BMO Logo

BMO

Penetration Tester

Posted 22 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in TX, USA
89K-166K Annually
Senior level
Remote
Hiring Remotely in TX, USA
89K-166K Annually
Senior level
Perform deep, manual penetration tests of network, cloud, Active Directory and AI environments; scope engagements, execute tests, write reports, advise on remediation and secure development, and mentor junior testers while aligning work to regulatory frameworks.
The summary above was generated by AI

Application Deadline:

08/27/2026

Address:

VIRTUAL43 - HomeRes - TX

Job Family Group:

Technology

Join a team where your work goes beyond checklists protecting critical Network and Cloud environments with real business and regulatory impact.  Why join this team?

  • High-impact, meaningful work

  • Directly influence the security of Network\Cloud environments and AI solutions that support applications that matter to customers, regulators, and the business.

  • Depth over volume
    Focus on deep, manual penetration testing (Network, Cloud, and AI with human in the loop)—not automated, scanner-driven assessments.

  • Accelerated technical growth
    Work in complex, enterprise-scale environments that expose you to advanced architectures and evolving threats.

  • End-to-end ownership
    Engage across the full lifecycle: scoping → testing → reporting → remediation, with visibility and influence throughout.

  • Modern tools and techniques
    Use advanced testing tools to enhance testing depth and efficiency.

  • More meaningful engagements
    Experience fewer, higher-quality engagements versus consulting-style, high-volume work.

  • Ongoing training expensed

CORE Responsibilities:

  • The Penetration Tester reports to the Sr. Manager of Network and Strategic Penetration Testing and assists with the security testing activities for BMO network, cloud, and AI technologies. The role will be responsible for the execution and coordination of ethical hacking to identify weaknesses and areas for improvement.

  • Penetration Testing - Assists in delivery of security testing projects according to a structured process, to include writing test reports. This may include oversight and/or execution of the configuration and deployment of security testing software and application of results to security analysis. Assists with the execution of highly technical/analytical security assessments of Active Directory environments, network infrastructure, cloud environments, and AI technologies, including manual, custom and industry known attack methods using a risk-based intelligence-led methodology. Identifies potential misuse scenarios. Advises on secure development practices.

  • Subject Matter Expertise - Provides technical leadership to business areas as a Security Testing subject matter expert. Assists with efforts on the execution of security testing operations to include pre-engagement (scoping), engagement (testing) and post-engagement activities (reporting).

  • Information Security Risk Management - Works with leadership to mature security testing team capabilities including reporting and remediation guidance in alignment with local and global regulatory requirements. Identifies security gaps and deficiencies by conducting risk assessments; able to recommend corrective action of identified vulnerabilities and weaknesses. Assists with the execution of planning, testing, tracking, and advises on necessary risk acceptance for identified security risks. 

  • Team Leadership – Assists security testing activities aimed at exploiting vulnerabilities in order to enhance the security of BMO network, cloud, and AI technologies. Works with management and peers to foster the development of less experienced Security Testing Consultants.

  • Performs hands-on penetration testing for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs

  • Provides technical consultation to business areas as a Security Testing subject matter expert.

  • Assists with efforts on the execution of security testing operations to include pre-engagement (scoping), engagement (testing) and post-engagement activities).

  • Understands and can explain to others the core processes, risks and mitigation techniques for identified security gaps.

  • Develops and champions information security best practices, including staying abreast of industry information security and business trends through participation in professional associations.

  • Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.

  • Bachelor’s degree in Information Security, Information Technology, Information Systems Management, Computer Science, Engineering or related field(s) or equivalent demonstrated work experience.

  • Strong written and verbal skills with the ability to present complex technical observations to a non-technical audience.

  • Good time management skills; the ability to commit and adhere to time-sensitive deliverables.

  • Ability to work remotely, with or without others, take direction, and be a self-starter that takes initiative

KEY SKILLS:

- Min of 3+ years experience with Manual Penetration Testing of Networks, Cloud Environments. This includes strong exposure for testing in the following areas:  

  • Active Directory Environments and associated vulnerabilities and exploitation techniques

  • Cloud Environments and associated vulnerabilities in commonly used features utilized in large multi-tenant and hybrid enterprise environments

  • Strong proficiency with security testing tools and penetration testing Linux distributions such as Kali

  • Deep practical knowledge of applying the Mitre Attack framework

- Ability to identify and exploit vulnerabilities in Active Directory environments and Cloud workflows as well as multi-step attack paths

- Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. OSCP, OSEP, HackTheBox Cloud security testing certificates, etc)

- Network and Cloud architecture understanding

- Proficiency in at least one scripting language

- Ability in documenting reproducible steps for technical accurate findings

- Experience with security testing of agentic AI solution is a plus

- Experience with security testing of CI/CD pipelines is a plus

Additional Information:

Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Leads the development of information security strategy by understanding business processes, policies, information and information systems. Builds exceptional relationships with internal and external stakeholders. Ensures that requirements and solutions align to a real business need, are approved by all relevant stakeholders, and meets essential information security standards. Provides thought leadership, promotes new processes and methodologies and emerging technologies, with the flexibility to align to the unique requirements of the business/group and deliverables.

