About the Role
This role involves identifying potential threats, developing mitigation strategies, and delivering secure Python-based applications within a client engagement at Deloitte Operations. The specialist will collaborate with cross-functional teams and present findings to leadership.
Responsibilities
- Conduct threat modeling using documented processes such as STRIDE, PASTA, and Attack Trees.
- Develop and maintain automation tools to enhance threat identification and mitigation.
- Maintain high standards in identifying threats and specifying mitigating controls.
- Manage the lifecycle of identified threats and controls, ensuring timely delivery within set timeframes.
- Provide feedback and continuous improvements to the existing threat modeling process.
- Develop, test, and deploy secure Python-based applications adhering to established SDLC processes and quality standards.
- Collaborate with diverse teams, presenting work clearly and effectively.
Requirements
- Minimum of 6 years IT experience with at least 4 years in Cybersecurity or Information Security roles.
- Proven expertise in threat modeling methodologies (STRIDE, PASTA, Attack Trees, ATT&CK).
- Strong knowledge of vulnerability identification using CWE or OWASP standards.
- Hands-on experience with security practices including authentication, authorization, logging/monitoring, encryption, infrastructure security, and network segmentation.
- Proficiency in Python programming, including asynchronous programming and FastAPI framework.
- Experience with unit testing frameworks such as Pytest.
- Familiarity with development concepts like CICD, pipelines, SDLC, and Infrastructure as Code (Terraform, CloudFormation).
- Experience working in DevOps or agile team environments.
- Proficient with Jira or other ticketing systems.
- Strong analytical skills, attention to detail, and a problem-solving mindset.
- Experience with Docker, Kubernetes, serverless architectures, and Helm.
- Knowledge of Snowflake, MongoDB, Terraform Cloud, GitHub, and Databricks.
- Ability to design and review technical architectures.
- Experience supporting or performing penetration testing.
Skills
- Threat Modeling
- Cybersecurity
- Python
- STRIDE
- PASTA
- Attack Trees
- ATT&CK
- CWE
- OWASP
- Authentication
- Authorization
- Logging/Monitoring
- Encryption
- Infrastructure Security
- Network Segmentation
- Asynchronous Programming
- FastAPI
- Pytest
- CICD
- SDLC
- Infrastructure as Code
- Terraform
- CloudFormation
- DevOps
- Agile
- Jira
- Docker
- Kubernetes
- Serverless Architectures
- Helm
- Snowflake
- MongoDB
- Terraform Cloud
- GitHub
- Databricks
- Penetration Testing
Location
- London
Work Type
- Contract
- Inside IR35
Experience Level
- Minimum 6 years IT experience
- At least 4 years in Cybersecurity or Information Security roles
Education Level
- Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent work experience.
- Associate level cloud certification from AWS, GCP, or Azure.
- Associate or professional cybersecurity certification.
Salary/Compensations
- up to £450 daily rate
About the Company
- Deloitte Operations is engaging this role with one of their clients.
