Senior Threat Modeler

State Street

Devon (PA)

Hybrid

USD 120,000 - 202,500

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

State Street is seeking a Senior Threat Modeler to perform threat modeling across enterprise applications, cloud platforms, APIs, and emerging technologies to identify security risks early in the development lifecycle and drive secure-by-design outcomes.

The role involves partnering with architects, engineers, developers, and cybersecurity teams to strengthen the security posture of critical business systems and technology platforms.

Qualifications

  • Degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline.
  • 12 years or more of experience in application security, cloud security, cybersecurity architecture, threat modeling, or related disciplines, with at least 7 years of hands-on cybersecurity experience preferred.
  • Demonstrated experience conducting threat modeling exercises for enterprise applications, APIs, cloud platforms, and distributed systems.
  • Strong expertise in application security principles, secure software development lifecycles, OWASP Top 10, API security, and secure coding practices.
  • Experience assessing and securing cloud environments across AWS, Azure, and/or Google Cloud Platform.
  • Knowledge of microservices, containers, Kubernetes, CI/CD pipelines, DevSecOps practices, and modern software architectures.
  • Experience with threat modeling methodologies such as STRIDE, MITRE ATT&CK, attack trees, and adversary-based risk analysis.
  • Professional certifications such as CISSP, CCSP, CSSLP, GWAPT, GWEB, AWS Security Specialty, Azure Security Engineer, or equivalent security certifications are highly desirable.
  • Experience within financial services or other highly regulated industries is preferred.

Responsibilities

  • Conduct threat modeling activities for business applications, cloud-native platforms, APIs, and strategic technology initiatives.
  • Analyze application architectures, data flows, trust boundaries, and cloud deployments to identify security threats and design weaknesses.
  • Partner with application development, cloud engineering, and security teams to recommend practical risk mitigation strategies and secure design improvements.
  • Perform security assessments using established methodologies such as STRIDE, MITRE ATT&CK, attack trees, and risk-based analysis techniques.
  • Contribute to the development of threat modeling standards, reusable patterns, training materials, and secure-by-design practices across the enterprise.
  • Possess strong knowledge of cloud-native architectures and security controls across AWS, Azure, and Google Cloud, with the ability to identify and mitigate risks in distributed, containerized, and platform-based environments.

Skills

Threat modeling
Cloud security
Application security
Risk assessment
Security architecture
Stakeholder influence
DevSecOps

Education

Degree in Computer Science, Cybersecurity, Information Technology, Engineering

Tools

Kubernetes
CI/CD

Job description

Who We Are Looking For

We are looking for a Senior Threat Modeler responsible for performing threat modeling activities across enterprise applications, cloud platforms, APIs, and emerging technologies to identify security risks early in the development lifecycle and drive secure‑by‑design outcomes. The role involves partnering with architects, engineers, developers, and cybersecurity teams to strengthen the security posture of critical business systems and technology platforms.

Why This Role Is Important To Us

The team joins the Security Architecture organization, a critical function that protects the firm's applications, data, cloud environments, and technology services. Threat modeling enables proactive identification of security weaknesses, reduction of cyber risk, improved architectural resiliency, and integration of security requirements throughout the development lifecycle.

