Ce recruteur est en ligne!

Voilà ta chance d'être vu en premier!

Postuler maintenant

Senior Network and Cloud Penetration Tester

Toronto, ON
  • À discuter
  • Publié il y a 6 jour(s)

  • 1 poste à combler dès que possible

Date limite pour présenter sa candidature :

10/01/2026

Adresse :

VIRTUAL59 - REMOTE/TELETRAVAIL - ON - BMO

Groupe de famille d'emploi :

Technologie

Join a team where your work goes beyond checklists protecting critical Network and Cloud environments with real business and regulatory impact.

  • High-impact, meaningful work

  • Directly influence the security of Network\Cloud environments and AI solutions that support applications that matter to customers, regulators, and the business.

  • Depth over volume
    Focus on deep, manual penetration testing (Network, Cloud, and AI with human in the loop)-not automated, scanner-driven assessments.

  • Accelerated technical growth
    Work in complex, enterprise-scale environments that expose you to advanced architectures and evolving threats.

  • End-to-end ownership
    Engage across the full lifecycle: scoping testing reporting remediation, with visibility and influence throughout.

  • Modern tools and techniques
    Use advanced testing tools to enhance testing depth and efficiency.

  • More meaningful engagements
    Experience fewer, higher-quality engagements versus consulting-style, high-volume work.

  • Ongoing training expensed

Work remotely in Canada within EST or CST time zones.

The Senior Penetration Tester reports to the Sr. Manager of Penetration Testing and leads the security testing activities for BMO network, cloud, and AI technologies. The role will be responsible for the execution and coordination of ethical hacking to identify weaknesses and areas for improvement.

KEY Responsibilities:

  • Penetration Testing - Responsible for execution of security testing projects according to a structured process, to include writing test reports. This may include oversight and/or execution of the configuration and deployment of security testing software and application of results to security analysis. Assists with the execution of highly technical/analytical security assessments of Active Directory environments, network infrastructure, cloud environments, and AI technologies, including manual, custom and industry known attack methods using a risk-based intelligence-led methodology. Identifies potential misuse scenarios. Advises on secure development practices.

  • Subject Matter Expertise - Provides technical leadership to business areas as a Security Testing subject matter expert. Assists with efforts on the execution of security testing operations to include pre-engagement (scoping), engagement (testing) and post-engagement activities (reporting).

  • Team Leadership - Assists security testing activities aimed at exploiting vulnerabilities in order to enhance the security of BMO network, cloud, and AI technologies. Works with management and peers to foster the development of less experienced Security Testing Consultants.

  • Information Security Risk Management - Works with leadership to mature security testing team capabilities including reporting and remediation guidance in alignment with local and global regulatory requirements. Identifies security gaps and deficiencies by conducting risk assessments; able to recommend corrective action of identified vulnerabilities and weaknesses. Assists with the execution of planning, testing, tracking, and advises on necessary risk acceptance for identified security risks.

  • Performs hands-on penetration testing for BMO overall and businesses/groups.

  • Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs

  • Provides technical consultation to business areas as a Security Testing subject matter expert.

  • Assists with efforts on the execution of security testing operations to include pre-engagement (scoping), engagement (testing) and post-engagement activities (reporting).

  • Understands and can explain to others the core processes, risks and mitigation techniques for identified security gaps.

  • Develops and champions information security best practices, including staying abreast of industry information security and business trends through participation in professional associations.

  • Facilitates discussions and follows a disciplined approach to plan, elicit, analyze, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.

KEY SKILLS and EXPERIENCE :

  • Minimum of 5+ years experience with Manual Penetration Testing of Networks, and Cloud Environments.

  • Strong proficiency with Active Directory Environments and associated vulnerabilities and exploitation techniques

  • Deep experience with Cloud Environments and associated vulnerabilities in commonly used features utilized in large multi-tenant and hybrid enterprise environments

  • Strong proficiency with security testing tools and penetration testing Linux distributions such as Kali

  • Deep practical knowledge of applying the Mitre Attack framework

  • Strong experience Network and Cloud architecture understanding

  • Proficiency in at least one scripting language

  • Ability in documenting reproducible steps for technical accurate findings

  • Experience with security testing of agentic AI solution is a plus

  • Experience with security testing of CI/CD pipelines is a plus

  • Ability to identify and exploit vulnerabilities in Active Directory environments and Cloud workflows as well as multi-step attack paths.

