1

Threat Modeling Jobs (NOW HIRING)

Threat Modeling (STRIDE, PASTA, Attack trees, tooling, Att&ck) - must have demonstrated experience. * Experience working in a cybersecurity role - must have. * Security practices pertaining to ...

Threat Modeling (STRIDE, PASTA, Attack trees, tooling, Att&ck) - must have demonstrated experience. * Experience working in a cybersecurity role - must have. * Security practices pertaining to ...

Showing results 41-60

Threat Modeling information

See salary details

$47

$60

$72

How much do threat modeling jobs pay per hour?

As of Sep 8, 2026, the average hourly pay for threat modeling in the United States is $60.46, according to ZipRecruiter salary data. Most workers in this role earn between $55.77 and $65.87 per hour, depending on experience, location, and employer.

What is threat modeling?

Threat modeling is a structured process used to identify, evaluate, and address potential security threats and vulnerabilities in systems, applications, or processes. The goal is to proactively understand security risks and design effective defenses before problems occur. It typically involves identifying critical assets, potential attackers, attack vectors, and existing controls, which helps organizations prioritize their security efforts. Threat modeling is an essential part of secure software development and risk management.

What are the key skills and qualifications needed to thrive as a threat modeler, and why are they important?

To thrive as a Threat Modeler, you need a solid understanding of cybersecurity principles, risk assessment, and software architecture, often supported by a degree in computer science or information security. Familiarity with threat modeling frameworks (like STRIDE or PASTA), diagramming tools (such as Microsoft Threat Modeling Tool), and relevant certifications (like CISSP or CEH) is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for collaborating with cross-functional teams and clearly documenting risks. These skills enable the identification and mitigation of potential security threats, ensuring robust protection of organizational assets.

What are some common challenges faced by professionals in threat modeling roles, and how can they be addressed?

Professionals in threat modeling often encounter challenges such as keeping up with evolving threats, effectively communicating risk to stakeholders, and integrating threat modeling into fast-paced development cycles. Addressing these challenges involves continuous learning, fostering strong collaboration with development and security teams, and leveraging automated tools to streamline the process. Proactively engaging with cross-functional teams and maintaining clear documentation can also help ensure that threat modeling remains an integral part of the software development lifecycle.

What is the difference between Threat Modeling vs Security Analyst?

AspectThreat ModelingSecurity Analyst
Primary FocusIdentifying potential security threats during system design and developmentMonitoring, analyzing, and responding to security incidents and vulnerabilities
Skills & CertificationsKnowledge of security frameworks, risk assessment, threat identificationSecurity certifications (e.g., CISSP, CompTIA Security+), incident response skills
Work EnvironmentTypically involved in early-stage design, often within development teamsOperational, monitoring security tools, and incident management teams

Threat Modeling and Security Analysts both play vital roles in cybersecurity. Threat Modeling focuses on proactively identifying potential threats during system design, while Security Analysts respond to ongoing security incidents. Understanding their distinct responsibilities helps organizations strengthen their security posture effectively.

More about Threat Modeling jobs

What cities are hiring for Threat Modeling jobs?

Cities with the most Threat Modeling job openings:

What states have the most Threat Modeling jobs?

States with the most job openings for Threat Modeling jobs include:

Infographic showing various Threat Modeling job openings in the United States as of September 2026, with employment types broken down into 70% Full Time, and 30% Contract. Highlights an 100% In-person job distribution, with an average salary of $125,752 per year, or $60.5 per hour.

Full-time

Posted 13 days ago


Job description

Technical skills
  • Expected to have two to five years of experience in several of the following:
  • IT experience minimum of 6 years with minimum of 4 years Cybersecurity/Information Security – must have.
  • Threat Modeling (STRIDE, PASTA, Attack trees, tooling, Att&ck) – must have demonstrated experience.
  • Experience working in a cybersecurity role – must have.
  • Security practices pertaining to authentication, authorization, logging/monitoring,  encryption, infrastructure security, network/segmentation – must have.
  • Scripting languages, Infrastructure as Code (Terraform, CloudFormation) – must have.
  • Jira or other ticketing systems – must have.
  • Design and review technical architectures – must have.
  • Strong proficiency in Programming Languages, with a preference for Python (asynchronous programming), and FastAPI (must have).
  • Unit Testing: Developing and executing unit tests using frameworks like Pytest to ensure code quality (must have).
  • Ensure all software platforms adhere to Citi's security standards and Software Development Life Cycle (SDLC) processes (must have).
  • Identifying vulnerabilities using CWE or OWASP.
  • Operating systems and their hardening.
  • Development concepts (such as: CICD, Pipelines, SDLC).
  • Cloud Development Kit (CDK), GitOps.
  • Operating in a DevOps / agile team structure.
  • Understanding of docker/K8S/serverless/helm.
  • Support or perform pen testing.
  • Snowflake/MongoDB/Terraform Cloud/GitHub/Databricks.
  • Karat Assessment (Python focus) is required for consideration.
Roles & Responsibilities
  • Threat Modeling using a documented process. 
  • Development of automation tools as required. 
  • Maintain a high standard of work in identifying threats and specifying mitigating controls. 
  • Attending to the lifecycle of identified threats and controls. 
  • Delivery of threat models and supporting tasks within existing timeframes. 
  • Provide feedback, support, and improvements to the existing threat modeling process. 
  • Present work to seniors, the team, and other technical teams. 
  • Work with little supervision to complete work.
  • Develop, test, and deploy secure and efficient Python-based applications, adhering to established SDLC processes and quality standards.