Senior Network and Cloud Penetration Tester

BMO·Texas·Posted 18d ago·via Talent.com

RegionUSA
Apply Now

Job description

Job Description: - Responsible for execution of security testing projects according to a structured process, to include writing test reports.

  • This may include oversight and/or execution of the configuration and deployment of security testing software and application of results to security analysis.
  • Assists with the execution of highly technical/analytical security assessments of Active Directory environments, network infrastructure, cloud environments, and AI technologies, including manual, custom and industry known attack methods using a risk-based intelligence-led methodology.
  • Identifies potential misuse scenarios. Advises on secure development practices.
  • Provides technical leadership to business areas as a Security Testing subject matter expert.
  • Assists with efforts on the execution of security testing operations to include pre-engagement (scoping), engagement (testing) and post-engagement activities (reporting).
  • Assists security testing activities aimed at exploiting vulnerabilities in order to enhance the security of BMO network, cloud, and AI technologies.
  • Works with management and peers to foster the development of less experienced Security Testing Consultants.
  • Works with leadership to mature security testing team capabilities including reporting and remediation guidance in alignment with local and global regulatory requirements.
  • Identifies security gaps and deficiencies by conducting risk assessments; able to recommend corrective action of identified vulnerabilities and weaknesses.
  • Assists with the execution of planning, testing, tracking, and advises on necessary risk acceptance for identified security risks.
  • Performs hands-on penetration testing for BMO overall and businesses/groups.
  • Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs.
  • Provides technical consultation to business areas as a Security Testing subject matter expert.
  • Understands and can explain to others the core processes, risks and mitigation techniques for identified security gaps.
  • Develops and champions information security best practices, including staying abreast of industry information security and business trends through participation in professional associations.
  • Facilitates discussions and follows a disciplined approach to plan, elicit, analyze, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.

Requirements: - Minimum of 5+ years experience with Manual Penetration Testing of Networks, and Cloud Environments.

  • Strong proficiency with Active Directory Environments and associated vulnerabilities and exploitation techniques
  • Deep experience with Cloud Environments and associated vulnerabilities in commonly used features utilized in large multi-tenant and hybrid enterprise environments
  • Strong proficiency with security testing tools and penetration testing Linux distributions such as Kali
  • Deep practical knowledge of applying the Mitre Attack framework
  • Strong experience Network and Cloud architecture understanding
  • Proficiency in at least one scripting language
  • Ability in documenting reproducible steps for technical accurate findings
  • Experience with security testing of agentic AI solution is a plus
  • Experience with security testing of CI/CD pipelines is a plus
  • Ability to identify and exploit vulnerabilities in Active Directory environments and Cloud workflows as well as multi-step attack paths.
  • 5-8 years of experience in the areas of information systems, software development, and/or information security experience desired.
  • Strong written and verbal skills with the ability to present complex technical observations to a non-technical audience.
  • Good time management skills; the ability to commit and adhere to time-sensitive deliverables.
  • Ability to work remotely, with or without others, take direction, and be a self-starter that takes initiative.
  • Ability to lead conference calls, be the main point of contact, lead report generation activities, and be the main interface with internal teams on engagements.
  • Bachelor’s degree in Information Security, Information Technology, Information Systems Management, Computer Science, Engineering or related field(s) or equivalent demonstrated work experience.
  • Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. OSCP, OSEP, HackTheBox Cloud security testing certificates, etc)

Benefits: - health insurance

  • tuition reimbursement
  • accident and life insurance
  • retirement savings plans

first seen 2026-08-07 04:48:01 · last verified 2026-08-07 08:40:01


pentestcareers.com // breach the job market

Senior Network and Cloud Penetration Tester at BMO | Pentest Careers