Qualifications
Responsibilities
Benefits
Application Deadline:
Address:
VIRTUAL43 - HomeRes - TXJob Family Group:
TechnologyJoin a team where your work goes beyond checklists protecting critical financial applications with real business and regulatory impact. Why join this team?
Directly influence the security of applications that matter to customers, regulators, and the business.
Depth over volume
Focus on deep, manual penetration testing (web, mobile, APIs)—not automated, scanner-driven assessments.
Accelerated technical growth
Work in complex, enterprise-scale environments that expose you to advanced architectures and evolving threats.
End-to-end ownership
Engage across the full lifecycle: scoping → testing → reporting → remediation, with visibility and influence throughout.
Modern tools and techniques
Use advanced testing tools to enhance testing depth and efficiency.
More meaningful engagements
Experience fewer, higher-quality engagements versus consulting-style, high-volume work.
- Min of 3+ years experience with Manual Penetration Testing experience in Web or API. This includes strong exposure for testing Web applications in the following areas:
A solid grasp of HTTP/S protocols, headers, cookies, sessions, and CORS behavior within your web testing experience
Experience testing authentication and authorization mechanisms (OAuth, JWT, session flaws, IDOR/BOLA)-
Strong proficiency with Burp Suite Professional , OWASP ZAP, IBM’s APP SCAN, (proxying, repeater, intruder, extensions)-
Deep practical knowledge of OWASP Top 10 (Web + API) and common vulnerabilities
- Ability to identify and exploit business logic vulnerabilities and multi-step attack paths
- Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. OSCP, GMOB, GWAPT, OSWE).
- Secure coding and architecture understanding
- Proficiency in at least one scripting language
- Proficiency in documenting reproducible steps for technical accurate findings -
CORE Responsibilities:
Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs
Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs.
Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.
Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.
Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.
Additional Information:
Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Leads the development of information security strategy by understanding business processes, policies, information and information systems. Builds exceptional relationships with internal and external stakeholders. Ensures that requirements and solutions align to a real business need, are approved by all relevant stakeholders, and meets essential information security standards. Provides thought leadership, promotes new processes and methodologies and emerging technologies, with the flexibility to align to the unique requirements of the business/group and deliverables.
Qualifications:
Salary:
Pay Type:
SalariedThe above represents BMO Financial Group’s pay range and type.
Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group’s expected target for the first year in this position.
BMO Financial Group’s total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit:
About Bank of Montreal
Similar Jobs


More Jobs at Bank of Montreal





More Information Technology Jobs

