> Markdown version of [/jobs/ext/2838034-contract-cyber-security-engineer-threat-modelling](https://www.wearedevelopers.com/jobs/ext/2838034-contract-cyber-security-engineer-threat-modelling). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Contract - Cyber Security Engineer (Threat Modelling) - **Company:** Deloitte - **Location:** London, UK - **Contract:** Temporary contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Computing Platforms, JIRA, Unit Testing, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Continuous Integration, DevOps, Github, Python (Programming Language), MongoDB, Network Segmentation, Open Web Application Security, Systems Development Life Cycle, Data Logging, Scripting, Snowflake, Mitre Att&ck, Cloudformation, Fastapi, Pytest, Kubernetes, Infrastructure Automation Frameworks, Asynchronous Programming, Terraform, Serverless Computing, Docker, Databricks, Vulnerability Analysis - **Published:** September 11, 2026 - **Apply:** https://apply.deloitte.co.uk/UKCareers/Login?jobId=25099 ## About the Role * An experienced IT professional with cyber security or information security experience * Technical expertise with threat modelling using STRIDE, PASTA, attack trees, tooling and MITRE ATT&CK. * Cyber security experience covering authentication, authorisation, logging and monitoring, encryption, infrastructure security and network segmentation. * Development and DevOps knowledge, including CI/CD, pipelines, SDLC, scripting, Infrastructure as Code (Terraform or CloudFormation), Docker, Kubernetes (K8s), serverless and Helm. * Strong programming capability, preferably Python including asynchronous programming and FastAPI, plus unit testing with Pytest. * Experience applying security standards and SDLC controls to software platforms. * Experience identifying vulnerabilities using CWE or OWASP, hardening operating systems, and designing or reviewing technical architectures. * Working knowledge of agile/DevOps delivery, Jira, CDK/GitOps, penetration testing and technologies such as Snowflake, MongoDB, Terraform Cloud, GitHub or Databricks. * Analytical and adversarial mindset, attention to detail, problem-solving ability and a commitment to continuous learning. * Strong documentation, research, communication and collaboration skills, with experience building relationships across diverse teams in a regulated environment. * Desirable - Professional-level cloud certification, vendor cloud security certification and professional cyber security certification from either AWS, CGP or Azure ## Description We are looking for an experienced Threat Modelling Security Engineer to identify security threats, define effective mitigating controls and manage findings throughout their lifecycle. You will deliver threat models to agreed timeframes, develop secure Python-based automation and help improve the existing threat modelling service. The role involves presenting technical work to senior and cross-functional stakeholders, while training and supervising junior team members. You will work with minimal supervision across cloud, DevOps and regulated security environments., 1. Threat Modeling using a documented process. 2. Development of automation tools as required. 3. Maintain a high standard of work in identifying threats and specifying mitigating controls. 4. Attending to the lifecycle of identified threats and controls. 5. Delivery of threat models and supporting tasks within existing timeframes. 6. Provide feedback, support, and improvements to the existing threat modeling process. 7. Present work to seniors, the team, and other technical teams. 8. Train newer members of the team 9. Supervise junior members of the team 10. Run parts of our threat model service 11. Work with little supervision to complete work 12. Develop, test, and deploy secure and efficient Python-based applications, adhering to established SDLC processes and quality standards. ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023)