Join a team where your work goes beyond checklists protecting critical financial applications with real business and regulatory impact. Why join this team?
Directly influence the security of applications that matter to customers, regulators, and the business.
Depth over volume
Focus on deep, manual penetration testing (web, mobile, APIs)—not automated, scanner-driven assessments.
Accelerated technical growth
Work in complex, enterprise-scale environments that expose you to advanced architectures and evolving threats.
End-to-end ownership
Engage across the full lifecycle: scoping → testing → reporting → remediation, with visibility and influence throughout.
Modern tools and techniques
Use advanced testing tools to enhance testing depth and efficiency.
More meaningful engagements
Experience fewer, higher-quality engagements versus consulting-style, high-volume work.
- Min of 3+ years experience with Manual Penetration Testing experience in Web or API. This includes strong exposure for testing Web applications in the following areas:
A solid grasp of HTTP/S protocols, headers, cookies, sessions, and CORS behavior within your web testing experience
Experience testing authentication and authorization mechanisms (OAuth, JWT, session flaws, IDOR/BOLA)-
Strong proficiency with Burp Suite Professional , OWASP ZAP, IBM’s APP SCAN, (proxying, repeater, intruder, extensions)-
Deep practical knowledge of OWASP Top 10 (Web + API) and common vulnerabilities
- Ability to identify and exploit business logic vulnerabilities and multi-step attack paths
- Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. OSCP, GMOB, GWAPT, OSWE).
- Secure coding and architecture understanding
- Proficiency in at least one scripting language
- Proficiency in documenting reproducible steps for technical accurate findings -
CORE Responsibilities:
Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs
Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs.
Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.
Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.
Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.
Additional Information:
Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Leads the development of information security strategy by understanding business processes, policies, information and information systems. Builds exceptional relationships with internal and external stakeholders. Ensures that requirements and solutions align to a real business need, are approved by all relevant stakeholders, and meets essential information security standards. Provides thought leadership, promotes new processes and methodologies and emerging technologies, with the flexibility to align to the unique requirements of the business/group and deliverables.
Qualifications:
About Us
At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.
As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset.
To find out more visit us at https://jobs.bmo.com/ca/en.
BMO is committed to an inclusive, equitable and accessible workplace. By learning from each other’s differences, we gain strength through our people and our perspectives. Accommodations are available on request for candidates taking part in all aspects of the selection process. To request accommodation, please contact your recruiter.
Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.
We are committed to hiring military and Veteran spouses and encourage you to identify your connection with the MSEN when reaching out to us or applying to any of our open roles.
Have questions or want to learn more about us? We would love to hear from you!
Whenever possible, reach out to a named contact rather than a general inbox - it helps ensure a quicker, more personalized response. If you hit a bounce-back, let us know at
We’re proud to be the official bank of the Canadian Defence Community – and that goes beyond supporting your financial well-being. We value the skills you’ve earned in the military, and we’re here to help as you move into the next stage of your professional life.
BMO is a top ten North American bank that provides personal and commercial banking, global markets and investment banking services to 13 million customers and clients. Founded in 1817, we’re driven by our Purpose: Boldly Grow the Good in business and life. BMO has established itself as a destination for top talent, with an employee experience that’s built on personalized career development opportunities, a performance-driven winning culture, competitive rewards and benefits, and a deepcommitment to the health and well-being of our people.
If you’re ambitious, curious, creative, and eager to make an impact, you should consider BMO as a place to build your career.
#ProudtoWork@BMO