Cybersecurity Architect - Threat Modeling & Kill Chain
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are seeking a Security Architect - Threat Modeling & Kill Chain contractor to provide advisory support for clients designing and maturing security architectures aligned to threat models, attack paths, adversary behavior, and kill-chain analysis. This role will assess existing security architecture across prevention, detection, and response layers and provide practical recommendations to strengthen security controls., * Conduct threat modeling and attack path analysis to identify adversary techniques, exploitation paths, and potential control gaps.
- Assess existing security architecture across prevention, detection, and response capabilities.
- Evaluate cloud, network, endpoint, and application security controls against likely threat scenarios.
- Provide recommendations to strengthen controls aligned to kill-chain analysis, MITRE ATT&CK, and threat modeling outputs.
- Advise on target-state security architecture, security capability improvements, and security architecture roadmaps.
- Identify gaps in security controls, architecture design, monitoring, detection, segmentation, hardening, and response capabilities.
- Support integration of threat modeling outputs into broader cybersecurity strategy, risk management, vulnerability management, and remediation planning.
- Communicate architectural findings, security trade-offs, risk implications, and recommendations to technical and executive stakeholders.
- Document threat models, attack paths, control gaps, architecture recommendations, and roadmap considerations.
- Provide advisory support across complex enterprise technology environments and multiple technology stacks.
Requirements
Do you have experience in Vulnerability management?, Do you have a Bachelor’s degree?, The ideal candidate has deep experience in security architecture or security engineering, strong knowledge of threat modeling and MITRE ATT&CK, and the ability to translate technical architecture risks into clear recommendations for technical and executive stakeholders., * 8+ years of experience in security architecture, security engineering, or related cybersecurity architecture roles.
- Strong knowledge and experience aligning architecture recommendations to kill-chain analysis, MITRE ATT&CK, risk management, or vulnerability management programs.
- Experience assessing or designing controls across cloud, network, endpoint, and application security domains.
- Experience conducting threat modeling, attack path analysis, control gap assessments, or security architecture reviews.
- Ability to clearly articulate architectural concepts, security trade-offs, and risk-based recommendations.
- Ability to communicate effectively with technical teams, business stakeholders, and executive audiences.
- Strong documentation, presentation, and stakeholder communication skills.
- Experience supporting large, complex enterprise environments.
- Consulting or client-facing advisory experience.
- Ability to operate across multiple industries and technology stacks.
Preferred Qualifications
- Experience developing target-state security architectures or capability roadmaps.
- Strong executive communication, technical advisory, and documentation skills., * Cybersecurity Architecture & Assessment: 8 years (Required)
- Threat Modeling: 3 years (Required)
- Big 4 Consulting: 3 years (Preferred)
Benefits & conditions
Job Types: Full-time, Contract
Base Pay: From $70.00 per hour
Application Question(s):
- Are you eligible to work as a direct 1099 contractor (no W2 or C2C arrangements)? Please indicate your eligibility by typing ‘Yes’ or ‘No’. Note - This question is required. Failure to answer may result in disqualification
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?
Walking Into The Era of Supply Chain Risks