Cybersecurity Senior Architect - Application Threat Modeler
TruistAbout the role
The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see your application status and any communications. If you already have a profile with us, you can log in to check status.
If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).
Regular or Temporary:
RegularLanguage Fluency: English (Required)
Work Shift:
1st shift (United States of America)Please review the following job description:
The Cybersecurity Sr. Architect conducts threat modeling activities utilizing the Process of Attack Simulation Threat Analysis (PASTA) methodology, to create an offensive security perspective for technology delivery teams with the goal of creating visibility and context to threats and vulnerabilities to applications and solutions. Analyze business requirements, while validating security specifications, and assess security solutions that support core organizational functions, and assure their confidentiality, integrity and high availability. Principally works, under limited supervision, with Corporate Information Security (CIS) personnel, Line of Business (LOB) personnel, external vendors, and internal IT Services personnel including Enterprise Architects, Application & Data Services personnel and other IT Operations Services teams.Essential Duties and Responsibilities
The following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.
Threat Modeling & Risk Identification
• Conduct structured threat modeling for applications, APIs, and services across the Technology Delivery Lifecycle (TDLC)
• Identify potential threats, attack vectors, design flaws, and vulnerabilities that may impact delivery timelines, system security, or regulatory compliance
• Assess risks to confidentiality, integrity, availability, and resiliency of business-critical systems
Integration into TDLC
• Embed security-by-design practices into each TDLC phase (requirements, design, build, test, deploy)
• Collaborate with delivery teams to ensure security controls and mitigations are defined early and consistently implemented
• Track and validate mitigation strategies throughout delivery cycles to ensure secure releases
Risk Communication & Reporting
• Document threat models, risk scenarios, and security design considerations in clear, actionable reports.
• Deliver tailored risk communication to technical teams, product owners, and executive stakeholders
• Provide risk ratings and recommendations to support informed go/no-go release decisions
Collaboration & Influence
• Partner with architects, engineers, product managers, and delivery leads to balance security and business objectives.
• Act as a subject matter expert on secure application design, emerging attack vectors, and industry frameworks (e.g., STRIDE, PASTA, OWASP).
• Mentor TDLC team members on threat modeling practices and proactive risk identification.
Continuous Improvement
• Refine threat modeling processes, frameworks, and automation for scalability across delivery portfolios.
• Incorporate real-world threat intelligence, incident data, and vulnerability management findings into TDLC risk assessments.
• Contribute to the creation of reusable playbooks, secure design patterns, and threat libraries for enterprise-wide adoption.
Qualifications
Required Qualifications:
The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
• Bachelor's degree in a technical or business field, or equivalent education and related training
• Eight years of demonstrated experience of systems engineering and/or architecture in at least one of the information security ar
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s