> Markdown version of [/jobs/ext/2939962-senior-threat-modeler](https://www.wearedevelopers.com/jobs/ext/2939962-senior-threat-modeler). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Threat Modeler - **Company:** Siri InfoSolutions Inc - **Location:** Dallas, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Computing Platforms, JIRA, Unit Testing, Cloud Computing, Cloud Engineering, Software Quality, Cyber Security, Continuous Integration, DevOps, Github, Issue Tracking Systems, Python (Programming Language), MongoDB, Open Web Application Security, Systems Development Life Cycle, Software Engineering, Data Logging, Scripting, Snowflake, Mitre Att&ck, Cloudformation, Fastapi, Pytest, Kubernetes, Information Technology, Asynchronous Programming, Terraform, Serverless Computing, Docker, Databricks, Vulnerability Analysis - **Published:** September 16, 2026 - **Apply:** https://www.careerjet.com/jobad/usa8e6402fb3b3709bf88924ded3415370 ## About the Role Expected to have two to five years of experience in several of the following: * IT experience minimum of 6 years with minimum of 4 years Cybersecurity/Information Security must have. * Threat Modeling (STRIDE, PASTA, Attack trees, tooling, Att&ck) must have demonstrated experience. * Experience working in a cybersecurity role must have. * Security practices pertaining to authentication, authorization, logging/monitoring, encryption, infrastructure security, network/segmentation must have. * Scripting languages, Infrastructure as Code (Terraform, CloudFormation) must have. * Jira or other ticketing systems must have. * Design and review technical architectures must have. * Strong proficiency in Programming Languages, with a preference for Python (asynchronous programming), and FastAPI (must have). * Unit Testing: Developing and executing unit tests using frameworks like Pytest to ensure code quality (must have). * Ensure all software platforms adhere to Citi's security standards and Software Development Life Cycle (SDLC) processes (must have). * Identifying vulnerabilities using CWE or OWASP. * Operating systems and their hardening. * Development concepts (such as: CICD, Pipelines, SDLC). * Cloud Development Kit (CDK), GitOps. * Operating in a DevOps / agile team structure. * Understanding of docker/K8S/serverless/helm. * Support or perform pen testing. * Snowflake/MongoDB/Terraform Cloud/GitHub/Databricks. * Karat Assessment (Python focus) is required for consideration. ## Description * Threat Modeling using a documented process. * Development of automation tools as required. * Maintain a high standard of work in identifying threats and specifying mitigating controls. * Attending to the lifecycle of identified threats and controls. * Delivery of threat models and supporting tasks within existing timeframes. * Provide feedback, support, and improvements to the existing threat modeling process. * Present work to seniors, the team, and other technical teams. * Work with little supervision to complete work * Develop, test, and deploy secure and efficient Python-based applications, adhering to established SDLC processes and quality standards., Responsibilities: The Structural Technical Modeler is a top-level drafter/technician (non-supervisory level), and is responsible for preparation of construction documents for BIM… + 2 months ago + ## Related Videos - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [pytest: Simple, rapid and fun testing with Python](https://www.wearedevelopers.com/videos/213-pytest-simple-rapid-and-fun-testing-with-python) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Automagic Configuration in Python](https://www.wearedevelopers.com/videos/363-automagic-configuration-in-python) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)