Vista previa generada por IA
Penetration Testing Consultant – Remote (Virtual) – Join a high-impact team protecting critical financial applications.
Apply by 08/30/2026. Earn $88k–$166k, with benefits, certifications preferred, and a focus on manual, web/API testing.
Title
Penetration Testing Consultant
Location
Virtual, TX, USA
Description
Application Deadline: 08/30/2026
Address: VIRTUAL43 - HomeRes - TX
Job Family Group: Technology
Join a team where your work goes beyond checklists protecting critical financial applications with real business and regulatory impact. Why join this team?
High-impact, meaningful work
Directly influence the security of applications that matter to customers, regulators, and the business.
Depth over volume Focus on deep, manual penetration testing (web, mobile, APIs)—not automated, scanner-driven assessments.
Accelerated technical growth Work in complex, enterprise-scale environments that expose you to advanced architectures and evolving threats.
End-to-end ownership Engage across the full lifecycle: scoping → testing → reporting → remediation , with visibility and influence throughout.
Modern tools and techniques Use advanced testing tools to enhance testing depth and efficiency.
More meaningful engagements Experience fewer, higher-quality engagements versus consulting-style, high-volume work.
KEY SKILLS
- Min of 3+ years experience with Manual Penetration Testing experience in Web or API. This includes strong exposure for testing Web applications in the following areas:
A solid grasp of HTTP/S protocols, headers, cookies, sessions, and CORS behavior within your web testing experience
Experience testing authentication and authorization mechanisms (OAuth, JWT, session flaws, IDOR/BOLA)-
Strong proficiency with Burp Suite Professional , OWASP ZAP, IBM’s APP SCAN, (proxying, repeater, intruder, extensions)-
Deep practical knowledge of OWASP Top 10 (Web + API) and common vulnerabilities
- Ability to identify and exploit business logic vulnerabilities and multi-step attack paths
- Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. OSCP, GMOB, GWAPT, OSWE).
- Secure coding and architecture understanding
- Proficiency in at least one scripting language
- Proficiency in documenting reproducible steps for technical accurate findings -
CORE Responsibilities
Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs
Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs.
Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.
Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.
Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.
Additional Information
Provides information security consulting services for BMO overall and businesses/groups. Liaises ... (continues with the full paragraphs as originally provided, preserving all text as given).
Qualifications
Typically between 4 - 7 years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experience.
Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).
Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002, Payment Card Industry (PCI) Data Security Standard (DSS), etc. - In-depth.
Experience in information security concepts and methodology.
Knowledge of business analysis, project delivery practices and standards across the project lifecycle - In-depth.
Knowledge of information security processes, procedures and controls - In-depth.
Understanding of and problem solving ability for information security issues within their business group - Working.
Understanding of information security risk and regulatory requirements - Working.
Deep knowledge and technical proficiency gained through extensive education and business experience.
Verbal & written communication skills - In-depth.
Collaboration & team skills - In-depth.
Analytical and problem solving skills - In-depth.
Influence skills - In-depth.
Data driven decision making - In-depth.
Salary
$88,800.00 - $165,600.00
Pay Type
Salaried
About Us
At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.
As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset.
To find out more visit us at http://jobs.bmo.com/us/en
Legal Notice
BMO is proud to be an equal employment opportunity employer. We evaluate applicants without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or any other legally protected characteristics. We also consider applicants with criminal histories, consistent with applicable federal, state and local law.
BMO is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please send an e‑mail to BMOCareers.Support@bmo.com and let us know the nature of your request and your contact information.
Note to Recruiters
Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.