Principal Threat Modeling Architect
Listed on 2026-07-18
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, Systems Engineer, IT Consultant
Who We Are Looking For
We are looking for a Principal Threat Modeling Architect
. You will be responsible for leading the enterprise Threat Modeling program, establishing threat modeling standards, methodologies, and governance, and building a high‑performing team of threat modeling professionals. You will partner with application development, cloud engineering, cybersecurity, and business stakeholders to proactively identify and mitigate security risks across the software development lifecycle, cloud environments, and emerging technology initiatives.
The team you will be joining is part of the Security Architecture organization, a function that is critical to the firm’s ability to design and deliver secure technology solutions. As cyber threats continue to evolve, threat modeling serves as a foundational security practice that enables the organization to identify architectural weaknesses early, reduce risk, strengthen security‑by‑design practices, and improve the resilience of applications, cloud platforms, and critical business services.
WhatYou Will Be Responsible For
As a Principal Threat Modeling Architect
, you will:
- Lead and mature the enterprise Threat Modeling program, including methodologies, standards, tooling, governance, and metrics.
- Build, lead, and mentor a team of threat modelers responsible for conducting threat assessments across enterprise applications, cloud platforms, APIs, and emerging technologies.
- Partner with Security Architecture, Application Security, Cloud Security, Engineering, and Development teams to embed threat modeling throughout the software development lifecycle.
- Conduct and oversee threat modeling exercises for critical business applications, cloud‑native services, AI solutions, and strategic transformation initiatives.
- Define actionable risk mitigation strategies and architectural recommendations to address identified threats and security weaknesses.
- Establish security architecture patterns, guidance, and best practices related to application security, cloud security, and secure‑by‑design principles.
- Drive adoption of automated and scalable threat modeling capabilities while measuring program effectiveness through meaningful metrics and reporting.
- Evaluate emerging threats, attack techniques, and technology trends to continuously enhance the firm’s threat modeling capabilities.
These skills will help you succeed in this role:
- Deep expertise in threat modeling methodologies such as STRIDE, MITRE ATT&CK, Kill Chain, attack trees, and risk‑based security analysis.
- Strong application security and cloud security experience, including modern cloud‑native architectures, APIs, containers, microservices, and Dev Sec Ops practices.
- Proven leadership experience building, mentoring, and leading highly skilled technical teams.
- Strong communication, stakeholder management, and executive presentation skills with the ability to influence strategic technology decisions.
- Ability to translate complex technical risks into practical, business‑aligned security recommendations.
- Proven ability to successfully drive and develop teams that work remotely and across multiple geographic time zones.
Preferred Qualifications
- Degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline.
- 13 years or more of experience leading large‑scale application security, cloud security, threat modeling, security architecture, or cybersecurity transformation initiatives in complex, global environments, with at least 8 years of cybersecurity leadership experience preferred.
- Demonstrated experience leading enterprise threat modeling, application security, or secure architecture programs.
- Deep understanding of secure software development, application security testing, cloud security architecture, and secure design principles.
- Experience securing cloud platforms such as AWS, Azure, and Google Cloud.
- Knowledge of software development frameworks, APIs, microservices, containers, Kubernetes, CI/CD pipelines, and Dev Sec Ops practices.
- Experience with threat modeling tools and frameworks.
- Professional certifications such as CISSP,…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: