Point your AI agent at freehire and let it find you a job.

Get the CLI →

emagine

NewBe an early applicant

IT Security Consultant - Threat Modeling Activities

Posted Updated
Discussion

Summary

An IT Security Consultant supporting threat modeling activities: running workshops with application/platform teams, identifying assets, trust boundaries, attack surfaces, and AI/LLM-related threats, and documenting risks and mitigations using STRIDE-based methodology. B2B contract at 130 PLN/h, hybrid with 3 office days per week in Gdańsk/Tricity or Warsaw.

Contract: B2B

Rate: 130 PLN/h

Location: Gdańsk/Tricity OR Warsaw

Hybrid mode: 3 days per week at the office

Language: English (fluent)

Summary: The role of the IT Security Consultant focuses on enhancing cybersecurity by supporting threat modeling activities, specifically in assessing application-level security concerns related to emerging AI threats.

Main Responsibilities:

  • Support threat modeling workshops with application and platform teams.

  • Assist in identifying assets, trust boundaries, attack surfaces, threats, and security risks.

  • Create and update threat models using the approved tooling, methodology, and provided templates.

  • Review solution designs and architecture documentation with support from senior team members.

  • Assist in mapping relevant threat scenarios to application components and data flows.

  • Document identified threats, risks, assumptions, and proposed mitigation actions.

  • Collaborate with development and security teams to collect information and follow up on remediation activities.

  • Track identified threats, mitigation actions, and remediation status.

Key Requirements:

  • Knowledge of IT Security Architecture principles.

  • General understanding of security threats related to AI agents, machine learning systems, and large language models.

  • Basic knowledge of threat modeling methodologies, particularly STRIDE.

  • Ability to support the identification of assets, trust boundaries, attack surfaces, threat actors, and abuse cases under guidance.

  • Ability to use and update existing threat models and threat libraries.

  • Ability to support the mapping of threats to predefined security controls and remediation actions.

Nice to Have:

  • Ability to support the translation of technical threats into understandable business risks under guidance.

  • Basic knowledge of the OWASP Top 10 for LLM Applications and MITRE ATLAS, with the ability to use these frameworks as references during threat assessments.

Skills

What Senior Security jobs ask for — and how much of it you have →

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available