Penetration Testing Consultant
$88.8k - $165.6kBMO
Application Deadline: 08/30/2026 Address: VIRTUAL43 - HomeRes - TX Job Family Group: Technology Join a team where your work goes beyond checklists protecting critical financial applications with real business and regulatory impact. Why join this team? High-impact, meaningful work Directly influence the security of applications that matter to customers, regulators, and the business. Depth over volume Focus on deep, manual penetration testing (web, mobile, APIs)—not automated, scanner-driven assessments. Accelerated technical growth Work in complex, enterprise-scale environments that expose you to advanced architectures and evolving threats. End-to-end ownership Engage across the full lifecycle: scoping → testing → reporting → remediation, with visibility and influence throughout. Modern tools and techniques Use advanced testing tools to enhance testing depth and efficiency. More meaningful engagements Experience fewer, higher-quality engagements versus consulting-style, high-volume work. KEY SKILLS: - Min of 3+ years experience with Manual Penetration Testing experience in Web or API. This includes strong exposure for testing Web applications in the following areas: A solid grasp of protocols, headers, cookies, sessions, and CORS behavior within your web testing experience Experience testing authentication and authorization mechanisms (OAuth, JWT, session flaws, IDOR/BOLA)- Strong proficiency with Burp Suite Professional , OWASP ZAP, IBM’s APP SCAN, (proxying, repeater, intruder, extensions)- Deep practical knowledge of OWASP Top 10 (Web + API) and common vulnerabilities - Ability to identify and exploit business logic vulnerabilities and multi-step attack paths - Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. OSCP, GMOB, GWAPT, OSWE). - Secure coding and architecture understanding - Proficiency in at least one scripting language - Proficiency in documenting reproducible steps for technical accurate findings - CORE Responsibilities: Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Understands and can explain to others the core processes, risks and mitigation techniques for designated areas. Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations. Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks. Additional Information: Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Leads the development of information security strategy by understanding business processes, policies, information and information systems. Builds exceptional relationships with internal and external stakeholders. Ensures that requirements and solutions align to a real business need, are approved by all relevant stakeholders, and meets essential information security standards. Provides thought leadership, promotes new processes and methodologies and emerging technologies, with the flexibility to align to the unique requirements of the business/group and deliverables. Acts as a trusted advisor to assigned business/group. Assists in the development of strategic plans. Understands and can explain to others the core processes, risks and mitigation techniques for designated areas. Supports the execution of strategic initiatives in collaboration with internal and external stakeholders. Helps determine business priorities and best sequence for execution of business/group strategy. Breaks down strategic problems, and analyses data and information to provide insights and recommendations. Acts as the day to day contact for vendors; supports the implementation, maintenance, and sustainment of vendor solutions. Understands the strategy, plans, activities and needs of all stakeholders and translates those business needs into solutions and makes recommendations. Provides advice, counsel and support on information security matters and recommends solutions to assigned business/group leaders on principles, frameworks, programs, approaches, trends, legislation and regulatory requirements including interpretation of policy and identification and management of risk. Builds credibility and influences/negotiates effectively to drive business performance through development and delivery of information security solutions. Tracks metrics and milestones, providing recommendations for resolution and escalating as appropriate when issues arise. Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks. Promotes process improvements and methodologies; keeps emerging information security issues and trends in mind and ensures standards are followed. Creates professional presentations and deliver them in a meaningful concise way. Assesses information security impact to a project’s benefits and risks when scope changes. Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations. Gathers, examines and interprets data and information to extract meaningful insights, answer business questions and provide actionable recommendations. Assists with continuous improvement activities and root cause analysis with the goal of strengthening information security capabilities. Ensures consistent, high quality practices/work and the achievement of business results in alignment with business/group strategies and with productivity goals. Focus is primarily on business/group within BMO; may have broader, enterprise-wide focus. Provides specialized consulting, analytical and technical support. Exercises judgment to identify, diagnose, and solve problems within given rules. Works independently and regularly handles non-routine situations. Broader work or accountabilities may be assigned as needed. Take measured risks while protecting the bank by applying our Risk Management Framework in the execution of your role, in line with our Risk Culture and within our approved Risk Appetite, making sound and risk informed decisions that align to business strategy, protect assets, and adhere to applicable policy documents (Frameworks, Policies, Standards, Procedures and Supporting documents), laws and regulations. Qualifications: Typically between 4 - 7 years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experience. Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS). Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002, Payment Card Industry (PCI) Data Security Standard (DSS), etc. - In-depth. Experience in information security concepts and methodology. Knowledge of business analysis, project delivery practices and standards across the project lifecycle - In-depth. Knowledge of information security processes, procedures and controls - In-depth. Understanding of and problem solving ability for information security issues within their business group - Working. Understanding of information security risk and regulatory requirements - Working. Deep knowledge and technical proficiency gained through extensive education and business experience. Verbal & written communication skills - In-depth. Collaboration & team skills - In-depth. Analytical and problem solving skills - In-depth. Influence skills - In-depth. Data driven decision making - In-depth. Salary: $88,800.00 - $165,600.00 Pay Type: Salaried The above represents BMO Financial Group’s pay range and type. Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group’s expected target for the first year in this position. BMO Financial Group’s total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit: About Us At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world. As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset. To find out more visit us at BMO is proud to be an equal employment opportunity employer. We evaluate applicants without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or any other legally protected characteristics. We also consider applicants with criminal histories, consistent with applicable federal, state and local law. BMO is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please send an e-mail to View email address on click.appcast.io and let us know the nature of your request and your contact information. Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes. BMO is a leading bank driven by a single purpose: to Boldly Grow the Good in business and life. Everywhere we do business, we’re focused on building, investing and transforming how we work to drive performance and continue growing the good. Who we are We’re proud to be fueling growth and expanding possibilities for individuals, families and businesses. More than 12 million customers count on us for personal and commercial banking, wealth management and investment services. As the 8th largest bank in North America by assets, we provide personal and commercial banking, wealth management and investment services to more than 12 million customers. In Canada, the United States and across the globe, we’ll continue to build, invest and transform to drive performance that serves the good that grows.
- IBM Computing is seeking a Senior Pentest Consultant for its X-Force Red Offensive Security team. This role involves conducting penetration tests on applications and networks while assisting in client interactions. Candidates should have over three years of experience in...SuggestedRemote job
- ...Schedule: 6:30PM - 7:00AM PRIMARY PURPOSE Serves as a lactation consultant in the Women & Family Education department within the WISH and... ...right to change/cancel exam dates and delays the release of test results. In instances when the staff member's exam date is...SuggestedFull timeTemporary work
- ...Infosys is seeking a Senior 09 Consultant with a strong background in supply chain solutions, and you will anchor different phases of... ...requirements specifications, consulting on functionalities implemented, testing of deployed planning process with the objective of providing...SuggestedFull timeTemporary workRelocation
$183.3k - $240.6k
...Candidate will be responsible for leading the design, build, testing and deployment of changed or new business processes enabled by... ...objectives Qualifications: • Experience leading large global, consulting led Demand to Supply (DTS) business transformation program...Suggested- ...General information Name Consultant, Internal Audit - Banking Posting Title Consultant, Internal Audit - Banking Ref... ...compliance engagements, including documentation, walkthroughs, testing, evaluation, and reporting. Identify control deficiencies, evaluate...SuggestedFull timeFlexible hoursShift work
- ...Hi, we're Phiture — the mobile growth consultancy working with the teams behind leading apps like Adobe, Headspace, and LEGO ??. We're... ...integrated performance growth initiatives, connecting creative testing, data insights, and experimentation. This is a high-impact role...Work at officeRemote workHome officeFlexible hours
- ...Retail Merchandise Planning And Allocation Senior Consultant Clarkston Consulting is seeking motivated, self-driven leaders who are... ...Contribute to system implementation efforts from design through testing and go-live Develop process documentation, including...RelocationHome office
- ...and evaluates educational outcomes. Provides outpatient care, consultation, and home visits for families experiencing breastfeeding difficulties... ...requirement, you will be required to submit to regular testing in accordance with the law. Organization Description Careers...Full timeLocal areaNight shift
$90k - $120k
...your ambitions. About the role: The Peripheral Vascular Consultant position requires someone with strong clinical aptitude that... ...positions: It is unlawful to require or administer a lie detector test for employment. Violators are subject to criminal penalties and...Full timeCasual work$55 - $60 per hour
...essential to translate requirements into technical implementations. The role also includes responsibilities such as code reviews, unit testing, performance tuning, and supporting production environments through troubleshooting and root cause analysis. Participation in Agile...Temporary work$110.7k - $184.5k
...Senior-Level Building Enclosure Consultant Bring your problem-solving mindset, entrepreneurial spirit, and established expertise to... ...performing and training others in hands-on field work and diagnostic testing Mentorship, including exemplifying WJE's culture of shared...For contractorsWork at officeLocal areaImmediate startWorldwide- ...resources, and extensive diagnostic, analytical, and physical testing capabilities empower us to provide our clients with the most comprehensive... ...for an individual with broad knowledge and experience as a consulting design engineer to join our team of highly skilled forensic...Contract workFor contractorsFor subcontractorCasual workWork at officeFlexible hours
$122k - $182k
...Full time Job Description Who We’re Looking For We are seeking a Consultant level HRIS Analyst who is as comfortable designing and... ...comfortable managing data loads and complex logic independently. Testing & Documentation: A disciplined approach to UAT, regression testing...Permanent employmentFull timeWork at officeLocal areaRemote work- ...Systems team is seeking a driven and technically skilled Technical Consultant specializing in Build and Software Engineering for Treasury... ...using SQL and treasury system tools. Execute rigorous testing protocols including unit, integration, and user acceptance testing...Relocation package
- ...Job Summary We are seeking an experienced SAP S/4HANA RTR Consultant with 8-10+ years of experience to manage and optimize the... ...with business stakeholders and cross-functional teams Support testing, documentation, and deployment activities Required Skills &...
