven experience in cybersecurity, security architecture, threat modelling, or related fields within Public Sector and MOD and will have achieved or be working towards Full Membership of CIISEC … NPSA and NCSC security policies, standards and guidance. Have experience building and implementing secure by design principals within the software development lifecycle (SDLC). Threat Modelling - Kill Chain - Attack tree analysis. Working understanding of: Cloud security including Azure, Amazon Web Service, Key Management Systems, Containerisation, Network Security Groups ...

Senior Security Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
secure‐by‐design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers … software development practices Experience working closely with software engineering teams Hands‐on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note ...

Staff Security Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
secure-by-design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers … software development practices Experience working closely with software engineering teams Hands‐on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note ...

Software Security Engineer

Hiring Organisation
Data Idols
Location
London, Farringdon, United Kingdom
Employment Type
Permanent
Salary
£140000 - £150000/annum
secure-by-design culture across the business. Key responsibilities include: Driving application and product security initiatives across multiple engineering teams Conducting security reviews, threat modelling and risk assessments Implementing and improving vulnerability management processes Embedding security tooling into CI/CD pipelines and development workflows Partnering with developers … software development practices Experience working closely with software engineering teams Hands-on experience securing cloud environments (AWS, GCP or Azure) Experience with vulnerability management, threat modelling and security reviews Knowledge of CI/CD security and modern development practices Excellent stakeholder management and communication skills Eligibility Please note ...

Senior Technical Security Risk Consultant

Hiring Organisation
Sanderson Government and Defence
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£80,000
frameworks including ISO 27005 and NIST RMF Lead risk identification, assessment and treatment across applications, infrastructure and digital services Facilitate structured risk workshops and threat modelling sessions Assess solution architectures to identify security risks and control gaps Review and interpret IT Health Check outputs and define clear remediation … defence Proven ability to engage senior stakeholders and influence decisions Ability to translate technical findings into clear, actionable risk outcomes Confident leading risk workshops, threat modelling and control assessments Experience working within Agile delivery environments Strong analytical capability and sound judgement Any candidates must have an active ...

Security Architect

Hiring Organisation
CBSbutler Holdings Limited trading as CBSbutler
Location
Portsmouth, Hampshire, United Kingdom
Employment Type
Contract
Contract Rate
£600 - £650/day
covering DevSecOps, policy-as-code and secure CI/CD pipelines. Leading software supply chain security, including SBOMs, artefact signing and software provenance. Conducting threat modelling and security risk assessments. Chairing security working groups and collaborating with multinational stakeholders. Engaging with senior leadership to communicate security risks, assurance … environments. Strong background in cloud security architecture across multi-cloud and edge platforms. Experience implementing Secure by Design principles and DevSecOps practices. Expertise in: Threat modelling and risk management Policy-as-Code CI/CD security controls Software Supply Chain Security SBOMs, artefact signing and software provenance Excellent ...

Product Application Security Analyst

Hiring Organisation
Robert Walters
Location
Manchester, Lancashire, England, United Kingdom
Employment Type
Full-Time
Salary
£60,000 - £70,000 per annum
hands-on, advisory and governance-focused role designed to embed "security-by-design" into modern monolithic and microservice application architectures. You'll lead threat modelling, conduct technical risk assessments, evaluate third-party SaaS vendors, and translate complex risk into pragmatic guidance for engineering squads and business stakeholders. Partnering … product teams, acting as the technical security authority across monolithic and microservice application architectures. What the day-to-day looks like Security by Design: Threat modelling (STRIDE/OWASP) and setting security requirements early in the SDLC alongside dev squads Architectural Assurance: Advising engineering teams on cloud-native ...

Security Architect (Cloud)

Hiring Organisation
Addition
Location
Warrington, Cheshire, England, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £90,000 per annum
permanent) Industry: Technology/Regulated Services What You'll Be Doing Design secure cloud architectures across Azure, AWS and/or GCP environments. Conduct threat modelling and security risk assessments for cloud-based solutions. Produce high and low-level security designs aligned with business and regulatory requirements. Embed … Skills Needed Strong experience designing secure cloud solutions across IaaS, PaaS and SaaS. Knowledge of Azure, AWS or Google Cloud security services. Experience with threat modelling methodologies (STRIDE, MITRE ATT&CK etc.). Understanding of IAM, encryption, networking and cloud-native security controls. Knowledge of CIS, NIST, ISO27001 ...

Security Consultant

Hiring Organisation
Anson Mccade
Location
City of London, London, United Kingdom
Employment Type
Permanent
into complex IT and digital initiatives Advise clients on cyber risk, governance and regulatory compliance frameworks including: ISO 27001 NIST GDPR PCI-DSS Conduct threat modelling and identify security vulnerabilities within solution designs Recommend pragmatic risk mitigation strategies to technical and non-technical stakeholders Support the implementation … IDAM Privileged Access Management (PAM) Single Sign-On (SSO) Network Security Encryption technologies Understanding of infrastructure, architecture methodologies and secure design principles Experience with threat modelling and reference architecture development Excellent stakeholder engagement and communication skills Ability to learn quickly and adapt within fast-paced environments Desirable Experience ...

