[Remote] Penetration Testing Consultant

Remote Full-time
Note: The job is a remote job and is open to candidates in USA. BMO Bank N.A. is seeking a Penetration Testing Consultant to provide high-impact information security consulting services. The role involves conducting manual penetration testing and collaborating with stakeholders to enhance the security of critical financial applications.ResponsibilitiesProvides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIsLiaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIsUnderstands and can explain to others the core processes, risks and mitigation techniques for designated areasDevelops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associationsFacilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risksActs as a trusted advisor to assigned business/groupAssists in the development of strategic plansUnderstands and can explain to others the core processes, risks and mitigation techniques for designated areasSupports the execution of strategic initiatives in collaboration with internal and external stakeholdersHelps determine business priorities and best sequence for execution of business/group strategyBreaks down strategic problems, and analyses data and information to provide insights and recommendationsActs as the day to day contact for vendors; supports the implementation, maintenance, and sustainment of vendor solutionsUnderstands the strategy, plans, activities and needs of all stakeholders and translates those business needs into solutions and makes recommendationsProvides advice, counsel and support on information security matters and recommends solutions to assigned business/group leaders on principles, frameworks, programs, approaches, trends, legislation and regulatory requirements including interpretation of policy and identification and management of riskBuilds credibility and influences/negotiates effectively to drive business performance through development and delivery of information security solutionsTracks metrics and milestones, providing recommendations for resolution and escalating as appropriate when issues ariseFacilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risksPromotes process improvements and methodologies; keeps emerging information security issues and trends in mind and ensures standards are followedCreates professional presentations and deliver them in a meaningful concise wayAssesses information security impact to a project’s benefits and risks when scope changesDevelops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associationsGathers, examines and interprets data and information to extract meaningful insights, answer business questions and provide actionable recommendationsAssists with continuous improvement activities and root cause analysis with the goal of strengthening information security capabilitiesEnsures consistent, high quality practices/work and the achievement of business results in alignment with business/group strategies and with productivity goalsFocus is primarily on business/group within BMO; may have broader, enterprise-wide focusProvides specialized consulting, analytical and technical supportExercises judgment to identify, diagnose, and solve problems within given rulesWorks independently and regularly handles non-routine situationsBroader work or accountabilities may be assigned as neededTake measured risks while protecting the bank by applying our Risk Management Framework in the execution of your role, in line with our Risk Culture and within our approved Risk Appetite, making sound and risk informed decisions that align to business strategy, protect assets, and adhere to applicable policy documents (Frameworks, Policies, Standards, Procedures and Supporting documents), laws and regulationsSkillsMin of 3+ years experience with Manual Penetration Testing experience in Web or APIA solid grasp of HTTP/S protocols, headers, cookies, sessions, and CORS behavior within your web testing experienceExperience testing authentication and authorization mechanisms (OAuth, JWT, session flaws, IDOR/BOLA)Strong proficiency with Burp Suite Professional, OWASP ZAP, IBM's APP SCAN, (proxying, repeater, intruder, extensions)Deep practical knowledge of OWASP Top 10 (Web + API) and common vulnerabilitiesAbility to identify and exploit business logic vulnerabilities and multi-step attack pathsSecure coding and architecture understandingProficiency in at least one scripting languageProficiency in documenting reproducible steps for technical accurate findingsTypically between 4 - 7 years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experienceUnderstanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002, Payment Card Industry (PCI) Data Security Standard (DSS), etc. - In-depthExperience in information security concepts and methodologyKnowledge of business analysis, project delivery practices and standards across the project lifecycle - In-depthKnowledge of information security processes, procedures and controls - In-depthUnderstanding of and problem solving ability for information security issues within their business group - WorkingUnderstanding of information security risk and regulatory requirements - WorkingDeep knowledge and technical proficiency gained through extensive education and business experienceVerbal & written communication skills - In-depthCollaboration & team skills - In-depthAnalytical and problem solving skills - In-depthInfluence skills - In-depthData driven decision making - In-depthPreference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. OSCP, GMOB, GWAPT, OSWE)Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS)BenefitsBMO Financial Group’s total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards.BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans.In-depth training and coachingManager support and network-building opportunitiesCompany OverviewWe’re a bank, but there’s more to it than that. ​ When you join BMO, it opens a world of opportunities. It was founded in 1817, and is headquartered in Toronto, Ontario, CAN, with a workforce of 10001+ employees. Its website is http://www.bmo.com.Company H1B SponsorshipBMO has a track record of offering H1B sponsorships, with 3 in 2026, 7 in 2025, 2 in 2024, 6 in 2023, 4 in 2022, 2 in 2021, 2 in 2020. Please note that this does not guarantee sponsorship for this specific role.

Apply Now →

Similar Jobs

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote

USPS Office Helper

Remote

Senior Manager, Operations - GHANA

Remote

Vice President, Sales and Strategic Accounts

Remote

[Remote] Clinical Data Analyst, Home Health, Limited Term

Remote

Digital Customer Success Manager – SaaS Solutions, Front‑End Innovation & Scalable Engagement Strategies

Remote

Senior Manager, Social Channel and Creator Marketing - Meta and Pinterest MSDS job at Henkel in Culver City, CA

Remote

Immediate Hiring: Urgently Require Personal Trainer in Kennett

Remote

RN Health Care Facility Surveyor

Remote

Experienced Healthcare Customer Success Manager – Hospital Pharmacy Solutions

Remote

Remote Data Entry Specialist – High‑Volume Workforce Management (WFM) Operations for arenaflex – $26/hr – Immediate Start

Remote

[Remote/WFM] Social Media Moderator - Facebook (Remote)

Remote
← Back