Application Deadline:
09/24/2026
Address:
320 S Canal Street
Job Family Group:
Business Management
This role offers a unique opportunity to gain enterprise-wide exposure to IT and operational controls across areas such as cybersecurity, cloud, infrastructure, Capital Markets, Fraud, Wealth Management, and Personal Banking. As part of a high-impact control testing team, you will help validate that critical issues identified through regulatory reviews, audit findings, and internal assessments are fully resolved and sustainable. You'll work with experienced professionals across the bank, strengthen your expertise in risk and control frameworks , and build a strong foundation for future growth in IT Risk, Cybersecurity Governance, Audit, and Enterprise Controls.
This is a HYBRID ROLE based in our downtown Chicago office or Naperville office. Currently 2-3 days per week in-office. CORE SKILLS/Experience:- 3 years of IT controls testing experience (preferably ITGC, Cybersecurity and Cloud Platforms etc..) OR3 years experience in operational controls testing (preferably in areas such as Capital Markets, Fraud , Wealth Management and Personal Banking)
- Strong understanding of IT risk and control frameworks (e.g., COBIT, ITIL, ISO 27001, COSO, NIST, PCI DSS).
- Certifications such as CISA, CISM, CISSP, or CPA are considered an asset.
KEY Responsibilities:- Perform technical and procedural control testing across various security domains, including access management, change management, disaster recovery, BCP, IT operations, network security, vulnerability management, incident response, logging & monitoring, and endpoint security.
- Support the execution of compliance testing activities by working with control owners and cross-functional teams to gather evidence and validate controls.
- Former knowledge and/or experience within Enterprise Operations or other functional areas (Capital Markets, Wealth Management etc.) at any financial institution.
- Good understanding of key risks and control principles for operations environments including operational risk, regulatory compliance/AML risk, reputational risk and processing and execution risk.
- Identify and document control gaps, weaknesses, or emerging risks observed during testing activities.
- Track remediation activities and assist in validating the closure of identified issues.
- Execute manual and automated testing procedures to assess compliance with internal security standards and external regulatory requirements.
- Assess controls against established frameworks such as NIST 800-53, NIST CSF, ISO 27001, CIS Controls, SOX ITGC, and PCI-DSS.
- Contribute to strategic initiatives by providing testing insights, highlighting trends, and supporting decision-making through findings.
- Collaborate with stakeholders to ensure timely completion of testing activities and alignment on requirements and expectations.
- Support communication activities by preparing updates, documenting findings, and assisting in conveying results to relevant stakeholders.
- Analyze test results, identify root causes of issues, and provide input to help resolve control deficiencies.
- Execute assigned testing tasks end-to-end with a focus on accuracy, timeliness, and adherence to quality standards.
- Prepare and maintain testing documentation, including workpapers, evidence logs, and reports to support audit conclusions and findings.
- Provide input on control effectiveness and assist in documenting observations and issue descriptions.
- Maintain knowledge of business processes and cybersecurity controls while contributing to continuous improvement efforts.
- Work independently on assigned tasks, following established procedures and adapting to changing priorities as needed.
- Verbal & written communication skills - In-depth.
- Collaboration & team skills - In-depth.
- Analytical and problem solving skills - In-depth.
- Influence skills - In-depth.
- Data driven decision making - In-depth.
Additional Details:
Executes testing to provide insights and recommendations on test results, findings, identified issues, re-performance testing, and continuous improvement insights. Executes testing, monitoring and operational activities of various complexity based on assigned portfolio ensuring adherences to established service levels and standards.
- Provides advice and guidance on control effectiveness, program compliance and issue descriptions.
- Supports the execution of strategic initiatives in collaboration with internal and external stakeholders.
- Analyzes data and information to provide insights and recommendations.
- Supports change management of varying scope and type; tasks typically focused on execution and sustainment activities.
- Performs complex reviews of business artifacts.
- Executes testing and fieldwork that is complex in nature that requires a subject matter expertise.
- Executes identified test programs for a variety of specializations to support effective testing & monitoring of controls within business groups and across the Bank.
- Understands the business/group strategy and develops and maintains knowledge of end to end processes.
- Develops knowledge related to program and/or area of specialty.
- Develops and maintains effective relationships with internal & external business partners/stakeholders to execute work and fulfill service delivery expectations.
- Participates in planning and implementation of operational testing programs and executes within required service level agreements and standards.
- Executes work to ensure timely, accurate, and efficient service delivery.
- Ensures consistent, high quality practices/work and the achievement of business results in alignment with business/group strategies and with productivity goals.
- Analyzes root causes of any errors discovered to provide for effective communication of issues to appropriate parties.
- Creates and maintains adequate testing support documentation such as workpapers, testing reports, etc. to support the results of reviews including the write-up of findings/issues for reporting.
- Provides ongoing support to the continuous improvement process of the business unit.
- Focus is primarily on business/group within BMO; may have broader, enterprise-wide focus.
- Exercises judgment to identify, diagnose, and solve problems within given rules.
- Works independently on a range of complex tasks, which may include unique situations.
- Broader work or accountabilities may be assigned as needed.
- Take measured risks while protecting the bank by applying our Risk Management Framework in the execution of your role, in line with our Risk Culture and within our approved Risk Appetite, making sound and risk informed decisions that align to business strategy, protect assets, and adhere to applicable policy documents (Frameworks, Policies, Standards, Procedures and Supporting documents), laws and regulations.
Qualifications:- Typically between 4 - 6 years of relevant experience and post-secondary degree in related field of study or an equivalent combination of education and experience.
- Technical proficiency gained through education and/or business experience.
- Verbal & written communication skills - In-depth.
- Collaboration & team skills - In-depth.
- Analytical and problem solving skills - In-depth.
- Influence skills - In-depth.
- Data driven decision making - In-depth.
Salary:$57,500.00 - $106,500.00
Pay Type: Salaried
The above represents BMO Financial Group's pay range and type.
Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group's expected target for the first year in this position.
BMO Financial Group's total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit: https://jobs.bmo.com/global/en/Total-Rewards