Job Description
Test patch management controls, including timely identification, prioritization, testing, deployment of patches, and validation of patch compliance reporting, exception handling, and remediation activities.
Evaluate incident management controls covering detection, response, escalation, documentation, severity classification, root‑cause analysis, and communication practices.
Assess asset management processes/ controls for identifying, classifying, tracking, and reconciling technology assets; validate CMDB and inventory accuracy and completeness.
Test platform and database security controls including authentication, access, backup, logging, configuration management, privileged access, segregation of duties, encryption, and baseline adherence.
Assess container governance and security including orchestration, image scanning, RBAC, network isolation, configuration hardening, and lifecycle processes/ controls (build, deploy, patch, retire).
Perform controls testing across cloud environments (IaaS/PaaS/SaaS) focusing on identity, data security, configuration management, monitoring, baseline compliance, provisioning, access, etc.
Evaluate technology currency controls ensuring systems remain vendor-supported; review upgrade planning, end‑of‑life tracking, remediation progress, and reporting accuracy.
Test change management processes including planning, approval, testing, scheduling, implementation, documentation, segregation of duties, and emergency change compliance.
Evaluate data governance controls related to classification, handling, retention, protection, integrity, lifecycle management, stewardship responsibilities, and data quality practices.
Test software asset management controls include license tracking, entitlement validation, deployment oversight, compliance, procurement, usage monitoring, and vendor management.
Assess enterprise architecture governance for alignment with standards, security patterns, reference architectures, and control checkpoints, review solution design and risk assessment outputs.
Test API governance and security controls covering API lifecycle, authentication, authorization, rate limiting, scanning, inventory accuracy, gateway configuration, logging, and monitoring.
***This role is REMOTE***
Additional Job Responsibilities
Execute IT controls testing using standardized methodologies, ensuring accurate, high‑quality, and well‑documented results.
Prepare clear and complete testing documentation including test plans, work papers, evidence, and issue writeups.
Analyze root causes of identified issues and communicate findings effectively to stakeholders.
Produce high‑quality deliverables such as reports and status updates.
Build strong relationships with technology, audit, compliance, and business partners to support testing activities.
Provide clear and constructive feedback on control gaps, risks, and improvement opportunities.
Apply strong analytical, problem‑solving, and critical‑thinking skills throughout testing engagements.
Manage time and priorities effectively to meet deadlines and engagement expectations.
Take ownership of deliverables and work independently with minimal supervision.
Contribute to CTU projects, process improvements, and ad‑hoc initiatives.
Qualifications
Bachelor’s degree in IT, Computer Science, Engineering, or equivalent experience.
Certifications such as CISA, CISM, CDPSE, CISSP, or CPA are considered an asset.
3–5 years of IT controls testing experience (ITGC, SOX, Cloud Platforms, Container Management, etc).
Strong understanding of IT risk and control frameworks (e.g., COBIT, ITIL, ISO 27001, COSO, NIST, PCI DSS).
Experience in banking or financial services is preferred
Additional information:
Investigates and identifies strategies to optimize business operations and services, and inform business decisions. Defines business requirements to inform technology build and operations by sourcing and analyzing relevant data, reviewing and documenting business processes and collaborating with business stakeholders. Sources business and market data to evaluate the effect of projects on business results. Also assesses the efficiency and the performance of technology (software, hardware and the wider IT system) to deliver expected business results. Identifies and analyzes malfunctions, system workflow, and troubleshoots issues raised by business.
Qualifications:
Foundational level of proficiency:
Intermediate level of proficiency:
About Us
At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.
As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset.
To find out more visit us at https://jobs.bmo.com/ca/en.
BMO is committed to an inclusive, equitable and accessible workplace. By learning from each other’s differences, we gain strength through our people and our perspectives. Accommodations are available on request for candidates taking part in all aspects of the selection process. To request accommodation, please contact your recruiter.
Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.
We are committed to hiring military and Veteran spouses and encourage you to identify your connection with the MSEN when reaching out to us or applying to any of our open roles.
Have questions or want to learn more about us? We would love to hear from you!
Whenever possible, reach out to a named contact rather than a general inbox - it helps ensure a quicker, more personalized response. If you hit a bounce-back, let us know at
We’re proud to be the official bank of the Canadian Defence Community – and that goes beyond supporting your financial well-being. We value the skills you’ve earned in the military, and we’re here to help as you move into the next stage of your professional life.
BMO is a top ten North American bank that provides personal and commercial banking, global markets and investment banking services to 13 million customers and clients. Founded in 1817, we’re driven by our Purpose: Boldly Grow the Good in business and life. BMO has established itself as a destination for top talent, with an employee experience that’s built on personalized career development opportunities, a performance-driven winning culture, competitive rewards and benefits, and a deepcommitment to the health and well-being of our people.
If you’re ambitious, curious, creative, and eager to make an impact, you should consider BMO as a place to build your career.
#ProudtoWork@BMO