Responsibilities
  • Conduct threat modeling activities for business applications, cloud‑native platforms, APIs, and strategic technology initiatives.
  • Analyze application architectures, data flows, trust boundaries, and cloud deployments to identify security threats and design weaknesses.
  • Partner with application development, cloud engineering, and security teams to recommend practical risk mitigation strategies and secure design improvements.
  • Perform security assessments using established methodologies such as STRIDE, MITRE ATT&CK, attack trees, and risk‑based analysis techniques.
  • Contribute to the development of threat modeling standards, reusable patterns, training materials, and secure‑by‑design practices across the enterprise.
  • Possess strong knowledge of cloud‑native architectures and security controls across AWS, Azure, and Google Cloud, with the ability to identify and mitigate risks in distributed, containerized, and platform‑based environments.
What We Value
  • Strong analytical, problem‑solving, and risk assessment skills that identify complex security threats and vulnerabilities.
  • Deep understanding of application security, cloud security, secure software development, and modern technology architectures.
  • Excellent communication and stakeholder management skills, with the ability to influence engineering and architecture teams.
  • Experience working in large‑scale, complex environments with diverse technology stacks and distributed teams.
  • Ability to translate technical security findings into actionable recommendations that reduce business risk.
Education & Preferred Qualifications
  • Degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline.
  • 12 years or more of experience in application security, cloud security, cybersecurity architecture, threat modeling, or related disciplines, with at least 7 years of hands‑on cybersecurity experience preferred.
  • Demonstrated experience conducting threat modeling exercises for enterprise applications, APIs, cloud platforms, and distributed systems.
  • Strong expertise in application security principles, secure software development lifecycles, OWASP Top 10, API security, and secure coding practices.
  • Experience assessing and securing cloud environments across AWS, Azure, and/or Google Cloud Platform.
  • Knowledge of microservices, containers, Kubernetes, CI/CD pipelines, DevSecOps practices, and modern software architectures.
  • Experience with threat modeling methodologies such as STRIDE, MITRE ATT&CK, attack trees, and adversary‑based risk analysis.
  • Professional certifications such as CISSP, CCSP, CSSLP, GWAPT, GWEB, AWS Security Specialty, Azure Security Engineer, or equivalent security certifications are highly desirable.
  • Experience within financial services or other highly regulated industries is preferred.
Additional Requirements
  • Ability to effectively collaborate with development, engineering, architecture, and cybersecurity teams.
  • Strong written and verbal communication skills with the ability to present technical findings to both technical and non‑technical audiences.
  • Limited travel may be required based on business needs.
Work Requirements

Hybrid: Expected to work in accordance with State Street's hybrid work model.

Shift: Standard business hours with flexibility to support global stakeholders across multiple time zones.

Salary Range

$120,000 – $202,500 Annual.

Benefits

Employees are eligible to participate in State Street’s comprehensive benefits program, which includes a retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, and long‑term disability; paid‑time off; an Employee Assistance Program; incentive compensation; and eligibility for tax‑advantaged savings plans.

Equal Opportunity Employer

We are committed to fostering an inclusive workplace and consider all qualified applicants regardless of race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, or other characteristics protected by applicable law.

Job Application Disclosure

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law may be subject to criminal penalties and civil liability.

Job ID

R-793830

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Threat Modeler
Senior Threat Modeler

State Street • Clifton (NJ)

Hybrid
USD 120,000 - 203,000
Hybrid work model
Comprehensive benefits
Senior Threat Modeler
Senior Threat Modeler

State Street • Austin (TX)

Hybrid
USD 120,000 - 203,000
401K matching
Health insurance
Paid time off
Senior Threat Modeler
Senior Threat Modeler

State Street • Princeton (NJ)

Hybrid
USD 120,000 - 203,000
Hybrid work model
Competitive benefits
401(k) with company match
+1
Senior Threat Modeler: Secure-by-Design Architect
Senior Threat Modeler: Secure-by-Design Architect

State Street • Clifton (NJ)

Hybrid
USD 120,000 - 203,000
Hybrid work model
Comprehensive benefits
Senior Threat Modeler — Secure-by-Design Architect
Senior Threat Modeler — Secure-by-Design Architect

State Street • Princeton (NJ)

Hybrid
USD 120,000 - 203,000
Hybrid work model
Competitive benefits
401(k) with company match
+1
Senior Threat Modeler: Cloud & App Security Architect
Senior Threat Modeler: Cloud & App Security Architect

State Street • Austin (TX)

Hybrid
USD 120,000 - 203,000
401K matching
Health insurance
Paid time off
Senior Threat Modeler: Cloud, API & Secure Architecture
Senior Threat Modeler: Cloud, API & Secure Architecture

State Street • Devon (PA)

Hybrid
USD 120,000 - 203,000
Cyber Threat Modeler
Cyber Threat Modeler

ManpowerGroup Global, Inc. • Charlotte (NC), Town of Norway (WI)

On-site
USD 100,000 - 130,000
Opportunity to work on cutting-edge AI security solutions
Engagement with a dynamic and innovative security team
Potential for extension or full-time conversion
+2
Senior Cloud Security Architect
Senior Cloud Security Architect

State Street • Princeton (NJ)

Hybrid
USD 120,000 - 203,000
Senior Data Security Architect
Senior Data Security Architect

State Street • Quincy (MA)

Hybrid
USD 120,000 - 203,000
401K with company match
Health insurance
Paid time off
+1