โšก New

Cyber Security Analyst

Damia Group

LondonFull-timeMid LevelOn-site

Job Description

Threat Modelling Engineer

Location: London

Working Pattern: 4 days onsite / 1 day remote

Contract: Initial 6-month contract

Rate: ยฃ400 - ยฃ500 per day


Damia Group is supporting a leading organisation in the delivery of a high-profile Cyber Security programme and is looking for an experienced Senior Threat Modelling Engineer to join the team in London.


You will play a key role in identifying and assessing security threats, defining appropriate mitigating controls, and helping to continuously improve the organisation's threat modelling capability.

This is a hands-on position combining Threat Modelling, Cyber Security, Cloud Security and Python development, with responsibility for delivering high-quality threat models while also supporting and mentoring more junior members of the team.


Key Responsibilities

  • Conduct Threat Modelling using established and documented methodologies.
  • Apply techniques including STRIDE, PASTA, Attack Trees and MITRE ATT&CK to identify and assess threats.
  • Identify vulnerabilities using frameworks such as CWE and OWASP.
  • Define, document and maintain appropriate security controls and mitigations.
  • Manage the lifecycle of identified threats and associated controls.
  • Deliver threat models and supporting activities within agreed timelines.
  • Develop automation tools and solutions to improve the threat modelling process.
  • Develop, test and deploy secure and efficient Python-based applications in line with established SDLC processes and quality standards.
  • Contribute to the continuous improvement of existing threat modelling processes and methodologies.
  • Present threat modelling outputs and recommendations to senior stakeholders, technical teams and wider audiences.
  • Support and mentor junior members of the team.
  • Supervise and provide technical guidance to less experienced team members.
  • Take responsibility for elements of the threat modelling service.
  • Work independently with minimal supervision while maintaining a consistently high standard of delivery.
  • Collaborate with engineering, architecture, DevOps and Cyber Security teams.
  • Support or participate in penetration testing activities where required.
  • Design and review technical architectures from a security perspective.


Essential Technical Skills & Experience

You should have 6+ years of overall IT experience, including a minimum of 4 years within Cyber Security / Information Security.

Strong experience in several of the following is required:

  • Threat Modelling โ€“ essential, including STRIDE, PASTA, Attack Trees, tooling and MITRE ATT&CK.
  • Professional experience working within a Cyber Security / Information Security role โ€“ essential.
  • Identifying vulnerabilities using CWE and OWASP.
  • Security principles covering:
  • Authentication and authorisation
  • Logging and monitoring
  • Encryption
  • Infrastructure security
  • Network security and segmentation
  • Operating systems and security hardening.
  • Software development concepts including CI/CD, pipelines and SDLC.
  • Scripting and Infrastructure as Code, including Terraform and CloudFormation.
  • Cloud Development Kit (CDK) and GitOps.
  • Experience working within DevOps and Agile environments.
  • Jira or similar ticketing/workflow platforms.
  • Docker, Kubernetes, Serverless and Helm โ€“ essential.
  • Cloud security and secure cloud architecture.
  • Technical architecture design and review.
  • Strong programming skills, particularly Python, including asynchronous programming.
  • FastAPI โ€“ essential.
  • Pytest / unit testing โ€“ essential.
  • Experience developing and maintaining software in line with security standards and SDLC processes.
  • Experience with technologies such as Snowflake, MongoDB, Terraform Cloud, GitHub and Databricks would be advantageous.


Key Attributes

We're looking for someone who demonstrates:

  • Strong analytical skills and exceptional attention to detail.
  • An adversarial mindset and the ability to think like an attacker.
  • A proactive approach to research, particularly using vendor documentation and technical resources.
  • Strong documentation and technical writing skills.
  • Experience working within regulated environments.
  • A genuine interest in emerging technologies, security methodologies and industry developments.
  • Strong problem-solving and critical-thinking skills.
  • Excellent communication and collaboration skills.
  • The ability to build effective relationships across technical and non-technical teams.
  • Confidence presenting technical findings to senior stakeholders.
  • A willingness to mentor, support and develop other members of the team.


This is an opportunity to work on a technically challenging Cyber Security programme where you will have significant responsibility across Threat Modelling, Cloud Security, Secure Development and Cyber Security architecture.


Posted Today

Related Jobs

Related Searches

Apply Now