1

Threat Model Assessor Jobs (NOW HIRING)

Threat Modeler

Berwyn, PA · Hybrid

$90K - $157K/yr

Participate in threat modeling assessments for applications, APIs, cloud platforms, and technology initiatives. * Analyze application architectures, data flows, trust boundaries, and cloud ...

Threat Modeler

Austin, TX · Hybrid

$90K - $157K/yr

Participate in threat modeling assessments for applications, APIs, cloud platforms, and technology initiatives. * Analyze application architectures, data flows, trust boundaries, and cloud ...

Threat Modeler

Clifton, NJ · Hybrid

$90K - $157K/yr

Participate in threat modeling assessments for applications, APIs, cloud platforms, and technology initiatives. * Analyze application architectures, data flows, trust boundaries, and cloud ...

Threat Modeler

Quincy, MA · On-site

$90K - $157K/yr

Participate in threat modeling assessments for applications, APIs, cloud platforms, and technology initiatives. * Analyze application architectures, data flows, trust boundaries, and cloud ...

Threat Modeler

Quincy, MA · Hybrid

$90K - $157K/yr

Participate in threat modeling assessments for applications, APIs, cloud platforms, and technology initiatives. * Analyze application architectures, data flows, trust boundaries, and cloud ...

Senior Threat Modeler

Boston, MA · On-site

$120K - $202K/yr

Perform security assessments using established methodologies such as STRIDE, MITRE ATT&CK, attack trees, and risk-based analysis techniques. * Contribute to the development of threat modeling ...

About the Role As a threat modeler, you will own OpenAI's holistic approach to identifying ... assessments. * Communicate complex risks clearly and compellingly to both technical and non ...

Deep understanding of threat modeling methodologies such as STRIDE, Attack Trees, Kill Chains, or equivalent risk assessment frameworks * Demonstrated experience identifying, documenting, and ...

Deep understanding of threat modeling methodologies such as STRIDE, Attack Trees, Kill Chains, or equivalent risk assessment frameworks * Demonstrated experience identifying, documenting, and ...

Operations (CUSO) processes and overall Application Security model. Responsibilities include ... assessments, risk analysis, and compliance testing required * Experience working in a highly ...

next page

Showing results 1-20

Threat Model Assessor information

See salary details

$32.5K

$75.3K

$125.5K

How much do threat model assessor jobs pay per year?

As of Jul 26, 2026, the average yearly pay for threat model assessor in the United States is $75,259.00, according to ZipRecruiter salary data. Most workers in this role earn between $46,000.00 and $97,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Threat Model Assessor, and why are they important?

To thrive as a Threat Model Assessor, you need a solid understanding of cybersecurity principles, risk assessment methodologies, and software development processes, often supported by a degree in cybersecurity or computer science. Familiarity with threat modeling tools like Microsoft Threat Modeling Tool, STRIDE, and industry certifications such as CISSP or CEH are typically required. Strong analytical thinking, communication, and collaboration skills help convey complex security concepts to technical and non-technical stakeholders. These competencies are crucial to effectively identify vulnerabilities, communicate risks, and strengthen an organization's security posture.

What is the difference between Threat Model Assessor vs Security Analyst?

AspectThreat Model AssessorSecurity Analyst
Required CertificationsCertified Threat Intelligence Analyst (CTIA), CISSPCISSP, Security+
Work EnvironmentFocus on threat modeling, risk assessment, and security architectureMonitor security alerts, investigate incidents, and analyze vulnerabilities
Employer & Industry UsageUsed in cybersecurity consulting, product security, and risk management teamsCommon in IT departments, security operations centers, and corporate security teams

The Threat Model Assessor specializes in identifying and evaluating potential security threats through threat modeling techniques, focusing on proactive risk assessment. In contrast, the Security Analyst primarily monitors and responds to security incidents, analyzing vulnerabilities and maintaining security systems. While both roles require cybersecurity certifications and work within similar environments, their core responsibilities differ: threat assessment versus incident response.

What are Threat Model Assessors?

Threat Model Assessors are cybersecurity professionals who evaluate systems, applications, or processes to identify potential security threats and vulnerabilities. Their main role is to anticipate how an attacker might exploit weaknesses in a system and recommend strategies to mitigate those risks. They work closely with development teams, security architects, and stakeholders to ensure security is integrated throughout the design and implementation phases. Threat Model Assessors use structured methodologies to map out threats and prioritize them based on potential impact. Their assessments are essential for building secure, resilient systems.

What are some typical challenges Threat Model Assessors face when collaborating with cross-functional teams?

Threat Model Assessors often work closely with developers, security engineers, and project managers to identify and mitigate potential risks. One common challenge is ensuring that all stakeholders have a shared understanding of security concepts and priorities, as technical and non-technical team members may have different perspectives. Effective communication and the ability to translate complex threats into actionable recommendations are crucial. Additionally, balancing thorough risk analysis with project deadlines can require strong organizational and negotiation skills.
More about Threat Model Assessor jobs
Infographic showing various Threat Model Assessor job openings in the United States as of July 2026, with employment types broken down into 12% Locum Tenens, 60% Full Time, 4% Part Time, 1% Temporary, 2% Contract, and 21% Nights. Highlights an 87% Physical, 2% Hybrid, and 11% Remote job distribution, with an average salary of $75,259 per year, or $36.2 per hour.
Cyber Subject Matter Expert (SME, Threat Modeling)

Cyber Subject Matter Expert (SME, Threat Modeling)

Spatial Front, Inc

Arlington, VA • On-site

Full-time

Posted 9 days ago


Job description

Job Summary:
Spatial Front, Inc. is a recognized workplace seeking a Cyber Subject Matter Expert (SME) in Threat Modeling to join their team. The ideal candidate will lead threat modeling activities and provide expert guidance on identifying and mitigating security risks in Federal Government IT systems and applications.
Responsibilities:
• Lead and facilitate threat modeling sessions for new and existing systems, applications, and architectures.
• Serve as the Cyber Lead for the App Security Team as needed
• Apply threat modeling methodologies (e.g., STRIDE, PASTA, LINDDUN) to identify and prioritize security threats.
• Develop threat models, data flow diagrams, and attack trees for complex federal IT systems.
• Collaborate with architects, developers, and security engineers to integrate threat modeling into the SDLC.
• Produce threat model reports with identified threats, risk ratings, and recommended mitigations.
• Develop and deliver threat modeling training and workshops for technical teams.
• Maintain a threat intelligence library and incorporate emerging threats into threat modeling activities.
• Other duties as assigned.
Qualifications:
Required:
• Bachelor's in Computer Science, Cybersecurity, or related field.
• 7 years of cybersecurity, 5 years threat modeling.
• Experience with tools such as Splunk and New Relic.
• Demonstrated expertise in: Threat modeling, risk assessment, security architecture, attack vectors, mitigation strategies.
• Must be a U.S. Citizen.
• Must possess an active Secret security clearance or be able to obtain one.
Preferred:
• CISSP, CSSLP, or equivalent security architecture certification.
• Experience with threat modeling tools (e.g., Microsoft Threat Modeling Tool, IriusRisk, ThreatModeler).
• Experience with the Oracle tech stack, including PeopleSoft, is a plus.
• Familiarity with the MITRE ATT&CK framework and its application to threat modeling.
• Experience conducting threat modeling within DoD or federal agency programs.
Company:
SFI effectively delivers the right Information Technology solutions and Business Support services using thoughtful analysis, strategic planning and precise execution. Founded in 2008, the company is headquartered in Mc Lean, USA, with a team of 501-1000 employees. The company is currently Late Stage.