Penetration Tester @BMO
All Others
Salary usd 88,800 - 16..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 5d ago

[Hiring] Penetration Tester @BMO

5d ago - BMO is hiring a remote Penetration Tester. πŸ’Έ Salary: usd 88,800 - 165,600 per year πŸ“Location: USA

Role Description

Join a team where your work goes beyond checklists protecting critical Network and Cloud environments with real business and regulatory impact. Why join this team?

  • High-impact, meaningful work
  • Directly influence the security of Network/Cloud environments and AI solutions that support applications that matter to customers, regulators, and the business.
  • Depth over volume
  • Focus on deep, manual penetration testing (Network, Cloud, and AI with human in the loop)β€”not automated, scanner-driven assessments.
  • Accelerated technical growth
  • Work in complex, enterprise-scale environments that expose you to advanced architectures and evolving threats.
  • End-to-end ownership
  • Engage across the full lifecycle: scoping β†’ testing β†’ reporting β†’ remediation, with visibility and influence throughout.
  • Modern tools and techniques
  • Use advanced testing tools to enhance testing depth and efficiency.
  • More meaningful engagements
  • Experience fewer, higher-quality engagements versus consulting-style, high-volume work.
  • Ongoing training expensed

The Penetration Tester reports to the Sr. Manager of Network and Strategic Penetration Testing and assists with the security testing activities for BMO network, cloud, and AI technologies. The role will be responsible for the execution and coordination of ethical hacking to identify weaknesses and areas for improvement.

  • Penetration Testing: Assists in delivery of security testing projects according to a structured process, to include writing test reports. This may include oversight and/or execution of the configuration and deployment of security testing software and application of results to security analysis. Assists with the execution of highly technical/analytical security assessments of Active Directory environments, network infrastructure, cloud environments, and AI technologies, including manual, custom and industry known attack methods using a risk-based intelligence-led methodology. Identifies potential misuse scenarios. Advises on secure development practices.
  • Subject Matter Expertise: Provides technical leadership to business areas as a Security Testing subject matter expert. Assists with efforts on the execution of security testing operations to include pre-engagement (scoping), engagement (testing) and post-engagement activities (reporting).
  • Information Security Risk Management: Works with leadership to mature security testing team capabilities including reporting and remediation guidance in alignment with local and global regulatory requirements. Identifies security gaps and deficiencies by conducting risk assessments; able to recommend corrective action of identified vulnerabilities and weaknesses. Assists with the execution of planning, testing, tracking, and advises on necessary risk acceptance for identified security risks.
  • Team Leadership: Assists security testing activities aimed at exploiting vulnerabilities in order to enhance the security of BMO network, cloud, and AI technologies. Works with management and peers to foster the development of less experienced Security Testing Consultants. Performs hands-on penetration testing for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs.

Qualifications

  • Bachelor’s degree in Information Security, Information Technology, Information Systems Management, Computer Science, Engineering or related field(s) or equivalent demonstrated work experience.
  • Strong written and verbal skills with the ability to present complex technical observations to a non-technical audience.
  • Good time management skills; the ability to commit and adhere to time-sensitive deliverables.
  • Ability to work remotely, with or without others, take direction, and be a self-starter that takes initiative.
  • Min of 3+ years experience with Manual Penetration Testing of Networks, Cloud Environments.
  • Strong exposure for testing in the following areas:
    • Active Directory Environments and associated vulnerabilities and exploitation techniques.
    • Cloud Environments and associated vulnerabilities in commonly used features utilized in large multi-tenant and hybrid enterprise environments.
    • Strong proficiency with security testing tools and penetration testing Linux distributions such as Kali.
    • Deep practical knowledge of applying the Mitre Attack framework.
    • Ability to identify and exploit vulnerabilities in Active Directory environments and Cloud workflows as well as multi-step attack paths.
    • Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. OSCP, OSEP, HackTheBox Cloud security testing certificates, etc).
    • Network and Cloud architecture understanding.
    • Proficiency in at least one scripting language.
    • Ability in documenting reproducible steps for technical accurate findings.
    • Experience with security testing of agentic AI solution is a plus.
    • Experience with security testing of CI/CD pipelines is a plus.

Requirements

  • Typically between 4 - 7 years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experience.
  • Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).
  • Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002, Payment Card Industry (PCI) Data Security Standard (DSS), etc. - In-depth.
  • Experience in information security concepts and methodology.
  • Knowledge of business analysis, project delivery practices and standards across the project lifecycle - In-depth.
  • Knowledge of information security processes, procedures and controls - In-depth.
  • Understanding of and problem solving ability for information security issues within their business group - Working.
  • Understanding of information security risk and regulatory requirements - Working.
  • Deep knowledge and technical proficiency gained through extensive education and business experience.
  • Verbal & written communication skills - In-depth.
  • Collaboration & team skills - In-depth.
  • Analytical and problem solving skills - In-depth.
  • Influence skills - In-depth.
  • Data driven decision making - In-depth.

Benefits

  • Salary: $88,800.00 - $165,600.00
  • Pay Type: Salaried
  • BMO Financial Group’s total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards.
  • BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans.
  • To view more details of our benefits, please visit: Total Rewards
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Penetration Tester @BMO
All Others
Salary usd 88,800 - 16..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 5d ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 140,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 140,000+ Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 140,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews
Unlock All Jobs Now

Maybe later