Cloud Security Consultant

Hiring Organisation
83zero Limited
Location
City of London, London, United Kingdom
Employment Type
Permanent, Work From Home
governance models Supporting the design and deployment of secure cloud infrastructure Embedding security throughout the cloud lifecycle using Secure by Design principles Conducting threat modelling and architecture reviews Working with cross-functional teams to integrate secure cloud solutions across hybrid IT environments Implementing security automation, orchestration and DevSecOps … Google Cloud Platform (GCP) Secure cloud governance and operating models DevSecOps, Infrastructure as Code (IaC) and CI/CD security Zero Trust security principles Threat modelling and security architecture reviews Cloud networking, identity and access management, application and data security Security automation and orchestration Relevant cloud security certifications ...

Principal Product Security Engineer

Hiring Organisation
Expleo Group
Location
Bristol, Avon, South West, United Kingdom
Employment Type
Permanent
networks, communications and mission-supporting systems. Provide security input into formal engineering design reviews, including SRR, PDR, CDR and equivalent programme governance gates. Conduct threat modelling and risk assessment activity across ship systems, platform services, navigation, propulsion, communications, IT, OT and associated support environments. Define and assure network … assurance or risk management frameworks. Experience supporting security accreditation, assurance, compliance or certification activities in a UK defence or similarly regulated environment. Experience conducting threat modelling, security risk assessment and security requirements definition. Experience supporting FAT, integration testing, harbour trials, sea trials, or equivalent technical acceptance activities from ...

Principal Product Security Engineer

Hiring Organisation
Jobleads-UK
Location
West of England, England, United Kingdom
networks, communications and mission‐supporting systems. Provide security input into formal engineering design reviews, including SRR, PDR, CDR and equivalent programme governance gates. Conduct threat modelling and risk assessment activity across ship systems, platform services, navigation, propulsion, communications, IT, OT and associated support environments. Define and assure network … assurance or risk management frameworks. Experience supporting security accreditation, assurance, compliance or certification activities in a UK defence or similarly regulated environment. Experience conducting threat modelling, security risk assessment and security requirements definition. Experience supporting FAT, integration testing, harbour trials, sea trials, or equivalent technical acceptance activities from ...

Cloud Security Consultant

Hiring Organisation
83zero Limited
Location
City of London, London, United Kingdom
Employment Type
Permanent, Work From Home
What You'll Be Doing Design secure architectures across AWS, Azure and hybrid cloud environments Develop cloud security strategies, governance and security standards Conduct threat modelling and security architecture reviews Embed security into cloud deployments through DevSecOps and automation Advise clients on best practice and modern cloud security … Looking For You'll have experience with several of the following: Cloud Security Architecture AWS, Azure and/or GCP Secure by Design & Threat Modelling Zero Trust principles DevSecOps & Infrastructure as Code Cloud Governance & IAM Relevant cloud security certifications (desirable) What's On Offer ...

Information Security Review, Threat Modelling Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Information Security or Information Technology. Strong experience reviewing infrastructure security. Hands‐on cloud security experience across AWS and/or GCP. Demonstrated expertise in Threat Modelling methodologies such as STRIDE, PASTA or MITRE ATT&CK/ATLAS. Strong understanding of authentication, authorisation, encryption, logging & monitoring, infrastructure security ...

Security Engineer

Hiring Organisation
Vallum Associates Limited
Location
Sheffield, South Yorkshire, Yorkshire, United Kingdom
Employment Type
Contract
Contract Rate
Up to £550 per day
certificate lifecycle services. Support cryptographic key management and certificate rotation processes. Perform security reviews of solution designs, infrastructure and application code. Conduct threat modelling and security risk assessments. Identify, assess and remediate security vulnerabilities. Support vulnerability management and security patching activities. Develop and maintain security baselines, standards … Management Secrets Management Cryptography Cloud Security (GCP) Kubernetes Security Service Mesh Security API Security Policy-as-Code (OPA) DevSecOps Secure Software Development Lifecycle (SSDLC) Threat Modelling Vulnerability Management Security Monitoring and SIEM Security Compliance and Governance Incident Response ...

Cyber Product Architect

Hiring Organisation
Experis
Location
City of London, London, United Kingdom
Employment Type
Contract
Contract Rate
£500 - £600/day
secure-by-design role spanning embedded, connected, cloud and software products, not tied to any single sector or regulatory framework. If you thrive on threat modelling, secure architecture and translating standards into practical controls, this one's for you. What you'll be doing: Designing, reviewing and documenting … product, system, application, cloud and infrastructure architectures, advising on IAM, authentication, cryptography, key management, network security, logging, monitoring and data protection. Leading and supporting threat modelling, attack surface analysis and risk assessments, including TARA to ISO/SAE 21434 , from item definition through to attack feasibility rating ...