  • Acts as a trusted advisor to assigned business/group.

  • Assists in the development of strategic plans.

  • Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.

  • Supports the execution of strategic initiatives in collaboration with internal and external stakeholders.

  • Helps determine business priorities and best sequence for execution of business/group strategy.

  • Breaks down strategic problems, and analyses data and information to provide insights and recommendations.

  • Acts as the day to day contact for vendors; supports the implementation, maintenance, and sustainment of vendor solutions.

  • Understands the strategy, plans, activities and needs of all stakeholders and translates those business needs into solutions and makes recommendations.

  • Provides advice, counsel and support on information security matters and recommends solutions to assigned business/group leaders on principles, frameworks, programs, approaches, trends, legislation and regulatory requirements including interpretation of policy and identification and management of risk.

  • Builds credibility and influences/negotiates effectively to drive business performance through development and delivery of information security solutions.

  • Tracks metrics and milestones, providing recommendations for resolution and escalating as appropriate when issues arise.

  • Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.

  • Promotes process improvements and methodologies; keeps emerging information security issues and trends in mind and ensures standards are followed.

  • Creates professional presentations and deliver them in a meaningful concise way.

  • Assesses information security impact to a project’s benefits and risks when scope changes.

  • Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.

  • Gathers, examines and interprets data and information to extract meaningful insights, answer business questions and provide actionable recommendations.

  • Assists with continuous improvement activities and root cause analysis with the goal of strengthening information security capabilities.

  • Ensures consistent, high quality practices/work and the achievement of business results in alignment with business/group strategies and with productivity goals.

  • Focus is primarily on business/group within BMO; may have broader, enterprise-wide focus.

  • Provides specialized consulting, analytical and technical support.

  • Exercises judgment to identify, diagnose, and solve problems within given rules.

  • Works independently and regularly handles non-routine situations.

  • Broader work or accountabilities may be assigned as needed.

  • Take measured risks while protecting the bank by applying our Risk Management Framework in the execution of your role, in line with our Risk Culture and within our approved Risk Appetite, making sound and risk informed decisions that align to business strategy, protect assets, and adhere to applicable policy documents (Frameworks, Policies, Standards, Procedures and Supporting documents), laws and regulations.

    Qualifications:

  • Typically between 4 - 7 years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experience.

  • Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).

  • Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002, Payment Card Industry (PCI) Data Security Standard (DSS), etc. - In-depth.

  • Experience in information security concepts and methodology.

  • Knowledge of business analysis, project delivery practices and standards across the project lifecycle - In-depth.

  • Knowledge of information security processes, procedures and controls - In-depth.

  • Understanding of and problem solving ability for information security issues within their business group - Working.

  • Understanding of information security risk and regulatory requirements - Working.

  • Deep knowledge and technical proficiency gained through extensive education and business experience.

  • Verbal & written communication skills - In-depth.

  • Collaboration & team skills - In-depth.

  • Analytical and problem solving skills - In-depth.

  • Influence skills - In-depth.

  • Data driven decision making - In-depth.

Salary:

$88,800.00 - $165,600.00

Pay Type:

Salaried

The above represents BMO Financial Group’s pay range and type.

Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group’s expected target for the first year in this position.

BMO Financial Group’s total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit: https://jobs.bmo.com/global/en/Total-Rewards

About Us

At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.

As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact.  We strive to help you make an impact from day one – for yourself and our customers.  We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset.

To find out more visit us at http://jobs.bmo.com/us/en

BMO is proud to be an equal employment opportunity employer. We evaluate applicants without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or any other legally protected characteristics. We also consider applicants with criminal histories, consistent with applicable federal, state and local law.

BMO is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please send an e-mail to [email protected] and let us know the nature of your request and your contact information.

Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.

Similar Jobs

2 Days Ago
Remote
U.S.
Senior level
Senior level
Professional Services • Security • Software • Consulting
The Penetration Tester will conduct web application penetration tests, identify vulnerabilities, and provide remediation guidance to stakeholders. Candidates should have strong expertise in various security domains such as cloud and network security.
Top Skills: Cloud SecurityGoJavaJavaScriptMobile Application SecurityNetwork SecurityPowershellPythonRubySource CodeWeb Application Security
2 Days Ago
Remote
U.S.
Senior level
Senior level
Professional Services • Security • Software • Consulting
As a Penetration Tester at Bishop Fox, you'll perform security assessments on applications and networks, advise clients, and solve technical challenges.
Top Skills: AWSGoJavaJavaScriptLinuxmacOSPowershellPythonRubyWindows
3 Days Ago
Remote
United States
Senior level
Senior level
Security • Cybersecurity
Conduct penetration tests and security assessments on IoT, ICS, and automotive systems, providing actionable insights and risk mitigation guidance for clients.
Top Skills: AWSBashBinary NinjaCC++EmmcFirmware Reverse EngineeringGhidraI2CIcsIotJtagNand FlashOtPenetration TestingPythonSbomSpiSwdUart

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account