ELYON International, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Location Portland, Oregon (Remote) Employment Type Contractor Minimum Experience Experienced
Cloud Security Threat Modeler
Location
United States
Posted
2 days ago
Salary
Not specified
No structured requirement data.
Job Description
Role Description
Engineer and standardize reusable security patterns for Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). This role provides approved patterns for services, allowing application teams to utilize pre-approved service and API patterns without requiring them to threat model cloud services when developing application threat models.
Primary Responsibilities
- Backlog Execution: Conduct deep-dive threat model reviews for an immediate backlog of 22 cloud services.
- Pattern Engineering: Develop modular, "Lego-brick" threat models for cloud services and API patterns, defining mandatory security controls and standardized use cases.
- Stakeholder Defense: Schedule threat model reviews (TMRs) for cloud services. Present and defend service threat models in formal threat model reviews (TMRs) with the Boeing Enterprise Security (BES) to defend and secure approval for standardized patterns.
- Additional Reviews: For services that require changes to environment perimeters, coordinate with landing zone architects to update landing zone architecture standards, schedule reviews, and review changes with the Secure Perimeter Review Board (SPRB) reviews.
- Technical Research: Perform manual analysis using TrustOnCloud research libraries to identify Cloud Service Provider (CSP) specific threats and configuration requirements. Work with CSP subject matter experts to develop service threat models when necessary.
Secondary Responsibilities
- Library Stewardship: Manage repository of approximately 200 service and API threat models.
- Governance & Maintenance: Execute a manual biennial (2-year) refresh cycle for all models in the library to ensure continued alignment with CSP updates and feature releases.
Key Performance Indicators (KPIs)
- Throughput: Following a 1-month ramp-up and shadowing/training period, complete a minimum of 3 service threat model reviews per month.
- Backlog Resolution: Clear the initial 22-service backlog within approximately 8 months of the completion of the training period.
- Maintenance Compliance: Maintain 100% adherence to the biennial manual refresh schedule for the 200-pattern library.
Qualifications
- Experience: 5+ years in cloud security architecture or threat modeling.
- Technical Depth: Expert knowledge of AWS, Azure, and GCP managed services and the Shared Responsibility Model.
- Analytical Skill: Proven ability to synthesize complex technical data (e.g., TrustOnCloud reports) into concise, executable security standards.
- Communication: Ability to negotiate and defend technical security positions to central risk and compliance stakeholders.
Preferred Experience
- Direct experience using TrustOnCloud for threat research.
- Background in creating reusable security patterns in large-scale enterprise environments.
Benefits
- Paid sick leave
- Medical/Dental (optional)
- 401 (k) Retirement Plan (optional)
- Employer Paid Life Insurance
- Employer Paid Short Term Disability
- Optional Life Insurance
Company Description
ELYON International, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Location
Seattle, Washington (Remote)
Employment Type
Contractor
Minimum Experience
Experienced
Job Requirements
- Experience: 5+ years in cloud security architecture or threat modeling.
- Technical Depth: Expert knowledge of AWS, Azure, and GCP managed services and the Shared Responsibility Model.
- Analytical Skill: Proven ability to synthesize complex technical data (e.g., TrustOnCloud reports) into concise, executable security standards.
- Communication: Ability to negotiate and defend technical security positions to central risk and compliance stakeholders.
- Preferred Experience
- Direct experience using TrustOnCloud for threat research.
- Background in creating reusable security patterns in large-scale enterprise environments.
Benefits
- Paid sick leave
- Medical/Dental (optional)
- 401 (k) Retirement Plan (optional)
- Employer Paid Life Insurance
- Employer Paid Short Term Disability
- Optional Life Insurance
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Technical Writer Intern creating documentation for AI Security products
Senior security professional leading product security for autonomous aircraft at Shield AI
Senior Cybersecurity Engineer (Secret clearance)
Rise8An elite software development firm delivering a tomorrow where fewer bad things happen because of bad software.
The Senior Cybersecurity Engineer will be responsible for securing cloud-based environments by designing and implementing native security solutions and driving Continuous RMF practices through automation. Key duties include implementing security measures like firewalls and IDS/IPS, securing containerized systems, and establishing identity and access management policies.
Consumer Identity & Access Management (CIAM) Engineer II
Texas Health ResourcesAt Texas Health Resources, our mission is “to improve the health of the people in the communities we serve.” We are one of the largest faith-based, nonprofit health systems in the United States. Team of more than 23,000 employees of wholly owned/operated facilities plus 2,200 employees of consolidated joint ventures in the greater Dallas/Fort Worth area. Career growth and professional development opportunities are top-notch and benefits are equally outstanding.
CIAM Engineer II – Consumer Salesforce Bring your passion to Texas Health so we are Better + Together Work location: Texas Health Resources, Remote – Must reside in Texas or be willing to relocate. Required to attend in-person meetings at corporate office in Arlington. Work h...