Volver a ofertas

AI Penetration Tester

BMO Financial · Virtual, FL, USA · United States

Senior AI Penetration Tester at BMO shaping enterprise AI security. Remote US role: lead testing of LLMs, AI agents, and GenAI systems.

Vista previa generada por IA

Senior AI Penetration Tester at BMO shaping enterprise AI security.

Remote US role: lead testing of LLMs, AI agents, and GenAI systems.

Title: AI Penetration Tester

Location: Virtual, FL, USA

Job Family Group: Technology

Application Deadline: 10/29/2026

Address: VIRTUAL09 - HomeRes - FL

Be among the first dedicated AI Penetration Testers at BMO and help shape how AI systems are secured, challenged, and trusted at enterprise scale. As part of BMO's Security Testing Team, you'll play a key role in building and advancing our AI Security Testing capability, assessing cutting-edge AI technologies, large language models (LLMs), AI agents, and GenAI solutions before they are deployed across the organization.

In this highly visible role, you'll partner with cybersecurity leaders, engineers, architects, data scientists, and AI governance teams to identify emerging risks, develop innovative testing methodologies, and influence how AI security practices evolve across the enterprise.

What Makes This Role Unique?

Build something new: Help create and mature a first-of-its-kind AI Security Testing capability within BMO's Security Testing Team.

Work with emerging technology: Evaluate LLMs, AI agents, GenAI platforms, and machine learning systems using cutting-edge adversarial testing techniques.

Drive enterprise impact: Shape security outcomes for some of the bank's most strategic AI initiatives before they reach production.

Create the future of AI testing: Design and develop new AI adversarial testing methodologies that become part of BMO's long-term security testing strategy.

Expand your expertise: Lead security testing exercises, conduct AI threat research, and simulate emerging attack techniques targeting AI systems.

Work alongside experts: Collaborate with leading security practitioners, AI engineers, architects, and governance teams to solve complex security challenges.

Flexible remote work: Work remotely within EST or CST time zones.

KEY Responsibilities:

Conduct security assessments of AI systems, LLMs, AI agents, and machine learning applications.

Perform adversarial testing including prompt injection, jailbreaks, model manipulation, and abuse-case testing.

Execute application, API, and cloud security testing supporting AI-enabled solutions.

Develop repeatable AI security testing methodologies, tools, and automation.

Partner with development and engineering teams to validate and remediate findings.

Produce technical reports and executive summaries communicating risks and recommendations.

Research emerging AI threats and attack techniques.

Support red team exercises involving AI-enabled attack scenarios.

CORE Skills :

Advanced penetration testing experience across web applications, APIs, and cloud environments.

Hands-on experience assessing AI/LLM technologies, AI agents, ML models, or GenAI applications.

Strong understanding of offensive security methodologies and adversarial attack techniques.

Experience with Python scripting and security tool development/automation.

Knowledge of OWASP Top 10, API Security Top 10, and emerging OWASP LLM Security risks.

Experience performing threat modeling and security assessments.

Strong understanding of authentication, authorization, identity, and cloud security concepts.

Ability to clearly document findings and remediation recommendations.

Additional Information:

Provides analysis and reporting services in support of businesses/groups and BMO overall. Builds relationships and liaises with stakeholders to understand problems and opportunities and recommends solutions to enable the organization to meet its goals. Analyzes data and creates documents and plans in service of informing, advising, or updating internal stakeholders. Ensures that requirements map to a real business need, are approved by all relevant stakeholders, and meet essential quality standards. Participates or conducts user acceptance testing to ensure that changes made are in alignment with business requirements. Provides great customer service in support of the information security processes, applications and infrastructure.

Provides strategic input into business decisions as a trusted advisor.

Acts as a subject matter expert on relevant regulations and policies.

Provides specialized analytical support to senior management.

May network with industry contacts to gain competitive insights and best practices.

Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.

Anticipates and reduces complexity for others.

Develops innovative approaches to resolve problems and significant issues.

Provides input to the strategic direction of the group.

Acts as the prime subject matter expert for internal/external stakeholders.

Ensures alignment between stakeholders.

Defines business requirements for analytics and reporting to ensure data insights inform business decision making.

Analyzes trends to proactively prevent problems.

Presents and communicates at all levels within IT and across business units.

Prepares and delivers presentations for senior leaders.

Leads the preparation of end user reference materials and prepares end-user training materials.

Develops innovative approaches…

Qualifications:

Typically 7+ years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, Information Systems, Business or in a related field of study or an equivalent combination of education and experience.

Multiple Information Security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).

Expert in information security, technology, business requirements gathering and reporting in a financial services setting.

Data manipulation and analysis skills with the ability to collect, organize, analyze and disseminate significant amounts of information with attention to detail and accuracy - Expert.

Knowledge of Information Security processes, procedures and controls - Expert.

Understanding and problem solving ability of Information Security issues across the bank - Expert.

Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002 - Expert.

Understanding of Information Security risk and regulatory requirements - In-depth.

Understanding of the scope of complexity that exists in the computing environment and the ways which security platforms impact that environment.

Seasoned professional with a combination of education, experience and industry knowledge.

Verbal & written communication skills - In-depth / Expert.

Analytical and problem solving skills - In-depth / Expert.

Influence skills - In-depth / Expert.

Collaboration & team skills; with a focus on cross-group collaboration - In-depth / Expert.

Able to manage ambiguity.

Data driven decision making - In-depth / Expert.

Salary :

$122,400.00 - $228,000.00

Pay Type: Salaried

Pay Type:

Salaried

About Us

At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.

As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset.

To find out more visit us at http://jobs.bmo.com/us/en

Note to Recruiters:

BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.

BMO is proud to be an equal employment opportunity employer.

We evaluate applicants without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or any other legally protected characteristics. We also consider applicants with criminal histories, consistent with applicable federal, state and local law.

BMO is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please send an e-mail to BMOCareers.Support@bmo.com and let us know the nature of your request and your contact information.

Encuentra más ofertas como esta

Explora más ofertas activas de esta empresa o crea una cuenta en Insider Jobs para buscar, guardar y seguir oportunidades en todo el job board.