> Markdown version of [/jobs/ext/1531449-lead-threat-modeling-architect](https://www.wearedevelopers.com/jobs/ext/1531449-lead-threat-modeling-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Threat Modeling Architect - **Company:** Lenovo - **Location:** Morrisville, NC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Mobile Application Software, Release Management, Secure Coding, Smart Devices, Software Engineering, Web Applications, Devsecops - **Published:** July 2, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/9208760?backUrl=%2Fcareer%2F9208760%2FLead-Threat-Modeling-Architect-North-Carolina-Raleigh ## About the Role * Bachelor's degree or above in cyber security or a related discipline. * 3+ years of experience creating, maintaining and reviewing threat models for application development teams, leading threat modeling activities. * 3+ years experience in Security Architecture assessments of all types * 3+ years experience with threat modeling practices, tools and techniques. Preferred Qualifications: * 7+ years of experience creating, maintaining and reviewing threat models for application development teams, leading threat modeling activities. * In-depth knowledge of security concepts and design techniques relating to cloud/web application, IOT, client and mobile applications * Proficiency in software development practices, release planning, and quality assurance. * Proficient in STRIDE analysis method. * Expert-level skills with the Threat Modeler Tool. * Practical experience in Secure Development Lifecycle, DevSecOps. * Familiarity with security and privacy frameworks, standards and regulations like GDPR, CCPA, CSA STAR, ISO 27000 series, NIST, etc. * Strong learning ability, strong self-drive, good adaptability and passion for security. * Strong communication skills in English * Multiple Industry security certifications such as CISSP, CCSLP, SANS-GGWEB ( or other SANS certs) desired. * Mandarin and English Fluency ## Description We are searching for a Lead Threat Modeling Architect in the Security Center of Excellence for PC and Smart Devices business (PCSD). This is an exciting role where you will be leading the Threat Modeling team that supports our global development teams. You will be working alongside some of the best security teams in the industry. What You'll Do * Leads threat modeling training, workshops, and collaborative sessions for a wide array of products and services. * Partner with multiple international development teams across business units gaining in-depth knowledge of many products in order to design threat models and security architecture solutions for them in order to reduce the attack surface and lower the risk profiles of our products. * Lead training for global development teams related to threat modeling techniques and our threat modeling tools so that they become partners with the security organization to create, review and maintain threat models for products. * Champion threat modeling practices within the development teams, promoting best industry practices. * Develop meaningful metrics for threat modeling and use them to track improvements made to the cybersecurity posture of our product lines. * Remain current in the latest security technologies, methodologies and best practices, especially as it relates to threat modeling. ## Related Videos - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Welcome to Switzerland](https://www.wearedevelopers.com/magazine/4-welcome-to-switzerland) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)