Quick Overview
Job Description
AMS is a global workforce solutions partner committed to creating inclusive, dynamic, and future-ready workplaces. We help organisations adapt, grow, and thrive in an ever-evolving world by building, shaping, and optimising diverse talent strategies.
Our Contingent Workforce Solutions (CWS) is one of our service offerings. Acting as an extension of their recruitment teams, we connect them with skilled interim and temporary professionals, fostering workplaces where everyone can contribute and succeed.
Our Client is a big four consultancy firm with a global presence, operating in over 150 countries. This organisation works with many public and private companies spanning multiple industries. The advisory work that they cover spans across audit, Accountancy, tax, corporate finance and consulting.
On behalf of this organisation, AMS are looking for a Cybersecurity Engineer for a 6 Month contract based in London with 3 days/week in office.
Purpose of the role:
We are looking for an experienced Threat Modelling Security Engineer to identify security threats, define effective mitigating controls and manage findings throughout their lifecycle. You will deliver threat models to agreed timeframes, develop secure Python-based automation and help improve the existing threat modelling service. The role involves presenting technical work to senior and cross-functional stakeholders, while training and supervising junior team members. You will work with minimal supervision across cloud, DevOps and regulated security environments.
What you'll do:
- Lead and deliver threat modeling activities using established methodologies to identify, assess, and mitigate security risks across applications and platforms.
- Develop and maintain automation tools and Python-based solutions to enhance security processes, operational efficiency, and service delivery.
- Manage the lifecycle of identified threats and controls, ensuring timely remediation, tracking, and validation of security measures.
- Deliver high-quality threat models and security assessments within agreed timelines, maintaining accuracy and attention to detail.
- Contribute to the continuous improvement of threat modeling processes, frameworks, tooling, and best practices across the organisation.
- Present security findings and recommendations to technical teams, senior stakeholders, and cross-functional audiences, influencing secure design decisions.
- Mentor, train, and provide guidance to junior team members while supporting the day-to-day operation and evolution of the threat modeling service.
The skills you'll need:
- An experienced IT professional with cyber security or information security experience
- Technical expertise with threat modelling using STRIDE, PASTA, attack trees, tooling and MITRE ATT&CK.
- Cyber security experience covering authentication, authorisation, logging and monitoring, encryption, infrastructure security and network segmentation.
- Development and DevOps knowledge, including CI/CD, pipelines, SDLC, scripting, Infrastructure as Code (Terraform or CloudFormation), Docker, Kubernetes (K8s), serverless and Helm.
- Strong programming capability, preferably Python including asynchronous programming and FastAPI, plus unit testing with Pytest.
- Experience applying security standards and SDLC controls to software platforms.
- Experience identifying vulnerabilities using CWE or OWASP, hardening operating systems, and designing or reviewing technical architectures.
- Working knowledge of agile/DevOps delivery, Jira, CDK/GitOps, penetration testing and technologies such as Snowflake, MongoDB, Terraform Cloud, GitHub or Databricks.
- Analytical and adversarial mindset, attention to detail, problem-solving ability and a commitment to continuous learning.
- Strong documentation, research, communication and collaboration skills, with experience building relationships across diverse teams in a regulated environment.
- Desirable - Professional-level cloud certification, vendor cloud security certification and professional cyber security certification from either AWS, CGP or Azure
Next steps
Next steps
This client will only accept workers operating via an Umbrella or PAYE engagement model.
If you are interested in applying for this position and meet the criteria outlined above, please click the link to apply and we will contact you with an update in due course.
AMS, a Recruitment Process Outsourcing Company, may in the delivery of some of its services be deemed to operate as an Employment Agency or an Employment Business
Similar jobs
- CP
Security Engineer, Global Accounts EMEA
NewCheck Point Software Technologies
London🇬🇧On-site2 days agoTechnology - EP
Security Operations Specialist - 12 Month FTC
NewEvelyn Partners
London🇬🇧Hybrid2 days agoOperations & Project Management - EP
Security Operations Specialist - 12 Month FTC
NewEvelyn Partners
Glasgow🇬🇧Hybrid2 days agoOperations & Project Management - EP
Security Operations Specialist - 12 Month FTC
NewEvelyn Partners
Liverpool🇬🇧Hybrid2 days agoOperations & Project Management - FG
Vulnerability Analyst
NewFrasers Group
Shirebrook🇬🇧On-site2 days agoLESSPenetration TestingTechnology - FG
GRC Analyst
NewFrasers Group
Shirebrook🇬🇧Hybrid2 days agoPCI DSSLESSStakeholder ManagementTechnology