Government Careers
  • Senior Threat Modeling Architect | Remote

  • SAMPRASOFT
  • Mc Lean, Virginia 22101 United States View Map

Summary

Senior Threat Modeling Architect

This position may be offered to a candidate authorized to work in the US for his/her/their stated employer, without any restrictions which would prevent the candidate from working on the proposed assignment for the duration of the assignment period.

Must Haves: 5+ years of experience with Threat Modeling for applications, software Developing experience

Seeking a Senior Threat Modeling architect to join our Information Security Architecture team. The Senior Threat Modeling architect will partner closely and collaboratively with Enterprise Architecture (EA), Developers, Platform Owners, and other areas of the firm to help ensure Freddie Mac provides secure services and solutions.

Duties and Responsibilities:

  • Support the Security Architecture team to develop and mature a Threat Modeling Program by defining processes, procedures, controls, KRI's/KPI's, etc., that identify threats early in the development process reducing risks prior to deployment.
  • Hold brown bag sessions to educate developers on the value and benefit that they and the firm derive by identifying threats early.
  • Develop training material for how to engage the Threat Management service, make use of technologies, and interpret findings.
  • Drive beneficial security change into the business through supporting Developers with creation of threat models for their applications and remediation of potential threats, balancing risk against business need.
  • Remain aware of change to relevant frameworks such as MITRE, STRIDE, etc. and refresh the service accordingly.
  • Provide architectural oversight and guidance to help ensure the secure implementation and use of Freddie Mac services and solutions, and consumption of Threat Modeling service; including the transition to a predominantly automated environment and secure DevOps.
  • Advise and Contribute to Strategy and Roadmaps.
  • Work with the InfoSec functional teams in the development of the Information Security strategy and roadmap, including and with focus on Threat Modeling; liaison and consult with Enterprise Architecture, IT and the business for ongoing input and awareness.
  • Assess Security Risk from an Architectural Perspective and Apply a Risk-Based Approach to Security.

Qualifications:

  • 7+ years of Information Technology experience, preferably within the financial services industry
  • Minimum of 5 years' experience working as an Information Security Professional, preferably within the architecture or engineering disciplines
  • Minimum of 3 years' experience working as an Information Security Threat Modeling subject matter expert at a senior level
  • Senior level experience or equivalent knowledge in architecting secure solutions across major domains including:
    • Cloud
    • Network
    • Data
    • Application
    • End-Point (User and Server)
    • Mobile Device
  • Senior level experience developing and implementation of key Information Security services such as:
    • Identity and Access Management (IAM)
    • Data Protection (Encryption, DLP, Data Masking,...)
    • Micro-segmentation
    • Zero Trust
    • Continuous Security Monitoring
  • Thorough understanding of industry standard frameworks such as ISO 27001/27002, NIST, CIS, MITRE ATT&CK
  • Executive presence with very strong leadership attributes, business acumen, analytical, problem solving and verbal and written communication skills
  • Passion for leading change and ability to bring others along
  • (Desirable) CISSP (+ ISSAP), CCSP
  • (Desirable) One or more security-related certifications associated with AWS, GCP or Azure

Keys to Success in this Role:

  • Organizational, influence / conflict resolution, verbal and written communication and leadership skills.
  • Ability to work with others.
  • Self-motivated with attention to detail.
  • Excellent presentation, program management and relationship management skills.

Job Description

Senior Threat Modeling Architect

This position may be offered to a candidate authorized to work in the US for his/her/their stated employer, without any restrictions which would prevent the candidate from working on the proposed assignment for the duration of the assignment period.

Must Haves: 5+ years of experience with Threat Modeling for applications, software Developing experience

Seeking a Senior Threat Modeling architect to join our Information Security Architecture team. The Senior Threat Modeling architect will partner closely and collaboratively with Enterprise Architecture (EA), Developers, Platform Owners, and other areas of the firm to help ensure Freddie Mac provides secure services and solutions.

Duties and Responsibilities:

  • Support the Security Architecture team to develop and mature a Threat Modeling Program by defining processes, procedures, controls, KRI's/KPI's, etc., that identify threats early in the development process reducing risks prior to deployment.
  • Hold brown bag sessions to educate developers on the value and benefit that they and the firm derive by identifying threats early.
  • Develop training material for how to engage the Threat Management service, make use of technologies, and interpret findings.
  • Drive beneficial security change into the business through supporting Developers with creation of threat models for their applications and remediation of potential threats, balancing risk against business need.
  • Remain aware of change to relevant frameworks such as MITRE, STRIDE, etc. and refresh the service accordingly.
  • Provide architectural oversight and guidance to help ensure the secure implementation and use of Freddie Mac services and solutions, and consumption of Threat Modeling service; including the transition to a predominantly automated environment and secure DevOps.
  • Advise and Contribute to Strategy and Roadmaps.
  • Work with the InfoSec functional teams in the development of the Information Security strategy and roadmap, including and with focus on Threat Modeling; liaison and consult with Enterprise Architecture, IT and the business for ongoing input and awareness.
  • Assess Security Risk from an Architectural Perspective and Apply a Risk-Based Approach to Security.

Qualifications:

  • 7+ years of Information Technology experience, preferably within the financial services industry
  • Minimum of 5 years' experience working as an Information Security Professional, preferably within the architecture or engineering disciplines
  • Minimum of 3 years' experience working as an Information Security Threat Modeling subject matter expert at a senior level
  • Senior level experience or equivalent knowledge in architecting secure solutions across major domains including:
    • Cloud
    • Network
    • Data
    • Application
    • End-Point (User and Server)
    • Mobile Device
  • Senior level experience developing and implementation of key Information Security services such as:
    • Identity and Access Management (IAM)
    • Data Protection (Encryption, DLP, Data Masking,...)
    • Micro-segmentation
    • Zero Trust
    • Continuous Security Monitoring
  • Thorough understanding of industry standard frameworks such as ISO 27001/27002, NIST, CIS, MITRE ATT&CK
  • Executive presence with very strong leadership attributes, business acumen, analytical, problem solving and verbal and written communication skills
  • Passion for leading change and ability to bring others along
  • (Desirable) CISSP (+ ISSAP), CCSP
  • (Desirable) One or more security-related certifications associated with AWS, GCP or Azure

Keys to Success in this Role:

  • Organizational, influence / conflict resolution, verbal and written communication and leadership skills.
  • Ability to work with others.
  • Self-motivated with attention to detail.
  • Excellent presentation, program management and relationship management skills.
Government Careers

Government Careers

Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.

Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.

Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.

Show more

MORE JOBS