  • 5-8 years of experience in the areas of information systems, software development, and/or information security experience desired.

  • Strong written and verbal skills with the ability to present complex technical observations to a non-technical audience.

  • Good time management skills; the ability to commit and adhere to time-sensitive deliverables.

  • Ability to work remotely, with or without others, take direction, and be a self-starter that takes initiative.

  • Ability to lead conference calls, be the main point of contact, lead report generation activities, and be the main interface with internal teams on engagements.

  • Bachelor’s degree in Information Security, Information Technology, Information Systems Management, Computer Science, Engineering or related field(s) or equivalent demonstrated work experience.

  • Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. OSCP, OSEP, HackTheBox Cloud security testing certificates, etc)

Salaire :

$103,200.00 - $192,000.00

Type de rémunération :

Salaire

Ce qui précède représente la fourchette et le type de rémunération de BMO Groupe financier.

Les salaires varieront en fonction de facteurs comme l’emplacement, les compétences, l’expérience, les études et les qualifications pour le poste et pourront inclure une structure de commissions. Les salaires pour les postes à temps partiel seront calculés au prorata du nombre d’heures travaillées régulièrement. Pour les rôles à commission, le salaire susmentionné représente la cible de BMO Groupe financier pour la première année au poste.

La rémunération totale offerte par BMO variera selon le type de rémunération associé au poste et peut comprendre des primes de rendement, des primes discrétionnaires ainsi que d’autres avantages et récompenses. BMO offre également une assurance santé, le remboursement des frais de scolarité, une assurance accident et une assurance vie, ainsi que des régimes d’épargne-retraite. Pour en savoir plus sur nos avantages sociaux, consultez le site : https://jobs.bmo.com/ca/fr/R%C3%A9mun%C3%A9ration-globale

À propos de nous

À BMO, nous sommes animés par une raison d’être commune : Avoir le cran de faire une différence dans la vie, comme en affaires. Cette raison d’être nous invite à entraîner des changements positifs et durables pour nos clients, nos collectivités et nos gens. En travaillant ensemble, en innovant et en repoussant les limites, nous transformons des vies et des entreprises et favorisons la croissance économique partout dans le monde.

En tant que membre de l'équipe de BMO, vous êtes valorisé, respecté et entendu, et vous avez plus de moyens pour progresser et obtenir des résultats. Nous nous efforçons de vous aider à obtenir des résultats dès le premier jour, pour vous-même et nos clients. Nous vous offrirons les outils et les ressources dont vous avez besoin pour franchir de nouvelles étapes, car vous aidez nos clients à franchir les leurs. Au moyen de formation et de coaching approfondis ainsi que de soutien de la direction et d'occasions de réseautage, nous vous aiderons à acquérir une expérience enrichissante et à élargir votre groupe de compétences.

Pour en savoir plus, visitez-nous à l'adresse https://jobs.bmo.com/ca/fr.

BMO s'engage à offrir un milieu de travail inclusif, équitable et accessible. Nous apprenons de nos différences et tirons notre force des gens et de leurs différents points de vue. Des mesures d’adaptation sont disponibles sur demande pour les candidats qui participent à tous les aspects du processus de sélection. Pour demander des mesures d’adaptation, veuillez communiquer avec votre recruteur.

Remarque aux recruteurs : BMO n’accepte pas les curriculum vitæ non sollicités provenant de toute source autre que le candidat directement. Tout curriculum vitæ non sollicité envoyé à BMO, directement ou indirectement, sera considéré comme la propriété de BMO. BMO ne paiera aucuns frais pour les placements découlant de la réception d’un curriculum vitæ non sollicité. Une agence de recrutement doit d’abord détenir une entente de service écrite valide et dûment signée avant d’envoyer des curriculum vitæ.


Exigences

Niveau d'études

non déterminé

Diplôme

non déterminé

Années d'expérience

non déterminé

Langues écrites

non déterminé

Langues parlées

non déterminé