- ...Principal Consultant (AMI Water) Date: May 10, 2026 Location: Tampa, FL, US Phoenix, AZ, US Overland Park, KS, US Atlanta, GA, US Dallas... ...discovery, strategy, justification, planning, implementation, testing and/or operation. Principal Consultants define the client...Full timePart timeWork experience placementRelocationVisa sponsorshipFlexible hours
- ...Winchill Consultant Location: Houston, TX A Windchill Consultant designs, implements, and supports PTC Windchill PLM (Product Lifecycle... ...applications using Java, XML, and REST/SOAP APIs. Testing & Deployment: Execute functional and integration testing, conduct...
- ...specializing in the fields of Software Development, Software Consultancy and Information Technology Enabled Services. Job Description Job... ...data warehousing , system Analysis, Design, Development, Testing and Implementation of Data warehouse. Enhancement and Maintaining...Full time
$18k
...Program Evaluation Consultant | Assessment and Evaluation Services ProSidian is seeking a Program Evaluation Consultant for Program... ...must be a United States Citizen Background Check And Drug testing: ProSidian reserves the right to require background checks, including...Full timeContract workFor contractorsInterim rolePlacement yearH1bWork at officeImmediate startFlexible hours$60.71 - $62.5 per hour
...in Tool admin activities Coordinate with Tricentis and resolve the issues. Support the team in Automation and Data strategy testing activities. Minimum years of experience 10 years Certifications Needed : Yes (Tricentis Tosca certified AS1, AS2-) Top...Contract work- ...assisting credit union members from the teller line and member consultants desks as directed by manager # Perform opening and closing... ...Successfully complete all applicable compliance training and testing. # Participate in business development activities including...Full timeWork at office
- ...CI/CD tools like Jenkins ~ Track record in large-scale system software development. ~ Best practices with TDD, unit/integration testing, code coverage, strong documentation talent including functional designs, comments/readme's, how-to's/runbooks etc ~ Strong with...
- ...Senior Consultant with Guidewire - Policycenter - Claimcenter Location: San Antonio or Plano, TX The Senior Consultant specializing... ...assistance during the implementation phase. Conduct system testing and quality assurance to ensure the reliability and accuracy...
- ...difference. Your role and responsibilities As a Delivery Consultant specializing in Technology Expert Labs services for IBM's zStack... ...Services, and planning for sysplex split of production and test z/OS environments. Required technical and professional expertise...
- ...The IS Operations Consultant provides consulting, planning, and operational support for technology initiatives across the organization... ...efficiency and support operational goals. Participate in testing activities, including documentation, test planning support, and...Work experience placementInternshipImmediate start
$90k - $110k
...software engineering role. We’re hiring a Senior HubSpot Platform Consultant to lead complex HubSpot implementations, migrations, and... ...-phase lifecycle: Discovery → Solution Design → Build → Testing → Go-Live Each phase includes: A clear definition of "done...Remote workFlexible hours- ...Claims Technology team is seeking a highly experienced Informatica Consultant to work closely with business and technology partners to... ...Qualifications ~5-7 years of proven, hands-on experience in API testing using SoapUI, SOATest, or equivalent ~ Experience as a...Work experience placementWork at officeImmediate startFlexible hours
- ...to Cash process. Oversee integration with other processes (Record to Report, Source to Pay, Plan to Produce). Lead system testing, user training, and solution deployment. Manage ongoing operations, including team supervision and performance management....
- ...CATIA/DELMIA Automation Consultant We are seeking a skilled Automation Consultant with expertise in CATIA V5 and DELMIA to join our... ...manufacturing process planning and shop floor operations. Testing and Validation: Conducting unit testing, debugging, and user acceptance...Work experience placement
- ...MuleSoft Consultant Sonsoft, Inc. is a USA based corporation duly organized under the laws of the Commonwealth of Georgia. Sonsoft... ...documentation. Documents design specifications, troubleshoots and testing. Actively involved with requirement understanding and analysis...Full time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Testing Consultant. Be the first to apply!



