🔐 Threat Modeler (Cloud / DevSecOps)
📍 Irving, TX (preferred) | Jacksonville, FL (secondary)
💼 Full-time | Hybrid
We’re working on a genuinely strong opportunity for a Threat Modeler to join a high-performing security function operating across modern cloud and DevSecOps environments.
This isn’t a tick-box security role. You’ll be embedded with engineering teams, influencing architecture, identifying real-world threats, and shaping how security is built into systems from the ground up.
🚀 What you’ll be doing
- Lead threat modelling activities using structured methodologies (STRIDE, PASTA, ATT&CK)
- Work closely with engineering and architecture teams to identify risks and define mitigations
- Review cloud-native architectures and embed security into the SDLC
- Own the lifecycle of threats, from identification through to resolution
- Build and improve threat modelling processes, tooling, and automation
- Present findings to technical stakeholders and senior teams
🧠 What we’re looking for
- Strong experience in Threat Modelling (STRIDE, PASTA, Attack Trees, MITRE ATT&CK)
- Background in Cyber Security / Information Security (4+ years)
- Experience identifying vulnerabilities using OWASP / CWE
- Solid understanding of authentication, encryption, logging, and infrastructure security
- Exposure to cloud environments (AWS, Azure, or GCP)
- Familiarity with DevOps / SDLC / CI/CD pipelines
- Experience with Infrastructure as Code (Terraform, CloudFormation) or container platforms (Docker/Kubernetes)
- Ability to review and influence technical architecture
💡 Nice to have
- Cloud certifications (AWS / Azure / GCP)
- Security certifications (CISA, CySA+, GSEC, SSCP etc.)
- Experience with modern data platforms (Snowflake, Databricks, MongoDB)
🤝 Why it’s worth a conversation
- Proper hands-on threat modelling role (not just governance)
- High visibility across engineering and architecture teams
- Work on modern cloud and distributed systems
- Opportunity to shape and improve how security is done
If you’re working in AppSec, Cloud Security, or DevSecOps and have real exposure to threat modelling, this is well worth a look.