Job Title: Senior Threat Modeler (contract)
Location: London Hybrid, 2-3 days a week in the London office
Duration: 4 months
Contract Start Date: ASAP
Day Rate: Competitive (Inside IR35)
Deloitte
Working with the Deloitte Associate (Contractor) Programme means we can offer you the opportunity to work on a variation of industry and client related projects. Our aim is to retain the best talent and so when your project end date nears our team of Talent Community Advisors will be working with you to look at alternative projects within the firm that suit your experience should you wish to continue with Deloitte.
The Role
We are looking for an experienced Threat Modelling Security Engineer to identify security threats, define effective mitigating controls and manage findings throughout their lifecycle. You will deliver threat models to agreed timeframes, develop secure Python-based automation and help improve the existing threat modelling service. The role involves presenting technical work to senior and cross-functional stakeholders, while training and supervising junior team members. You will work with minimal supervision across cloud, DevOps and regulated security environments.
Essential Skills and Experience
- An experienced IT professional with cyber security or information security experience
- Technical expertise with threat modelling using STRIDE, PASTA, attack trees, tooling and MITRE ATT&CK.
- Cyber security experience covering authentication, authorisation, logging and monitoring, encryption, infrastructure security and network segmentation.
- Development and DevOps knowledge, including CI/CD, pipelines, SDLC, scripting, Infrastructure as Code (Terraform or CloudFormation), Docker, Kubernetes (K8s), serverless and Helm.
- Strong programming capability, preferably Python including asynchronous programming and FastAPI, plus unit testing with Pytest.
- Experience applying security standards and SDLC controls to software platforms.
- Experience identifying vulnerabilities using CWE or OWASP, hardening operating systems, and designing or reviewing technical architectures.
- Working knowledge of agile/DevOps delivery, Jira, CDK/GitOps, penetration testing and technologies such as Snowflake, MongoDB, Terraform Cloud, GitHub or Databricks.
- Analytical and adversarial mindset, attention to detail, problem-solving ability and a commitment to continuous learning.
- Strong documentation, research, communication and collaboration skills, with experience building relationships across diverse teams in a regulated environment.
- Desirable - Professional-level cloud certification, vendor cloud security certification and professional cyber security certification from either AWS, CGP or Azure
Deliverables: Responsibilities but not limited to:
- Threat Modeling using a documented process.
- Development of automation tools as required.
- Maintain a high standard of work in identifying threats and specifying mitigating controls.
- Attending to the lifecycle of identified threats and controls.
- Delivery of threat models and supporting tasks within existing timeframes.
- Provide feedback, support, and improvements to the existing threat modeling process.
- Present work to seniors, the team, and other technical teams.
- Train newer members of the team
- Supervise junior members of the team
- Run parts of our threat model service
- Work with little supervision to complete work
- Develop, test, and deploy secure and efficient Python-based applications, adhering to established SDLC processes and quality standards.
IR35
As a means of managing tax, commercial and reputational risks, Deloitte prohibits the use of Associates through Personal Service Companies (‘PSCs’). All Associates must contract under PAYE arrangements through a Deloitte approved ‘Employment Company’ (aka ‘umbrella company.’)