Job Overview
Threat Modeler with Development background in Toronto, ON.
Core Responsibilities
- Conduct threat modeling, identify attack vectors and vulnerabilities using CAPEC, ATT&CK, STRIDE.
- Perform application security controls for web, API, mobile, and AI.
- Design application security architecture, implement DevSecOps, and integrate secure coding practices.
- Manage application architecture (SPA, REST APIs, SOAP APIs, mobile) with a focus on secure design.
- Oversee cloud security architecture, design, implementation, and operations for AWS/GCP, including IAM controls such as OAuth 2.0, OIDC, and JWT.
- Perform security risk assessments of applications concerning design and code.
- Work with PostgreSQL and query/optimize data structures.
- Contribute to system architecture and design discussions.
- Automate workflows by scripting to reduce manual effort.
- Apply DevOps practices suc...