Senior Threat Modelling Analyst

Sky
Eh547Hh, United Kingdom
Today
Job Type
Permanent
Work Pattern
Full-time
Work Location
On-site
Seniority
Senior
Education
Degree
Posted
1 Jun 2026 (Today)

Benefits

25 days holiday Pension Private healthcare
We don't just believe in better. We make it happen. "

Better content. Better products. And better careers.""

"

Working in Tech, Product or Data at Sky is about building the next and the new. From broadband to broadcast, streaming to mobile, Sky Stream to Sky Glass, we never stand still. We optimise and innovate. We turn big ideas into the products, content and services millions of people love. And we do it all right here at Sky."

And we do it all right here at Sky.

Role/ Team overview"

Cyber Security

Our products, platforms and technologies are constantly evolving that's why keeping Sky safe from cyber-attacks is one of our top priorities. Our Cyber Security team helps the business grow while protecting our customers, colleagues and partners from increasingly sophisticated cyber threats. Our global team works across the UK, US & India. As the business adopts AI and autonomous technologies, the team plays a key role in ensuring these systems are designed and operated securely and responsibly. Join us and you'll get involved in tackling challenges and future threats in an ever-changing cyber landscape

What you'll do
  • You will bring strong technical knowledge to end-to-end threat modelling, with the ability to plan, facilitate, document and follow up on threat modelling activities with a high degree of independence.
  • You will apply your technical knowledge to threat modelling for AI-enabled systems, including LLM-based and agentic architectures, identifying risks introduced by autonomy, tool use, memory, and orchestration layers.
  • You will work with engineering and product teams to help define secure design patterns, guardrails, and mitigations for AI agents, such as least-privilege tool access and human-in-the-loop controls.
  • You will be expected to manage your workload with a good degree of independence, build familiarity with relevant industry practices and procedures, and take an active role in your ongoing development with support from your line manager and colleagues.
  • You will help promote the value Cyber brings to the business and support workshops and initiatives that build understanding across teams.
  • You will support and coach junior members of the team to help develop their skills, knowledge, and professional confidence.
  • You will support external departments by contributing to bespoke integrations and the effective sharing of information.
  • You will engage with cyber stakeholders, the wider business, and external partners to support the delivery of cyber services and initiatives.
  • You will be expected to continue building your understanding and knowledge in areas such as the following.
  • Regulatory requirements on our business. TSA, PCI, SWIFT, GDPR (not an exhaustive list)
  • Architectural domains. DLP, Cloud, IDAM, Logging & Monitoring (not an exhaustive list)
  • Departments and their verticals. CONTENT, CUSTOMER, ISP, PRODUCT, DIGITAL, DATA (not an exhaustive list)
What you'll bring
  • Experience working with enterprise-scale technology, ideally with a strong foundation in end-to-end security assessment practices.
  • A working understanding of AI-specific threat classes, such as prompt injection, model abuse, data leakage, insecure plugin or tool execution, and emergent agent behaviour, together with an interest in continuing to build knowledge in this rapidly evolving area.
  • A collaborative and professional approach, with behaviours that reflect the Sky Values.
  • A clear interest in cyber security, with a positive and thoughtful approach to the work and its impact on the business.
  • Experience working within a cyber security or information security environment, with exposure to technologies, compliance requirements, or regulatory frameworks that shape cyber services and decision-making.
  • Strong analytical, decision-making, verbal and written communication skills.
  • Strong collaboration skills, with the ability to share knowledge, work effectively with others, and support colleagues across the team.
  • A willingness to continue developing your skills and to share knowledge with others in the team.
Benefits and perks

There's one thing people can't stop talking about when it comes to life at Sky: the perks. Here's a taster:""
  • Free Sky TV or NOW package, including Sky Sports and Sky Cinema"""
  • Pension package"with up to 9% employer contribution
  • Private healthcare"with mental health support"
  • Aviva Digital GP and dental insurance"
  • Discounts on Sky products, including Sky Mobile, Sky Broadband, Sky Glass and Sky Protect""
  • Sharesave and Tech schemes"
  • A range of Sky VIP rewards and experiences""
"

How you'll work"

At Sky, we want to be a community that thrives by being together. Flexible working remains a key part of that. We want our people to have the best of both worlds - time working at home, as well as time in the office.

The hybrid working expectations for this role are 2 days in the office per week.

Your office space :

Osterley:

Our Osterley Campus is a 10-minute walk from Syon Lane train station. Or you can hop on one of our free shuttle buses that run to and from Osterley, Gunnersbury, Ealing Broadway and South Ealing tube stations. There's also plenty of bike shelters and showers.

On campus, you'll find 13 subsidised restaurants, cafes, and a Waitrose. You can keep in shape at our subsidised gym, catch the latest shows and movies at our cinema, get your car washed and even get pampered at our beauty salon.

Leeds:

Our spacious tech hub is under

Related Jobs

View all jobs

Senior Cyber Security Analyst

Picture More Ec1A1Bb, EC1A 1BB, United Kingdom
£80,000 – £90,000 pa Hybrid

Senior Penetration Tester

VIQU IT Horsham, West Sussex, United Kingdom
£70,000 – £80,000 pa Hybrid

Senior Penetration Tester

VIQU IT Recruitment Horsham, United Kingdom
£70,000 – £80,000 pa Hybrid

DevSecOps Consultant

Talent Smart Orchard Square, South Yorkshire, United Kingdom
£650 – £675 pd

Product Security Architect

SRT Marine Systems PLC Bristol, Bristol (county), United Kingdom
£75,000 – £110,000 pa Hybrid

Product Security Architect

SRT Marine Systems PLC Cardiff, South Glamorgan, CF10 2AF, United Kingdom
£75,000 – £110,000 pa Hybrid

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Cyber Security Jobs in the UK (2026 Guide)

Where to advertise cyber security jobs UK in 2026: the specialist boards, communities and channels that reach offensive, defensive and GRC security talent. The candidate pool is small, heavily vetted and in high demand across government, financial services, critical national infrastructure and the private sector simultaneously. Many of the strongest candidates hold active security clearances, are not actively job-searching through general platforms, and move primarily through specialist networks and trusted referrals. General job boards reach a broad audience but lack the specificity that security professionals expect. Specialist platforms, government-affiliated channels and cleared candidate networks each serve a different part of the market. This guide, published by CybersecurityJobs.tech, covers where to advertise cyber security roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Cyber Security Jobs UK 2026: What to Expect Over the Next 3 Years

Cyber Security Jobs UK 2026: roles, salaries and the threat intelligence, cloud security and zero-trust hiring trends shaping UK cyber careers. Cyber security is one of the few sectors where demand for talent has never once dipped. Every major technological shift of the past decade — cloud migration, remote working, AI adoption, the proliferation of connected devices — has expanded the attack surface that security professionals are expected to defend. And every expansion of that attack surface has generated more jobs. But the cyber security jobs market of 2026 is not simply a larger version of what it was three years ago. It is a structurally different market. The threats have evolved, the technologies used to combat them have changed, the regulatory environment has tightened considerably, and the roles being created reflect all of that. A job seeker who understands only the cyber security landscape of 2023 is already working with an outdated map. The candidates who will thrive over the next three years are those who understand where the sector is heading — which specialisms are attracting the most investment, which technologies are reshaping defensive and offensive security practice, and how the definition of a cyber security professional is broadening well beyond the traditional image of a network defender in a SOC. This article breaks down what the UK cyber security jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the curve.