Senior Vice President, Cloud Security Threat Modeler at Information Technology Senior Management Forum
Irving, Texas, USA -
Full Time


Start Date

Immediate

Expiry Date

02 Nov, 25

Salary

234240.0

Posted On

03 Aug, 25

Experience

5 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Snowflake, Code, Mastery, Encryption, Infrastructure Security, Kubernetes, Penetration Testing, Financial Services, Linux, Operating Systems, Threat Modeling, Vulnerability Scanning, Authentication, Docker, Scripting Languages, Application Testing, Authorization

Industry

Information Technology/IT

Description

QUALIFICATIONS:

  • 10+ years of experience in a Cybersecurity or Information Security role.
  • 5+ years of Experience specifically focused on Threat Modeling in Cloud Environments.
  • Expertise in Threat Modeling Methodologies like STRIDE, PASTA, Attack Trees, and the MITRE ATT&CK framework, as well as threat modeling tools (e.g., IriusRisk, ThreatModeler, Microsoft Threat Modeling Tool).
  • Proven ability to identify and analyze vulnerabilities using CWE or OWASP frameworks.
  • Deep understanding of security principles related to authentication, authorization, logging/monitoring, encryption, infrastructure security, and network segmentation.
  • Mastery of Operating Systems (e.g., Windows, Linux) and their hardening best practices.
  • Strong familiarity with Development Concepts such as CI/CD pipelines, and SDLC.
  • Extensive experience with major Cloud Platforms (e.g., AWS, Azure, GCP), including their security services and best practices.
  • Proficiency in scripting languages (e.g., Python, Bash, PowerShell) or Infrastructure as Code (IaC) tools (e.g., Terraform, CloudFormation).
  • Proven ability to design, review, and critique technical architectures for security vulnerabilities and risks.
  • Excellent written and verbal communication skills, with a demonstrated ability to collaborate effectively with diverse teams.
  • Strong analytical and problem-solving skills, with a meticulous attention to detail.

PREFERRED SKILLS:

  • Experience with Docker, Kubernetes, Serverless Technologies (e.g., AWS Lambda, Azure Functions, Google Cloud Functions), and Helm.
  • Familiarity with Cloud Development Kit (CDK) and GitOps principles.
  • Experience supporting or performing Penetration Testing activities (e.g., vulnerability scanning, network penetration testing, web application testing, mobile application testing).
  • Experience with Snowflake, MongoDB, Terraform Cloud, GitHub, or Databricks.
  • Experience working in a regulated environment (e.g., financial services).

EDUCATION:

Bachelor’s degree/University degree or equivalent experience
Master’s degree is preferred
-

MOST RELEVANT SKILLS

Please see the requirements listed above.
-

OTHER RELEVANT SKILLS

For complementary skills, please see above and/or contact the recruiter.
-

Responsibilities

OVERVIEW OF THE ROLE:

Citi is looking for a security focused person with a good understanding of cybersecurity principles to work in the Cloud Threat Modeling team. Using threat modeling you will identify threats and specify mitigating controls which will directly reduce the risk of Citi operating in the public cloud.

RESPONSIBILITIES:

  • Threat Modeling using a documented process.
  • Development of automation tools as required.
  • Maintain a high standard of work in identifying threats and specifying mitigating controls.
  • Attending to the lifecycle of identified threats and controls.
  • Delivery of threat models and supporting tasks within existing timeframes.
  • Provide feedback, support, and improvements to the existing threat modeling process.
  • Present work to seniors, the team, and other technical teams.
  • Train newer members of the team.
  • Supervise junior members of the team.
  • Run parts of our threat model service.
  • Assist in the wider threat modeling activities across Citi.
  • Work with little supervision to complete work.
Loading...