Why This Role Stands Out
This on-site role offers a competitive day rate and the chance to significantly impact secure-by-design practices within a major organization. You'll thrive here if you have a strong background in threat modelling and application security, and enjoy collaborating with engineering teams to embed robust security measures. Apply now to leverage your expertise and contribute to cutting-edge cloud and application security initiatives.
Quick Overview
Job Description
Day rate: Up to £450 - £500 (Inside IR35)
Location: London/Hybrid - 4 days a week onsite
Duration: 6 months (Initial)
A major organisation is seeking a Senior Threat Modelling & Application Security Engineer to help drive secure-by-design practices across cloud and application environments.
Key Responsibilities- Conduct threat modelling using STRIDE, PASTA, ATT&CK and Attack Trees.
- Identify vulnerabilities and define mitigating security controls.
- Review technical architectures and support secure SDLC processes.
- Develop security automation tooling and Python-based applications.
- Partner with engineering teams to embed security best practices.
- Track threats and controls through to remediation and closure.
Required Experience
- 6+ years in IT, including 4+ years within Cyber Security.
- Strong threat modelling and application security experience.
- Knowledge of OWASP, CWE, authentication, authorisation, encryption and infrastructure security.
- Experience with Terraform/CloudFormation, CI/CD and Jira.
- Strong Python skills, including FastAPI and Pytest.
- Experience within a regulated environment.
Desirable
- Docker, Kubernetes, Helm, Serverless, GitOps and CDK.
- Penetration testing exposure.
- Snowflake, MongoDB, Databricks, GitHub and Terraform Cloud.
Certifications
- Associate-level cloud certification (AWS, Azure, GCP or equivalent).
- Cyber security certification such as CySA+, CISA, GSEC, SSCP or Microsoft Security certifications.
What You'll Bring
- Strong analytical and problem-solving skills.
- Excellent communication and stakeholder management.
- An adversarial mindset and passion for continuous learning.
- Ability to work independently and collaboratively across teams.
Reasonable Adjustments:
Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.
If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.
Similar jobs
- C-
Application Security Engineer
NewCentrica - CHP
Windsor, Berkshire🇬🇧Hybrid51 minutes agoTechnology - FC
Threat Intelligence Analyst
NewFCDO
Milton Keynes, Buckinghamshire🇬🇧£51.2k/yrHybrid51 minutes agoTechnology - PO
Technical Security Architect
NewPontoon
Warwick, Warwickshire🇬🇧Remote52 minutes agoRESTGenerative AITechnology - CO
Experienced Vulnerability Researcher
NewCoretechsecurity
Salisbury🇬🇧Hybrid8 hours agoAssemblyC++PythonTechnology - TA
Security Engineer IAM
NewTelstra Associates
London🇬🇧On-site2 hours agoGCPSOAPAWS+8Technology - HA
Corporate Security Engineering Engineer Role
NewHackajob Ltd
Manchester Science Park, Manchester🇬🇧Hybrid18 hours agoStakeholder ManagementAdministrative