Deloitte - Recruitment

Threat Modeling and Cybersecurity Specialist

Deloitte - Recruitment · Greater London, England, United Kingdom · £117K/yr

Business Consulting and Services · 10,001+ employees

19 h ago
Senior (5-10 yrs) Contractor United Kingdom
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The specialist will identify potential threats, develop mitigation strategies, and deliver secure Python-based applications. They will also manage the lifecycle of identified threats and collaborate with cross-functional teams to present findings to leadership.

What they look for

Threat modeling Cybersecurity Python FastAPI STRIDE PASTA Attack trees Vulnerability identification OWASP Authentication Encryption Network segmentation DevOps CI/CD Infrastructure as code Terraform

Requirements

Candidates must have at least 6 years of IT experience, including 4 years in cybersecurity, with proven expertise in threat modeling methodologies. Proficiency in Python, vulnerability assessment, and relevant cloud or cybersecurity certifications are required.

Full description

Role: Threat Modeling and Cybersecurity Specialist

Location: London

Start Date: September 2026

End Date: 6 months

Daily Rate: up to £450 depending on experience - Inside IR35

Payroll provider – Rockford Payroll Info for Contingent Workers – Rockford Pay

This is an exciting opportunity to join Deloitte Operations for an engagement with one of our clients.

The Role

As a Threat Modeling and Cybersecurity Specialist, you will play a critical role in identifying potential threats, developing mitigation strategies, and delivering secure, efficient Python-based applications. You will work closely with cross-functional teams, presenting your findings and improvements to senior leadership and technical teams, while operating with minimal supervision.

Key Responsibilities

· Conduct threat modeling using documented processes such as STRIDE, PASTA, and Attack Trees.

· Develop and maintain automation tools to enhance threat identification and mitigation.

· Maintain high standards in identifying threats and specifying mitigating controls.

· Manage the lifecycle of identified threats and controls, ensuring timely delivery within set timeframes.

· Provide feedback and continuous improvements to the existing threat modeling process.

· Develop, test, and deploy secure Python-based applications adhering to established SDLC processes and quality standards.

· Collaborate with diverse teams, presenting work clearly and effectively.

Experience & Skills Required

· Minimum of 6 years IT experience with at least 4 years in Cybersecurity or Information Security roles.

· Proven expertise in threat modeling methodologies (STRIDE, PASTA, Attack Trees, ATT&CK).

· Strong knowledge of vulnerability identification using CWE or OWASP standards.

· Hands-on experience with security practices including authentication, authorization, logging/monitoring, encryption, infrastructure security, and network segmentation.

· Proficiency in Python programming, including asynchronous programming and FastAPI framework.

· Experience with unit testing frameworks such as Pytest.

· Familiarity with development concepts like CICD, pipelines, SDLC, and Infrastructure as Code (Terraform, CloudFormation).

· Experience working in DevOps or agile team environments.

· Proficient with Jira or other ticketing systems.

· Strong analytical skills, attention to detail, and a problem-solving mindset.

Preferred Skills and Tools

· Experience with Docker, Kubernetes, serverless architectures, and Helm.

· Knowledge of Snowflake, MongoDB, Terraform Cloud, GitHub, and Databricks.

· Ability to design and review technical architectures.

· Experience supporting or performing penetration testing.

Required Qualifications / Certifications

· Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent work experience.

· Associate level cloud certification from AWS, GCP, or Azure (e.g., AWS Certified Developer, Google Associate Cloud Engineer, Microsoft Certified Azure Developer Associate).

· Associate or professional cybersecurity certification (e.g., CISA, GSEC, SSCP, CompTIA CySA+, Microsoft Security Operations Analyst Associate).