> Markdown version of [/jobs/ext/3045894-cyber-security-analyst](https://www.wearedevelopers.com/jobs/ext/3045894-cyber-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Analyst - **Company:** Damia Group - **Location:** Slough, UK (Remote available) - **Experience:** Expert - **Salary:** £104,000.0 - £130,000.0 - **Contract:** Temporary contract - **Skills:** Agile Methodology, Software System Penetration Testing, JIRA, User Authentication, Unit Testing, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Computer Programming, Continuous Integration, DevOps, Github, Information Systems Security Architecture Professional, Python (Programming Language), Network Security, MongoDB, Open Web Application Security, Software Maintenance, Systems Development Life Cycle, Secure Coding, Software Engineering, Data Logging, Scripting, Snowflake, Mitre Att&ck, Cloudformation, Fastapi, Pytest, Kubernetes, Information Technology, Asynchronous Programming, Terraform, Serverless Computing, Docker, Databricks, Vulnerability Analysis - **Published:** September 24, 2026 - **Apply:** https://www.collegerecruiter.com/job/2891975660-cyber-security-analyst ## About the Role You should have 6+ years of overall IT experience, including a minimum of 4 years within Cyber Security / Information Security. Strong experience in several of the following is required: * Threat Modelling - essential, including STRIDE, PASTA, Attack Trees, tooling and MITRE ATT&CK. * Professional experience working within a Cyber Security / Information Security role - essential. * Identifying vulnerabilities using CWE and OWASP. * Security principles covering: * Authentication and authorisation * Logging and monitoring * Encryption * Infrastructure security * Network security and segmentation * Operating systems and security hardening. * Software development concepts including CI/CD, pipelines and SDLC. * Scripting and Infrastructure as Code, including Terraform and CloudFormation. * Cloud Development Kit (CDK) and GitOps. * Experience working within DevOps and Agile environments. * Jira or similar ticketing/workflow platforms. * Docker, Kubernetes, Serverless and Helm - essential. * Cloud security and secure cloud architecture. * Technical architecture design and review. * Strong programming skills, particularly Python, including asynchronous programming. * FastAPI - essential. * Pytest / unit testing - essential. * Experience developing and maintaining software in line with security standards and SDLC processes. * Experience with technologies such as Snowflake, MongoDB, Terraform Cloud, GitHub and Databricks would be advantageous., * Strong analytical skills and exceptional attention to detail. * An adversarial mindset and the ability to think like an attacker. * A proactive approach to research, particularly using vendor documentation and technical resources. * Strong documentation and technical writing skills. * Experience working within regulated environments. * A genuine interest in emerging technologies, security methodologies and industry developments. * Strong problem-solving and critical-thinking skills. * Excellent communication and collaboration skills. * The ability to build effective relationships across technical and non-technical teams. * Confidence presenting technical findings to senior stakeholders. * A willingness to mentor, support and develop other members of the team. This is an opportunity to work on a technically challenging Cyber Security programme where you will have significant responsibility across Threat Modelling, Cloud Security, Secure Development and Cyber Security architecture. ## Description Damia Group is supporting a leading organisation in the delivery of a high-profile Cyber Security programme and is looking for an experienced Senior Threat Modelling Engineer to join the team in London. You will play a key role in identifying and assessing security threats, defining appropriate mitigating controls, and helping to continuously improve the organisation's threat modelling capability. This is a hands-on position combining Threat Modelling, Cyber Security, Cloud Security and Python development, with responsibility for delivering high-quality threat models while also supporting and mentoring more junior members of the team., * Conduct Threat Modelling using established and documented methodologies. * Apply techniques including STRIDE, PASTA, Attack Trees and MITRE ATT&CK to identify and assess threats. * Identify vulnerabilities using frameworks such as CWE and OWASP. * Define, document and maintain appropriate security controls and mitigations. * Manage the lifecycle of identified threats and associated controls. * Deliver threat models and supporting activities within agreed timelines. * Develop automation tools and solutions to improve the threat modelling process. * Develop, test and deploy secure and efficient Python-based applications in line with established SDLC processes and quality standards. * Contribute to the continuous improvement of existing threat modelling processes and methodologies. * Present threat modelling outputs and recommendations to senior stakeholders, technical teams and wider audiences. * Support and mentor junior members of the team. * Supervise and provide technical guidance to less experienced team members. * Take responsibility for elements of the threat modelling service. * Work independently with minimal supervision while maintaining a consistently high standard of delivery. * Collaborate with engineering, architecture, DevOps and Cyber Security teams. * Support or participate in penetration testing activities where required. * Design and review technical architectures from a security perspective. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [pytest: Simple, rapid and fun testing with Python](https://www.wearedevelopers.com/videos/213-pytest-simple-rapid-and-fun-testing-with-python) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Automagic Configuration in Python](https://www.wearedevelopers.com/videos/363-automagic-configuration-in-python) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)