Threat Modeler
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+21 more
Job description
Ensure all software platforms adhere to Citi’s security standards and Software Development Life Cycle (SDLC) processes (must have). Identifying vulnerabilities using CWE or OWASP. Operating systems and their hardening. Development concepts (such as: CICD, Pipelines, SDLC). Cloud Development Kit (CDK), GitOps. Operating in a DevOps / agile team structure. Understanding of docker/K8S/serverless/helm. Support or perform pen testing. Snowflake/MongoDB/Terraform Cloud/GitHub/Databricks. Karat Assessment (Python focus) is required for consideration. Roles & Responsibilities Threat Modeling using a documented process. Development of automation tools as required. Maintain a high standard of work in identifying threats and specifying mitigating controls. Attending to the lifecycle of identified threats and controls. Delivery of threat models and supporting tasks within existing timeframes. Provide feedback, support, and improvements to the existing threat modeling process. Present work to seniors, the team, and other technical teams. Work with little supervision to complete work Develop, test, and deploy secure and efficient Python-based applications, adhering to established SDLC processes and quality standards., Overview: Are you an experienced construction modeler with expertise in Trimble Business Center (TBC) and heavy civil construction workflows that include machine control? As a Ge…
- 1 month ago, About Us: We design, install, and maintain advanced electrical systems. Our expertise spans traditional electrical contracting, security solutions, audio-visual integration, wire…
- 1 month ago
Requirements
Technical skills Expected to have two to five years of experience in several of the following: IT experience minimum of 6 years with minimum of 4 years Cybersecurity/Information Security must have. Threat Modeling (STRIDE, PASTA, Attack trees, tooling, Att&ck) must have demonstrated experience. Experience working in a cybersecurity role must have. Security practices pertaining to authentication, authorization, logging/monitoring, encryption, infrastructure security, network/segmentation must have. Scripting languages, Infrastructure as Code (Terraform, CloudFormation) must have. Jira or other ticketing systems must have. Design and review technical architectures must have. Strong proficiency in Programming Languages, with a preference for Python (asynchronous programming), and FastAPI (must have). Unit Testing: Developing and executing unit tests using frameworks like Pytest to ensure code quality (must have).
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Understanding and Mitigating Common Web Vulnerabilities
9 Ways to Make Money Hacking