Threat Modeler

Covetus, LLC
Jersey City, NJ, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Comptia Cloud+ Amazon Web Services Software System Penetration Testing JIRA Microsoft Azure Cloud Computing Cloud Engineering Cyber Security Information Systems Continuous Integration Data Security DevOps
+21 more
Github Issue Tracking Systems Microsoft Security Essentials MongoDB Oracle (Applications) Open Web Application Security Systems Development Life Cycle Data Logging Scripting Google Cloud Snowflake Mitre Att&ck Cloudformation Kubernetes Information Technology Terraform Oracle Cloud Infrastructure Serverless Computing Docker Databricks Vulnerability Analysis

Job description

Threat Modeling using a documented process. Development of automation tools as required. Maintain a high standard of work in identifying threats and specifying mitigating controls. Attending to the lifecycle of identified threats and controls. Delivery of threat models and supporting tasks within existing timeframes. Provide feedback, support, and improvements to the existing threat modeling process. Present work to seniors, the team, and other technical teams. Work with little supervision to complete work Bachelor’s degree in computer related field or equivalent work experience. Associate level cloud certification: AWS Certified Developer, AWS Certified Solutions Architect, AWS Certified SysOps Administrator CompTIA Cloud+ Google Associate Cloud Engineer or other professional Google Cloud Platform certification Oracle Cloud Infrastructure Certified Architect Associate, Oracle Cloud Infrastructure Certified Cloud Operations Associate Microsoft Certified: Azure Developer Associate Associate or professional cyber-security ISACA Certified Information Systems Auditor (CISA) GIAC Security Essentials (GSEC) ISC2 Systems Security Certified Practitioner (SSCP) CompTIA CySA+

Requirements

IT experience minimum of 6 years with minimum of 4 years Cyber-Security/Information Security must Threat Modeling (STRIDE, PASTA, Attack trees, tooling, Att&ck) must. Identifying vulnerabilities using CWE or OWASP. Experience working in a cyber-security role - must. Security practices pertaining to authentication, authorization, logging/monitoring, encryption, infrastructure security, network/segmentation must. Operating systems and their hardening. Development concepts (such as: CICD, Pipelines, SDLC). Scripting languages, Infrastructure as Code (Terraform, CloudFormation) must. Cloud Development Kit (CDK), GitOps. Operating in a DevOps / agile team structure. Jira or other ticketing systems must. Understanding of docker/K8S/serverless/helm. Support or perform pen testing. Snowflake/MongoDB/Terraform Cloud/GitHub/Databricks. Design and review technical architectures must., Microsoft Certified: Security Operations Analyst Associate; Information Protection Administrator A ssociate.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:11 min

Threat modeling techniques for cloud native infrastructure

Andrew Martin · WWC 2022

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

1:32 min

Pairing with teams for continuous threat modeling

Nazneen Rupawalla · WWC 2022

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all