Lead security testing activities for BMO's network, cloud, and AI technologies through deep, manual penetration testing. Execute ethical hacking across the full lifecycle from scoping to remediation, with focus on enterprise-scale environments and regulatory compliance.
Minimum 5+ years experience with manual penetration testing of networks and cloud environments
Strong proficiency with Active Directory environments and associated vulnerabilities
Deep experience with cloud environments in large multi-tenant and hybrid enterprise environments
Strong proficiency with security testing tools and penetration testing Linux distributions such as Kali
Deep practical knowledge of applying the MITRE ATT&CK framework
Strong network and cloud architecture understanding
Proficiency in at least one scripting language
Ability to document reproducible steps for technically accurate findings
5-8 years of experience in information systems, software development, or information security
Strong written and verbal skills to present complex technical observations to non-technical audiences
Bachelor's degree in Information Security, IT, Computer Science, Engineering or related field or equivalent experience
Preference for candidates with at least one security certification such as OSCP, OSEP, or HackTheBox Cloud
Execute security testing projects according to structured processes including writing test reports
Perform highly technical security assessments of Active Directory, network infrastructure, cloud, and AI technologies
Apply manual, custom and industry-known attack methods using risk-based intelligence-led methodology
Provide technical leadership as Security Testing subject matter expert to business areas
Assist with pre-engagement scoping, engagement testing, and post-engagement reporting activities
Foster development of less experienced Security Testing Consultants
Mature security testing team capabilities including reporting and remediation guidance
Identify security gaps through risk assessments and recommend corrective actions
Advise on necessary risk acceptance for identified security risks
Develop and champion information security best practices
Stay abreast of industry security and business trends through professional associations
Work remotely in Canada within EST or CST time zones
Reports to Sr. Manager of Penetration Testing
Fewer, higher-quality engagements versus consulting-style high-volume work
Ongoing training expensed
Application deadline is 10/01/2026
Job family group is Technology