About the Role
This role involves Threat Modeling using a documented process, developing automation tools, and maintaining a high standard of work in identifying threats and specifying mitigating controls. The position requires attending to the lifecycle of identified threats and controls, delivering threat models within existing timeframes, and providing feedback for process improvements. The individual will work with little supervision and present their work to seniors and technical teams.
Responsibilities
- Threat Modeling using a documented process.
- Development of automation tools as required.
- Maintain a high standard of work in identifying threats and specifying mitigating controls.
- Attending to the lifecycle of identified threats and controls.
- Delivery of threat models and supporting tasks within existing timeframes.
- Provide feedback, support, and improvements to the existing threat modeling process.
- Present work to seniors, the team, and other technical teams.
- Work with little supervision to complete work.
- Develop, test, and deploy secure and efficient Python-based applications, adhering to established SDLC processes and quality standards.
Requirements
- Minimum of 6 years IT experience with minimum of 4 years Cyber-Security/Information Security.
- Proficiency in Threat Modeling (STRIDE, PASTA, Attack trees, tooling, Att&ck).
- Experience identifying vulnerabilities using CWE or OWASP.
- Experience working in a cyber-security role.
- Knowledge of security practices pertaining to authentication, authorization, logging/monitoring, encryption, infrastructure security, network/segmentation.
- Understanding of operating systems and their hardening.
- Familiarity with development concepts (such as: CICD, Pipelines, SDLC).
- Experience with scripting languages and Infrastructure as Code (Terraform, CloudFormation).
- Experience with Cloud Development Kit (CDK), GitOps.
- Experience operating in a DevOps / agile team structure.
- Experience with Jira or other ticketing systems.
- Understanding of docker/K8S/serverless/helm.
- Experience supporting or performing pen testing.
- Experience with Snowflake/MongoDB/Terraform Cloud/GitHub/Databricks.
- Ability to design and review technical architectures.
- Strong proficiency in Programming Languages, with a preference for Python (asynchronous programming), and FastAPI.
- Experience developing and executing unit tests using frameworks like Pytest to ensure code quality.
- Ability to ensure all software platforms adhere to the clients security standards and Software Development Life Cycle (SDLC) processes.
- Analytical, diligence and attention to detail.
- Eagerness to research using vendor documentation.
- Ability to create and maintain quality documentation.
- Experience of regulated environment.
- Adversary mindset.
- Ability to work with diverse set of people and teams.
- Constant learner of new technologies and methodologies.
- Problem solver.
- Communication and collaboration skills.
- Builder of relationships across cross-functional teams.
Skills
- Threat Modeling
- STRIDE
- PASTA
- Attack trees
- Att&ck
- CWE
- OWASP
- Cyber-Security
- Information Security
- Authentication
- Authorization
- Logging/Monitoring
- Encryption
- Infrastructure Security
- Network/Segmentation
- Operating Systems Hardening
- CICD
- Pipelines
- SDLC
- Python
- FastAPI
- Pytest
- Scripting Languages
- Infrastructure as Code
- Terraform
- CloudFormation
- Cloud Development Kit (CDK)
- GitOps
- DevOps
- Agile
- Jira
- Docker
- K8S
- Serverless
- Helm
- Pen Testing
- Snowflake
- MongoDB
- Terraform Cloud
- GitHub
- Databricks
- Technical Architecture Design
- Asynchronous Programming
- Unit Testing
- Analytical Skills
- Attention to Detail
- Documentation
- Regulated Environment Experience
- Problem Solving
- Communication
- Collaboration
Location
- London
- Belfast
Work Type
- 6 Months
- Inside IR35
Experience Level
- Two to five years of experience in several of the following
- Minimum of 6 years IT experience
- Minimum of 4 years Cyber-Security/Information Security
Education Level
- Associate level cloud certification (AWS, GCP or Azure)
- Associate or professional cyber-security certification
- Bachelor's degree in computer related field or equivalent work experience
Salary/Compensations
- Competitive Day Rate
