Application Security Engineer (Threat Modeling)
Core
Lead threat modeling engagements to identify design risks early and translate them into practical security requirements for applications, APIs, and cloud services.
Role type
Senior IC Application Security Engineer (Threat Modeling)
Builds
Secure design patterns, threat libraries, and mitigation guidance embedded into the Secure SDLC
Domain
Cybersecurity / Application Security / Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Threat modeling methodologies (STRIDE, attack trees, PASTA, LINDDUN), secure software development lifecycle integration, architecture analysis, risk assessment, technical writing, stakeholder facilitation
Preferred skills
Enterprise security program experience, regulated industry background (financial services/insurance), modern cloud architecture assessment (Azure, AWS, GCP, Kubernetes), diagramming tools (Threat Modeling Tool, OWASP Threat Dragon), automation of threat modeling
Technologies
Microsoft Azure, AWS, Google Cloud, Kubernetes, microservices, event-driven systems, APIs, mobile applications, AI-enabled solutions
Responsibilities
Lead threat modeling engagements from design through implementation; define scope and document system components, assets, data flows, and trust boundaries; assess threats using likelihood, impact, and exploitability; translate findings into security requirements and remediation actions; coach delivery teams on secure design; produce service metrics and reporting on risk reduction
Seniority
Senior, hands-on IC
