Job description
Job Description: - Conduct security assessments of AI systems, LLMs, AI agents, and machine learning applications
- Perform adversarial testing including prompt injection, jailbreaks, model manipulation, and abuse-case testing
- Execute application, API, and cloud security testing for AI-enabled solutions
- Develop repeatable AI security testing methodologies, tools, and automation
- Partner with development and engineering teams to validate and remediate findings
- Produce technical reports and executive summaries communicating risks and recommendations
- Research emerging AI threats and attack techniques
- Support red team exercises involving AI-enabled attack scenarios
- Provide analysis and reporting services for business groups and BMO
- Build stakeholder relationships, understand problems and opportunities, and recommend solutions
- Analyze data and create documents and plans for internal stakeholders
- Ensure requirements map to business needs, receive stakeholder approval, and meet quality standards
- Participate in or conduct user acceptance testing
- Provide information security process, application, and infrastructure support
- Provide strategic input and specialized analytical support to senior management
- Act as a subject matter expert on regulations, policies, information security, and relevant processes
- Define analytics and reporting requirements and analyze trends to prevent problems
- Present to and communicate with IT and business-unit stakeholders, including senior leaders
- Prepare end-user reference and training materials
- Troubleshoot information security issues and work with vendors as required
- Gather, document, validate, and manage requirements for audits, reports, and projects
- Mentor employees, share expertise, and build information security communities of practice
- Collect, organize, clean, analyze, and disseminate complex data
- Develop data collection systems and strategies to improve efficiency and data quality
- Document and maintain processes, procedures, and requirements
- Recommend improvements to streamline and integrate information security processes
- Monitor emerging technologies and threats and determine mitigation approaches
- Apply BMO's Risk Management Framework and make risk-informed decisions aligned with policies, laws, regulations, and business strategy
Requirements: - Typically 7+ years of relevant experience
- Post-secondary degree in Information Security, Computer Science, Engineering, Information Systems, Business, or a related field, or equivalent combination of education and experience
- Multiple Information Security certifications from a well-recognized institution, such as (ISC)2, ISACA, or SANS
- Expert information security, technology, business requirements gathering, and reporting experience in a financial services setting
- Expert data manipulation and analysis skills
- Expert knowledge of Information Security processes, procedures, and controls
- Expert understanding and problem-solving ability regarding Information Security issues across the bank
- Expert understanding of NIST CSF, ISO 27001, and ISO 27002
- In-depth understanding of Information Security risk and regulatory requirements
- Understanding of computing-environment complexity and security-platform impacts
- In-depth/expert verbal and written communication skills
- In-depth/expert analytical and problem-solving skills
- In-depth/expert influence skills
- In-depth/expert collaboration and team skills
- Ability to manage ambiguity
- In-depth/expert data-driven decision-making skills
- Advanced penetration testing experience across web applications, APIs, and cloud environments
- Hands-on experience assessing AI/LLM technologies, AI agents, ML models, or GenAI applications
- Strong understanding of offensive security methodologies and adversarial attack techniques
- Experience with Python scripting and security tool development/automation
- Knowledge of OWASP Top 10, API Security Top 10, and emerging OWASP LLM Security risks
- Experience performing threat modeling and security assessments
- Strong understanding of authentication, authorization, identity, and cloud security concepts
- Ability to document findings and remediation recommendations clearly
- Work authorization/residence in the USA within EST or CST time zones
Benefits: - Performance-based incentives
- Discretionary bonuses
- Health insurance
- Tuition reimbursement
- Accident insurance
- Life insurance
- Retirement savings plans
- In-depth training and coaching
- Manager support
- Network-building opportunities
- Flexible remote work within EST or CST time zones
first seen 2026-08-20 21:30:01 · last verified 2026-08-20 21:30:01
pentestcareers.com // breach the job market