> Markdown version of [/jobs/ext/1249623-threat-modeler](https://www.wearedevelopers.com/jobs/ext/1249623-threat-modeler). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Threat Modeler - **Company:** State Street - **Location:** Quincy, MA, United States - **Experience:** Expert - **Salary:** $90,000.0 - $157,500.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Architectural Patterns, Microsoft Azure, Cloud Computing Security, Cloud Engineering, Cyber Security, Information Systems Security Architecture Professional, Open Web Application Security, Cloud Services, Software Engineering, Data Streaming, Google Cloud, Enterprise Software Applications, Cloud Platform System, Software Security, Mitre Att&ck, Containerization, Kubernetes, Information Technology, Devsecops, Microservices - **Published:** July 12, 2026 - **Apply:** https://www.jofdav.com/jobs/58801544-threat-modeler ## About the Role * Strong analytical, problem-solving, and critical-thinking skills. * Knowledge of application security, cloud security, and secure software development principles. * Understanding of modern architectures including APIs, microservices, containers, and cloud-native technologies. * Strong communication and collaboration skills with technical and non-technical stakeholders. * Willingness to learn, adapt, and develop expertise in threat modeling and security architecture., * Degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline. * 10 years or more of experience in application security, cloud security, cybersecurity architecture, threat modeling, or related technology disciplines, with at least 5 years of hands-on cybersecurity experience preferred. * Familiarity with threat modeling methodologies such as STRIDE, MITRE ATT&CK, attack trees, or similar security assessment techniques. * Understanding of secure software development practices, OWASP Top 10, API security, and cloud security fundamentals. * Experience with AWS, Azure, and/or Google Cloud platforms is preferred. * Knowledge of DevSecOps, CI/CD pipelines, containers, Kubernetes, or modern application architectures is desirable. * Security certifications such as Security+, SSCP, CCSK, AWS Cloud Practitioner, Azure Fundamentals, or equivalent certifications are a plus. Additional Requirements * Strong desire to build expertise in threat modeling, application security, and cloud security. * Ability to work effectively in a collaborative, global team environment. * Limited travel may be required based on business needs. ## Description We are looking for a Threat Modeler. You will be responsible for supporting threat modeling activities across enterprise applications, cloud platforms, APIs, and emerging technologies. Working closely with architects, engineers, developers, and cybersecurity teams, you will help identify security risks early in the technology lifecycle and contribute to secure-by-design initiatives across the organization. Why This Role Is Important To Us The team you will be joining is part of the Security Architecture organization, a function that is critical to safeguarding the firm's applications, cloud environments, data, and technology services. Threat modeling enables the organization to proactively identify security weaknesses, reduce cyber risk, and incorporate security requirements into technology solutions before they are deployed. What You Will Be Responsible For As a Threat Modeler, you will: * Participate in threat modeling assessments for applications, APIs, cloud platforms, and technology initiatives. * Analyze application architectures, data flows, trust boundaries, and cloud deployments to identify potential threats and security weaknesses. * Support the development of risk mitigation recommendations and secure design guidance. * Collaborate with application development, cloud engineering, and cybersecurity teams to improve security outcomes. * Contribute to threat modeling standards, reusable patterns, documentation, and security awareness initiatives. ## Related Videos - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)