Lead Threat Modeling Architect

Lenovo

Raleigh (NC)

On-site

USD 150,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Lenovo in Raleigh, NC is seeking a Lead Threat Modeling Architect to head the Threat Modeling team within the PC and Smart Devices security program. You will work with global development teams to design threat models, drive security architecture decisions, and educate engineers about STRIDE and secure SDLC practices.

This role requires strong leadership, cloud/web/iot security knowledge, and proven ability to quantify security improvements.

Qualifications

  • Bachelor’s degree in cyber security or related field.
  • 3+ years creating and reviewing threat models for development teams.
  • 3+ years in security architecture assessments.

Responsibilities

  • Lead threat modeling training, workshops, and collaborative sessions.
  • Design threat models and security architecture for global products.
  • Provide training to global teams on threat modeling methods and tools.
  • Promote best security practices within development teams.
  • Develop metrics to track cybersecurity posture improvements.
  • Stay updated on latest security technologies and threat modeling trends.

Skills

Threat modeling
STRIDE analysis
Security architecture
English communication

Education

Bachelor's degree in cyber security or related

Tools

Threat Modeler Tool
DevSecOps
Cloud security assessments

Job description

About Our Team

We are searching for a Lead Threat Modeling Architect in the Security Center of Excellence for PC and Smart Devices business (PCSD). This is an exciting role where you will be leading the Threat Modeling team that supports our global development teams. You will be working alongside some of the best security teams in the industry.

What You’ll Do
  • Leads threat modeling training, workshops, and collaborative sessions for a wide array of products and services.
  • Partner with multiple international development teams across business units gaining in-depth knowledge of many products in order to design threat models and security architecture solutions for them in order to reduce the attack surface and lower the risk profiles of our products.
  • Lead training for global development teams related to threat modeling techniques and our threat modeling tools so that they become partners with the security organization to create, review and maintain threat models for products.
  • Champion threat modeling practices within the development teams, promoting best industry practices.
  • Develop meaningful metrics for threat modeling and use them to track improvements made to the cybersecurity posture of our product lines.
  • Remain current in the latest security technologies, methodologies and best practices, especially as it relates to threat modeling.
Basic Qualifications
  • Bachelor’s degree or above in cyber security or a related discipline.
  • 3+ years of experience creating, maintaining and reviewing threat models for application development teams, leading threat modeling activities.
  • 3+ years experience in Security Architecture assessments of all types
  • 3+ years experience with threat modeling practices, tools and techniques.
Preferred Qualifications
  • 7+ years of experience creating, maintaining and reviewing threat models for application development teams, leading threat modeling activities.
  • In-depth knowledge of security concepts and design techniques relating to cloud/web application, IOT, client and mobile applications
  • Proficiency in software development practices, release planning, and quality assurance.
  • Proficient in STRIDE analysis method.
  • Expert-level skills with the Threat Modeler Tool.
  • Practical experience in Secure Development Lifecycle, DevSecOps.
  • Familiarity with security and privacy frameworks, standards and regulations like GDPR, CCPA, CSA STAR, ISO 27000 series, NIST, etc.
  • Strong learning ability, strong self-drive, good adaptability and passion for security.
  • Strong communication skills in English
  • Multiple Industry security certifications such as CISSP, CCSLP, SANS-GGWEB (or other SANS certs) desired.
  • Mandarin and English Fluency

We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, status as a veteran, and basis of disability or any federal, state, or local protected class.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Modeler
Threat Modeler

5 Star Recruitment • Dallas (TX)

On-site
USD 90,000 - 120,000
Senior Threat Modeler
Senior Threat Modeler

State Street • Princeton (NJ)

Hybrid
USD 120,000 - 203,000
Hybrid work model
Competitive benefits
401(k) with company match
+1
Senior Threat Modeler
Senior Threat Modeler

State Street • Clifton (NJ)

Hybrid
USD 120,000 - 203,000
Hybrid work model
Comprehensive benefits
Senior Threat Modeler
Senior Threat Modeler

State Street • Austin (TX)

Hybrid
USD 120,000 - 203,000
401K matching
Health insurance
Paid time off
Senior Threat Modeler
Senior Threat Modeler

State Street • Devon (PA)

Hybrid
USD 120,000 - 203,000
Threat Modeler
Threat Modeler

Veriipro • Irving (TX)

On-site
USD 100,000 - 130,000
Cyber Threat Modeler
Cyber Threat Modeler

ManpowerGroup Global, Inc. • Charlotte (NC), Town of Norway (WI)

On-site
USD 100,000 - 130,000
Opportunity to work on cutting-edge AI security solutions
Engagement with a dynamic and innovative security team
Potential for extension or full-time conversion
+2
Global Threat Modeling Lead & Security Architect
Global Threat Modeling Lead & Security Architect

Lenovo • Raleigh (NC)

On-site
USD 150,000 - 230,000
Threat Modeler
Threat Modeler

Tata Consultancy Services • Irving (TX)

On-site
USD 100,000 - 125,000
Cyber Subject Matter Expert (SME, Threat Modeling)
Cyber Subject Matter Expert (SME, Threat Modeling)

Spatial Front, Inc • Arlington (VA)

On-site
USD 120,000 - 150,000