What are the responsibilities and job description for the Threat Modeler / Cyber Security Engineer position at Centraprise?
Threat Modeler / Cyber Security Engineer
Irving, TX
Fulltime (Permanent)
Job Description:
Experience Required
- 8 years overall IT experience
- Minimum 4 years in Cyber Security / Information Security
Core Skills:
- Threat Modeling & Security Analysis: STRIDE, PASTA, Attack Trees, MITRE ATT&CK, threat assessment, attack surface analysis, security architecture reviews
- Vulnerability Management & Secure Coding: CWE, OWASP Top 10, vulnerability identification, remediation planning, penetration testing support
- Cyber Security & Infrastructure Security: Authentication, authorization, encryption, logging/monitoring, network security, segmentation, infrastructure hardening
- Cloud & DevSecOps: AWS, Azure, GCP, cloud security, CI/CD pipelines, DevOps, GitOps, SDLC security integration
- Infrastructure as Code (IaC): Terraform, CloudFormation, CDK (Cloud Development Kit), infrastructure automation
- Container & Platform Security: Docker, Kubernetes (K8S), Helm, serverless security
- Databases & Platforms: Snowflake, MongoDB, Databricks, Terraform Cloud, GitHub
- Automation & Scripting: Security automation, scripting languages, process automation
- Architecture & Design Reviews: Technical architecture reviews, secure solution design, cloud-native architectures
- Tools & Collaboration: Jira, ticketing systems, Agile/Scrum collaboration, stakeholder communication
Key Responsibilities:
- Perform threat modeling using documented methodologies and frameworks
- Identify threats, vulnerabilities, and mitigating security controls
- Maintain lifecycle management of identified threats and remediation controls
- Conduct architecture reviews for secure cloud and infrastructure deployments
- Develop automation tools and improve threat modeling processes
- Collaborate with engineering, DevOps, and security teams on secure implementations
- Support or participate in penetration testing and security validation activities
- Deliver threat models and associated artifacts within defined timelines
- Present findings, recommendations, and risk assessments to technical and leadership teams
- Continuously improve security posture across applications and infrastructure
Certifications Preferred:
Cloud Certifications:
- AWS Certified Developer
- AWS Certified Solutions Architect
- AWS Certified SysOps Administrator
- CompTIA Cloud
- Google Associate Cloud Engineer
- Oracle Cloud Infrastructure Certified Architect Associate
- Oracle Cloud Infrastructure Certified Cloud Operations Associate
- Microsoft Certified: Azure Developer Associate
Cyber Security Certifications:
- CISA
- GSEC
- SSCP
- CompTIA CySA
- Microsoft Certified: Security Operations Analyst Associate
- Microsoft Certified: Information Protection Administrator Associate