Logo for BMO Harris Bank

Senior Network and Cloud Penetration Tester

Role overview

Qualifications

  • Minimum of 5+ years experience with Manual Penetration Testing of Networks and Cloud Environments
  • Strong proficiency with Active Directory Environments and associated vulnerabilities
  • Bachelor’s degree in Information Security, Information Technology, Information Systems Management, Computer Science, Engineering or related field
  • Preference for candidates who have at least one certification in a related field

Responsibilities

  • Execute security testing projects including writing test reports
  • Provide technical leadership as a Security Testing subject matter expert
  • Assist with security testing operations through pre-engagement, engagement, and post-engagement activities
  • Identify security gaps and recommend corrective actions through risk assessments

About the company

BMO Harris Bank logo

BMO Harris Bank

Banking

At BMO, banking is our personal commitment to helping people at every stage of their financial lives. The truth is, people’s needs change: so we change too. But we never change who we are. Which means we’ll never waiver from providing our customers the best possible banking experience in the industry. Our incredible team of over 10,000 people, 600 plus branches and 1300 ATMs, are just the tip of the iceberg. You should get to know us. We’re here to help. Our social media terms of use: https://www.bmo.com/socialmediatermsofuse BMO Harris Bank® is a trade name used by BMO Harris Bank N.A. Member FDIC. BMO Harris Bank is part of BMO Financial Group.

Company details

Company typeXLarge
IndustryBanking
Company size5001 - 10000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Application Deadline:

10/01/2026

Address:

VIRTUAL59 - REMOTE/TELETRAVAIL - ON - BMO

Job Family Group:

Technology

Join a team where your work goes beyond checklists protecting critical Network and Cloud environments with real business and regulatory impact. 

  • High-impact, meaningful work

  • Directly influence the security of Network\Cloud environments and AI solutions that support applications that matter to customers, regulators, and the business.

  • Depth over volume
    Focus on deep, manual penetration testing (Network, Cloud, and AI with human in the loop)—not automated, scanner-driven assessments.

  • Accelerated technical growth
    Work in complex, enterprise-scale environments that expose you to advanced architectures and evolving threats.

  • End-to-end ownership
    Engage across the full lifecycle: scoping → testing → reporting → remediation, with visibility and influence throughout.

  • Modern tools and techniques
    Use advanced testing tools to enhance testing depth and efficiency.

  • More meaningful engagements
    Experience fewer, higher-quality engagements versus consulting-style, high-volume work.

  • Ongoing training expensed

Work remotely in Canada within EST or CST time zones.

The Senior Penetration Tester reports to the Sr. Manager of Penetration Testing and leads the security testing activities for BMO network, cloud, and AI technologies. The role will be responsible for the execution and coordination of ethical hacking to identify weaknesses and areas for improvement.

KEY Responsibilities:  

  • Penetration Testing - Responsible for execution of security testing projects according to a structured process, to include writing test reports. This may include oversight and/or execution of the configuration and deployment of security testing software and application of results to security analysis. Assists with the execution of highly technical/analytical security assessments of Active Directory environments, network infrastructure, cloud environments, and AI technologies, including manual, custom and industry known attack methods using a risk-based intelligence-led methodology. Identifies potential misuse scenarios. Advises on secure development practices.

  • Subject Matter Expertise - Provides technical leadership to business areas as a Security Testing subject matter expert. Assists with efforts on the execution of security testing operations to include pre-engagement (scoping), engagement (testing) and post-engagement activities (reporting).

  • Team Leadership - Assists security testing activities aimed at exploiting vulnerabilities in order to enhance the security of BMO network, cloud, and AI technologies. Works with management and peers to foster the development of less experienced Security Testing Consultants.

  • Information Security Risk Management - Works with leadership to mature security testing team capabilities including reporting and remediation guidance in alignment with local and global regulatory requirements. Identifies security gaps and deficiencies by conducting risk assessments; able to recommend corrective action of identified vulnerabilities and weaknesses. Assists with the execution of planning, testing, tracking, and advises on necessary risk acceptance for identified security risks. 

  • Performs hands-on penetration testing for BMO overall and businesses/groups.

  • Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs

  • Provides technical consultation to business areas as a Security Testing subject matter expert.

  • Assists with efforts on the execution of security testing operations to include pre-engagement (scoping), engagement (testing) and post-engagement activities (reporting).

  • Understands and can explain to others the core processes, risks and mitigation techniques for identified security gaps.

  • Develops and champions information security best practices, including staying abreast of industry information security and business trends through participation in professional associations.

  • Facilitates discussions and follows a disciplined approach to plan, elicit, analyze, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.

KEY SKILLS and EXPERIENCE :

  • Minimum of 5+ years experience with Manual Penetration Testing of Networks, and Cloud Environments.

  • Strong proficiency with Active Directory Environments and associated vulnerabilities and exploitation techniques

  • Deep experience with Cloud Environments and associated vulnerabilities in commonly used features utilized in large multi-tenant and hybrid enterprise environments

  • Strong proficiency with security testing tools and penetration testing Linux distributions such as Kali

  • Deep practical knowledge of applying the Mitre Attack framework

  • Strong experience Network and Cloud architecture understanding

  • Proficiency in at least one scripting language

  • Ability in documenting reproducible steps for technical accurate findings

  • Experience with security testing of agentic AI solution is a plus

  • Experience with security testing of CI/CD pipelines is a plus

  • Ability to identify and exploit vulnerabilities in Active Directory environments and Cloud workflows as well as multi-step attack paths.

  • 5-8 years of experience in the areas of information systems, software development, and/or information security experience desired.

  • Strong written and verbal skills with the ability to present complex technical observations to a non-technical audience.

  • Good time management skills; the ability to commit and adhere to time-sensitive deliverables.

  • Ability to work remotely, with or without others, take direction, and be a self-starter that takes initiative.

  • Ability to lead conference calls, be the main point of contact, lead report generation activities, and be the main interface with internal teams on engagements.

  • Bachelor’s degree in Information Security, Information Technology, Information Systems Management, Computer Science, Engineering or related field(s) or equivalent demonstrated work experience.

  • Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. OSCP, OSEP, HackTheBox Cloud security testing certificates, etc)

Salary:

$103,200.00 - $192,000.00

Pay Type:

Salaried

The above represents BMO Financial Group’s pay range and type.

Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group’s expected target for the first year in this position.

BMO Financial Group’s total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit: https://jobs.bmo.com/global/en/Total-Rewards

About Us

At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.

As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset.

To find out more visit us at https://jobs.bmo.com/ca/en.

BMO is committed to an inclusive, equitable and accessible workplace. By learning from each other’s differences, we gain strength through our people and our perspectives. Accommodations are available on request for candidates taking part in all aspects of the selection process. To request accommodation, please contact your recruiter.

Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Penetration Tester Related jobs

Other jobs at BMO Harris Bank

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.