HomeSearchSecurity Engineer Jobs › Contract - Cyber Security Engineer (Threat Modelling)

Contract - Cyber Security Engineer (Threat Modelling)

Deloitte

City of Westminster, Greater London, GB
More Security Engineer jobs: Security Engineer jobsSecurity Engineer salary

Job at a glance

City of Westminster, Greater London, GB
Location
Deloitte
Employer
Security Engineer jobs
Category

We are looking for an experienced Threat Modelling Security Engineer to identify security threats, define effective mitigating controls and manage findings throughout their lifecycle. You will deliver threat models to agreed timeframes, develop secure Python-based automation and help improve the existing threat modelling service. The role involves presenting technical work to senior and cross-functional stakeholders, while training and supervising junior team members.

You will work with minimal supervision across cloud, DevOps and regulated security environments., 1. Threat Modeling using a documented process. 2. Development of automation tools as required. 3. Maintain a high standard of work in identifying threats and specifying mitigating controls. 4. Attending to the lifecycle of identified threats and controls. 5. Delivery of threat models and supporting tasks within existing timeframes.

6. Provide feedback, support, and improvements to the existing threat modeling process. 7. Present work to seniors, the team, and other technical teams. 8. Train newer members of the team 9. Supervise junior members of the team 10. Run parts of our threat model service 11. Work with little supervision to complete work 12. Develop, test, and deploy secure and efficient Python-based applications, adhering to established SDLC processes and quality standards.

An experienced IT professional with cyber security or information security experience Technical expertise with threat modelling using STRIDE, PASTA, attack trees, tooling and MITRE ATT&CK. Cyber security experience covering authentication, authorisation, logging and monitoring, encryption, infrastructure security and network segmentation. Development and DevOps knowledge, including CI/CD, pipelines, SDLC, scripting, Infrastructure as Code (Terraform or CloudFormation), Docker, Kubernetes (K8s), serverless and Helm.

Strong programming capability, preferably Python including asynchronous programming and FastAPI, plus unit testing with Pytest. Experience applying security standards and SDLC controls to software platforms. Experience identifying vulnerabilities using CWE or OWASP, hardening operating systems, and designing or reviewing technical architectures. Working knowledge of agile/DevOps delivery, Jira, CDK/GitOps, penetration testing and technologies such as Snowflake, MongoDB, Terraform Cloud, GitHub or Databricks.

Analytical and adversarial mindset, attention to detail, problem-solving ability and a commitment to continuous learning. Strong documentation, research, communication and collaboration skills, with experience building relationships across diverse teams in a regulated environment. Desirable - Professional-level cloud certification, vendor cloud security certification and professional cyber security certification from either AWS, CGP or Azure As a means of managing tax, commercial and reputational risks, Deloitte prohibits the use of Associates through Personal Service Companies ('PSCs').

All Associates must contract under PAYE arrangements through a Deloitte approved 'Employment Company' (aka 'umbrella company.')

Search all live jobs — free, no account →