Cyber Security Analyst

Damia Group
Slough, UK
4 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
£104,000.0 - £130,000.0
Working hours
Regular working hours

Tech stack

Agile Methodology Software System Penetration Testing JIRA User Authentication Unit Testing Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Computer Programming Continuous Integration DevOps
+25 more
Github Information Systems Security Architecture Professional Python (Programming Language) Network Security MongoDB Open Web Application Security Software Maintenance Systems Development Life Cycle Secure Coding Software Engineering Data Logging Scripting Snowflake Mitre Att&ck Cloudformation Fastapi Pytest Kubernetes Information Technology Asynchronous Programming Terraform Serverless Computing Docker Databricks Vulnerability Analysis

Job description

Damia Group is supporting a leading organisation in the delivery of a high-profile Cyber Security programme and is looking for an experienced Senior Threat Modelling Engineer to join the team in London.

You will play a key role in identifying and assessing security threats, defining appropriate mitigating controls, and helping to continuously improve the organisation’s threat modelling capability.

This is a hands-on position combining Threat Modelling, Cyber Security, Cloud Security and Python development, with responsibility for delivering high-quality threat models while also supporting and mentoring more junior members of the team., * Conduct Threat Modelling using established and documented methodologies.

  • Apply techniques including STRIDE, PASTA, Attack Trees and MITRE ATT&CK to identify and assess threats.
  • Identify vulnerabilities using frameworks such as CWE and OWASP.
  • Define, document and maintain appropriate security controls and mitigations.
  • Manage the lifecycle of identified threats and associated controls.
  • Deliver threat models and supporting activities within agreed timelines.
  • Develop automation tools and solutions to improve the threat modelling process.
  • Develop, test and deploy secure and efficient Python-based applications in line with established SDLC processes and quality standards.
  • Contribute to the continuous improvement of existing threat modelling processes and methodologies.
  • Present threat modelling outputs and recommendations to senior stakeholders, technical teams and wider audiences.
  • Support and mentor junior members of the team.
  • Supervise and provide technical guidance to less experienced team members.
  • Take responsibility for elements of the threat modelling service.
  • Work independently with minimal supervision while maintaining a consistently high standard of delivery.
  • Collaborate with engineering, architecture, DevOps and Cyber Security teams.
  • Support or participate in penetration testing activities where required.
  • Design and review technical architectures from a security perspective.

Requirements

You should have 6+ years of overall IT experience, including a minimum of 4 years within Cyber Security / Information Security.

Strong experience in several of the following is required:

  • Threat Modelling - essential, including STRIDE, PASTA, Attack Trees, tooling and MITRE ATT&CK.
  • Professional experience working within a Cyber Security / Information Security role - essential.
  • Identifying vulnerabilities using CWE and OWASP.
  • Security principles covering:
  • Authentication and authorisation
  • Logging and monitoring
  • Encryption
  • Infrastructure security
  • Network security and segmentation
  • Operating systems and security hardening.
  • Software development concepts including CI/CD, pipelines and SDLC.
  • Scripting and Infrastructure as Code, including Terraform and CloudFormation.
  • Cloud Development Kit (CDK) and GitOps.
  • Experience working within DevOps and Agile environments.
  • Jira or similar ticketing/workflow platforms.
  • Docker, Kubernetes, Serverless and Helm - essential.
  • Cloud security and secure cloud architecture.
  • Technical architecture design and review.
  • Strong programming skills, particularly Python, including asynchronous programming.
  • FastAPI - essential.
  • Pytest / unit testing - essential.
  • Experience developing and maintaining software in line with security standards and SDLC processes.
  • Experience with technologies such as Snowflake, MongoDB, Terraform Cloud, GitHub and Databricks would be advantageous., * Strong analytical skills and exceptional attention to detail.
  • An adversarial mindset and the ability to think like an attacker.
  • A proactive approach to research, particularly using vendor documentation and technical resources.
  • Strong documentation and technical writing skills.
  • Experience working within regulated environments.
  • A genuine interest in emerging technologies, security methodologies and industry developments.
  • Strong problem-solving and critical-thinking skills.
  • Excellent communication and collaboration skills.
  • The ability to build effective relationships across technical and non-technical teams.
  • Confidence presenting technical findings to senior stakeholders.
  • A willingness to mentor, support and develop other members of the team.

This is an opportunity to work on a technically challenging Cyber Security programme where you will have significant responsibility across Threat Modelling, Cloud Security, Secure Development and Cyber Security architecture.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

3:05 min

Tagging and organizing execution scenarios with pytest markers

Florian Bruhin · World Congress 2021

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

Videos

See all

Related articles

See all