Source description
About the role
Experience: 7+ years Location: Bangalore Must Have: Threat Modeling (MITRE ATT&CK), DFD VAPT. Good to Have: PCI DSS, Banking Domain Job Responsibilities Conduct structured threat modeling exercises across applications, APIs, and cloud environments Lead and facilitate threat modeling workshops with development, architecture, and business teams Identify threats using methodologies such as STRIDE, PASTA, DREAD, etc. Analyze data flows, trust boundaries, and system architectures to identify security weaknesses Perform risk analysis including likelihood determination, impact assessment, and risk rating Develop and maintain threat models, attack surface documentation, and security architecture diagrams Provide actionable mitigation strategies and secure design recommendations Integrate threat modeling into SDLC / DevSecOps processes (Good to have) Collaborate with development teams to validate remediation and design improvements Support secure architecture reviews for cloud (AWS/Azure/GCP), microservices, APIs, and containerized environments Align threat modeling outputs with compliance frameworks and regulatory requirements Develop customized threat reports, executive summaries, and risk dashboards for stakeholders Contribute to improving organizational threat modeling frameworks, templates, and playbooks Proactively identify emerging threats relevant to client environments Engage with cross-functional teams from project initiation to closure ensuring secure design implementation Excellent communication skills are required
More at Cortex Consultants