Senior Engineer Threat Modeling
Listed on 2026-06-07
-
IT/Tech
Cybersecurity, Systems Engineer
5 days ago Be among the first 25 applicants
This range is provided by Synergy Interactive. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.
Base pay range$/yr - $/yr
About the RoleWe are seeking a talented Senior Engineer - Threat Modeling to join our dynamic, cross‑functional team. In this role, you will be focused on Security Architecture and Threat Modeling, collaborating with engineering, information security, and development teams to deliver digital business transformation solutions for our clients. Your expertise will be crucial in evaluating public cloud services, conducting security reviews, and pinpointing security opportunities in cloud architectures.
You will play a key role in identifying potential threats, recommending mitigation strategies, and continuously improving our security processes.
- Conduct in-depth threat modeling exercises using established methodologies (e.g., MITRE ATT&CK, STRIDE, PASTA).
- Maintain a high standard of excellence in identifying and mitigating potential security threats.
- Manage the lifecycle of identified threats and associated controls, ensuring regular updates and improvements.
- Deliver comprehensive threat models and related deliverables within established time frames.
- Offer constructive feedback on existing threat modeling processes and propose improvements.
- Present findings and progress updates to senior leadership and relevant technical stakeholders.
We’re looking for someone with 8+ years of experience in the following areas:
- Proficiency in GCP (essential).
- Security architecture
:
Strong knowledge of security principles, frameworks, and best practices. - Threat modeling methodologies
:
Experience with MITRE ATT&CK, STRIDE, PASTA, etc. - Cybersecurity experience
: 5+ years of practical experience. - Security practices
:
Experience in authentication, authorization, logging/monitoring, encryption, infrastructure security, and network segmentation. - API Knowledge
:
Strong understanding of Rest API security. - Scripting/Automation
:
Familiar with Terraform, Cloud Formation, and Infrastructure as Code. - Collaboration tools
:
Proficiency in Jira or other ticketing systems. - Technical architecture
:
Strong skills in designing and reviewing security architecture. - Vulnerability Identification
:
Experience using CWE, OWASP to identify and remediate security risks. - Operating systems
:
In-depth knowledge of hardening techniques. - Development and Dev Ops
:
Understanding of SDLC, CICD pipelines, and Dev Ops practices. - Penetration Testing
:
Familiarity with penetration testing methods is an added advantage. - Cloud Platforms
:
Hands‑on experience with Snowflake, Mongo
DB, Terraform Cloud, Git Hub, Databricks. - Analytical skills
:
Strong attention to detail and critical thinking ability. - Research Skills
:
Comfortable with vendor documentation and research for security solutions. - Documentation
:
Experience in creating high‑quality technical documentation. - Adversary Mindset
:
Ability to think from an attacker’s perspective to find weaknesses. - Continuous Learning
: A proactive attitude towards learning new technologies and security methodologies. - Collaboration
:
Excellent communication skills and the ability to work across teams.
- Professional Security Certifications
: CISSP, CCSP, CISA, CISM, ITIL. - GCP Certifications
: GCP Professional Cloud Architect, GCP Professional Cloud Security Engineer are highly desirable. - Industry Standards Knowledge
:
Familiarity with ISO, NIST, CSA, and cloud security standards. - Hands‑on Cloud Security Design
:
Experience with security design on GCP or similar cloud platforms. - Regulated Environments
:
Experience working in highly regulated industries. - Other Cloud Providers
:
Experience with AWS, Azure, or similar CSPs. - Development Experience
:
Familiarity with Python or Node.js. - Agile/Dev Ops/Sec Ops
:
Exposure to agile development and scrum practices. - Strong Desire to Learn
: A passion for continuous improvement and contributing to team solutions.
Mid‑Senior level
Employment typeFull‑time
Job functionEngineering and Analyst
IndustriesFinancial Services, IT Services and IT Consulting, and Business Consulting and Services
Referrals increase your chances of interviewing at Synergy Interactive by 2x
Apply BELOW
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).