> Markdown version of [/jobs/ext/1144217-cybersecurity-analyst-threat-modeling-security-testing](https://www.wearedevelopers.com/jobs/ext/1144217-cybersecurity-analyst-threat-modeling-security-testing). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst- Threat Modeling & Security Testing - **Company:** Inframia, L.L.C. - **Location:** United States (Remote available) - **Salary:** $104,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Software Security, Mitre Att&ck, Service Stack - **Published:** July 2, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=375055f55a2fe211 ## About the Role * 4+ years of experience in threat modeling, security testing, application security, infrastructure security, security engineering, or related disciplines. * Knowledge of threat modeling frameworks. * Experience conducting structured threat modeling exercises for applications, platforms, or infrastructure environments. * Experience with application and infrastructure security testing. * Ability to simulate attacker scenarios and identify weaknesses, exploitation paths, or control gaps. * Ability to document findings and provide actionable recommendations for risk mitigation. * Experience supporting large, complex enterprise environments. * Client-facing advisory experience. * Ability to operate across multiple industries and technology stacks. * Experience supporting continuous improvement of threat modeling or security testing methodologies. * Experience translating technical findings into practical remediation guidance. * Strong analytical, documentation, presentation, advisory, and stakeholder communication skills., * Applications and Infrastructure Security Testing: 5 years (Required) * Structured Threat Modeling: 3 years (Required) * Big 4 Consulting: 1 year (Preferred) * Attacker Simulation or Exploitation Analysis: 3 years (Required) ## Description We are seeking a Threat Modeling & Security Testing Specialist to provide advisory and execution support for proactive threat identification, structured threat modeling, and security testing. This role helps clients identify attack paths, validate control effectiveness, document security weaknesses, and provide actionable recommendations to reduce risk across applications, platforms, infrastructure, and enterprise technology environments., * Conduct structured threat modeling exercises for applications, platforms, infrastructure environments, and related systems. * Apply threat modeling methods such as STRIDE, MITRE ATT&CK, or similar frameworks to identify likely threats, weaknesses, and attack paths. * Execute and support security testing activities to validate security control effectiveness. * Simulate attacker scenarios to identify exploitation paths, control gaps, and potential risk exposures. * Assess application and infrastructure security controls for design weaknesses, implementation gaps, and exploitable conditions. * Document threat scenarios, findings, testing results, security weaknesses, and recommended mitigation actions. * Collaborate with engineering, infrastructure, application, and security teams to advise on remediation strategies. * Support continuous improvement of threat modeling methods, testing procedures, security testing playbooks, and advisory deliverables. * Communicate findings and recommendations clearly to technical and non-technical stakeholders. ## Related Videos - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) - [Introducing a Digital Service Catalog for speed and scale](https://www.wearedevelopers.com/videos/763-introducing-a-digital-service-catalog-for-speed-and-scale) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Building high performance and scalable architectures for enterprises](https://www.wearedevelopers.com/videos/19-building-high-performance-and-scalable-architectures-for-enterprises) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)