Senior Threat Modeler

@ Long Finch Technologies
Long Finch Technologieslongfinchtechnologies.com

Senior Threat Modeler

Bedford, Texas
Posted 3 days ago

About the job

The company specializes in cybersecurity and risk management services. The role involves threat modeling, developing security tools, and ensuring compliance with security standards. Candidates should have extensive cybersecurity experience and strong scripting skills, working in an agile environment.

Requirements

  • Threat modeling experience (STRIDE, PASTA)
  • Scripting languages (Python, FastAPI)
  • Cybersecurity and cloud security knowledge
  • Experience with CI/CD, SDLC, Infrastructure as Code
  • Strong problem-solving skills

Qualifications

  • 2-5 years related experience
  • Minimum 6 years IT experience
  • Proficient in Python and FastAPI
  • Knowledge of security standards (OWASP, CWE)
  • Experience with DevOps and cloud platforms

Full job description

Technical skills
  • Expected to have two to five years of experience in several of the following:
  • IT experience minimum of 6 years with minimum of 4 years Cybersecurity/Information Security – must have.
  • Threat Modeling (STRIDE, PASTA, Attack trees, tooling, Att&ck) – must have demonstrated experience.
  • Experience working in a cybersecurity role – must have.
  • Security practices pertaining to authentication, authorization, logging/monitoring, encryption, infrastructure security, network/segmentation – must have.
  • Scripting languages, Infrastructure as Code (Terraform, CloudFormation) – must have.
  • Jira or other ticketing systems – must have.
  • Design and review technical architectures – must have.
  • Strong proficiency in Programming Languages, with a preference for Python (asynchronous programming), and FastAPI (must have).
  • Unit Testing: Developing and executing unit tests using frameworks like Pytest to ensure code quality (must have).
  • Ensure all software platforms adhere to Citi's security standards and Software Development Life Cycle (SDLC) processes (must have).
  • Identifying vulnerabilities using CWE or OWASP.
  • Operating systems and their hardening.
  • Development concepts (such as: CICD, Pipelines, SDLC).
  • Cloud Development Kit (CDK), GitOps.
  • Operating in a DevOps / agile team structure.
  • Understanding of docker/K8S/serverless/helm.
  • Support or perform pen testing.
  • Snowflake/MongoDB/Terraform Cloud/GitHub/Databricks.
  • Karat Assessment (Python focus) is required for consideration.
Roles & Responsibilities
  • Threat Modeling using a documented process.
  • Development of automation tools as required.
  • Maintain a high standard of work in identifying threats and specifying mitigating controls.
  • Attending to the lifecycle of identified threats and controls.
  • Delivery of threat models and supporting tasks within existing timeframes.
  • Provide feedback, support, and improvements to the existing threat modeling process.
  • Present work to seniors, the team, and other technical teams.
  • Work with little supervision to complete work.
  • Develop, test, and deploy secure and efficient Python-based applications, adhering to established SDLC processes and quality standards.
Show full description