> Markdown version of [/jobs/ext/589439-threat-modeler](https://www.wearedevelopers.com/jobs/ext/589439-threat-modeler). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Threat Modeler - **Company:** Covetus, LLC - **Location:** Jersey City, NJ, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Comptia Cloud+, Amazon Web Services, Software System Penetration Testing, JIRA, Microsoft Azure, Cloud Computing, Cloud Engineering, Cyber Security, Information Systems, Continuous Integration, Data Security, DevOps, Github, Issue Tracking Systems, Microsoft Security Essentials, MongoDB, Oracle (Applications), Open Web Application Security, Systems Development Life Cycle, Data Logging, Scripting, Google Cloud, Snowflake, Mitre Att&ck, Cloudformation, Kubernetes, Information Technology, Terraform, Oracle Cloud Infrastructure, Serverless Computing, Docker, Databricks, Vulnerability Analysis - **Published:** June 19, 2026 - **Apply:** https://www.dice.com/job-detail/436389cf-133d-41ea-b404-29b44d8ab8b9 ## About the Role IT experience minimum of 6 years with minimum of 4 years Cyber-Security/Information Security must Threat Modeling (STRIDE, PASTA, Attack trees, tooling, Att&ck) must. Identifying vulnerabilities using CWE or OWASP. Experience working in a cyber-security role - must. Security practices pertaining to authentication, authorization, logging/monitoring, encryption, infrastructure security, network/segmentation must. Operating systems and their hardening. Development concepts (such as: CICD, Pipelines, SDLC). Scripting languages, Infrastructure as Code (Terraform, CloudFormation) must. Cloud Development Kit (CDK), GitOps. Operating in a DevOps / agile team structure. Jira or other ticketing systems must. Understanding of docker/K8S/serverless/helm. Support or perform pen testing. Snowflake/MongoDB/Terraform Cloud/GitHub/Databricks. Design and review technical architectures must., Microsoft Certified: Security Operations Analyst Associate; Information Protection Administrator A ssociate. ## Description Threat Modeling using a documented process. Development of automation tools as required. Maintain a high standard of work in identifying threats and specifying mitigating controls. Attending to the lifecycle of identified threats and controls. Delivery of threat models and supporting tasks within existing timeframes. Provide feedback, support, and improvements to the existing threat modeling process. Present work to seniors, the team, and other technical teams. Work with little supervision to complete work Bachelor's degree in computer related field or equivalent work experience. Associate level cloud certification: AWS Certified Developer, AWS Certified Solutions Architect, AWS Certified SysOps Administrator CompTIA Cloud+ Google Associate Cloud Engineer or other professional Google Cloud Platform certification Oracle Cloud Infrastructure Certified Architect Associate, Oracle Cloud Infrastructure Certified Cloud Operations Associate Microsoft Certified: Azure Developer Associate Associate or professional cyber-security ISACA Certified Information Systems Auditor (CISA) GIAC Security Essentials (GSEC) ISC2 Systems Security Certified Practitioner (SSCP) CompTIA CySA+ ## Related Videos - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)