Penetration Testing Consultant
$82.8k - $154.8kBmo
Information Security Consultant
Join a team where your work goes beyond checklists protecting critical financial applications with real business and regulatory impact. Why join this team?
High-impact, meaningful work
Directly influence the security of applications that matter to customers, regulators, and the business.
Depth over volume
Focus on deep, manual penetration testing (web, mobile, APIs)—not automated, scanner-driven assessments.
Accelerated technical growth
Work in complex, enterprise-scale environments that expose you to advanced architectures and evolving threats.
End-to-end ownership
Engage across the full lifecycle: scoping → testing → reporting → remediation, with visibility and influence throughout.
Modern tools and techniques
Use advanced testing tools to enhance testing depth and efficiency.
More meaningful engagements
Experience fewer, higher-quality engagements versus consulting-style, high-volume work.
Key Skills:
- Min of 3+ years experience with Manual Penetration Testing experience in Web or API. This includes strong exposure for testing Web applications in the following areas:
A solid grasp of protocols, headers, cookies, sessions, and CORS behavior within your web testing experience
Experience testing authentication and authorization mechanisms (OAuth, JWT, session flaws, IDOR/BOLA)-
Strong proficiency with Burp Suite Professional, OWASP ZAP, IBM's APP SCAN, (proxying, repeater, intruder, extensions)-
Deep practical knowledge of OWASP Top 10 (Web + API) and common vulnerabilities
- Ability to identify and exploit business logic vulnerabilities and multi-step attack paths
- Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. OSCP, GMOB, GWAPT, OSWE).
- Secure coding and architecture understanding
- Proficiency in at least one scripting language
- Proficiency in documenting reproducible steps for technical accurate findings -
Core Responsibilities:
Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs
Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.
Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.
Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.
Additional Information:
Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Leads the development of information security strategy by understanding business processes, policies, information and information systems. Builds exceptional relationships with internal and external stakeholders. Ensures that requirements and solutions align to a real business need, are approved by all relevant stakeholders, and meets essential information security standards. Provides thought leadership, promotes new processes and methodologies and emerging technologies, with the flexibility to align to the unique requirements of the business/group and deliverables.
- Acts as a trusted advisor to assigned business/group.
- Assists in the development of strategic plans.
- Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.
- Supports the execution of strategic initiatives in collaboration with internal and external stakeholders.
- Helps determine business priorities and best sequence for execution of business/group strategy.
- Breaks down strategic problems, and analyses data and information to provide insights and recommendations.
- Acts as the day to day contact for vendors; supports the implementation, maintenance, and sustainment of vendor solutions.
- Understands the strategy, plans, activities and needs of all stakeholders and translates those business needs into solutions and makes recommendations.
- Provides advice, counsel and support on information security matters and recommends solutions to assigned business/group leaders on principles, frameworks, programs, approaches, trends, legislation and regulatory requirements including interpretation of policy and identification and management of risk.
- Builds credibility and influences/negotiates effectively to drive business performance through development and delivery of information security solutions.
- Tracks metrics and milestones, providing recommendations for resolution and escalating as appropriate when issues arise.
- Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.
- Promotes process improvements and methodologies; keeps emerging information security issues and trends in mind and ensures standards are followed.
- Creates professional presentations and deliver them in a meaningful concise way.
- Assesses information security impact to a project's benefits and risks when scope changes.
- Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.
- Gathers, examines and interprets data and information to extract meaningful insights, answer business questions and provide actionable recommendations.
- Assists with continuous improvement activities and root cause analysis with the goal of strengthening information security capabilities.
- Ensures consistent, high quality practices/work and the achievement of business results in alignment with business/group strategies and with productivity goals.
- Focus is primarily on business/group within BMO; may have broader, enterprise-wide focus.
- Provides specialized consulting, analytical and technical support.
- Exercises judgment to identify, diagnose, and solve problems within given rules.
- Works independently and regularly handles non-routine situations.
- Broader work or accountabilities may be assigned as needed.
- Take measured risks while protecting the bank by applying our Risk Management Framework in the execution of your role, in line with our Risk Culture and within our approved Risk Appetite, making sound and risk informed decisions that align to business strategy, protect assets, and adhere to applicable policy documents (Frameworks, Policies, Standards, Procedures and Supporting documents), laws and regulations.
Qualifications:
- Typically between 4 - 7 years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experience.
- Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).
- Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002, Payment Card Industry (PCI) Data Security Standard (DSS), etc. - In-depth.
- Experience in information security concepts and methodology.
- Knowledge of business analysis, project delivery practices and standards across the project lifecycle - In-depth.
- Knowledge of information security processes, procedures and controls - In-depth.
- Understanding of and problem solving ability for information security issues within their business group - Working.
- Understanding of information security risk and regulatory requirements - Working.
- Deep knowledge and technical proficiency gained through extensive education and business experience.
- Verbal & written communication skills - In-depth.
- Collaboration & team skills - In-depth.
- Analytical and problem solving skills - In-depth.
- Influence skills - In-depth.
- Data driven decision making - In-depth.
Salary :
$82,800.00 - $154,800.00
- ...IBM Computing is looking for a Global Security Consultant who will lead penetration tests against various applications and provide expert security consulting. Ideal candidates will have over 10 years of specialized experience in security testing and consulting across...SuggestedRemote work
$64k - $117k
...what we do. We are thought leaders, consultants, and cybersecurity experts, but above all... ...best practices • Manage your own testing priorities and deliver high-quality work... ...executive stakeholders • Scope and lead penetration testing engagements from start to...SuggestedWork at officeRemote workFlexible hours- IBM Computing is seeking a Senior Pentest Consultant for its X-Force Red Offensive Security team. This role involves conducting penetration tests on applications and networks while assisting in client interactions. Candidates should have over three years of experience in...SuggestedRemote job
$88.8k - $165.6k
...and the business. Depth over volume Focus on deep, manual penetration testing (web, mobile, APIs)—not automated, scanner-driven assessments... ...Experience fewer, higher-quality engagements versus consulting-style, high-volume work. KEY SKILLS: - Min of 3+ years experience...SuggestedFull timeContract workPart timeLocal area$1,000 per month
..., with a focus on Purple Teams. The Senior Consultant will be responsible for leading and executing advanced purple team testing programs for Fortune 1000 companies. This role... ...have a strong background in cybersecurity, penetration testing, and incident response....SuggestedFull timeCasual workWork at officeLocal areaRemote workMonday to FridayFlexible hoursNight shiftAfternoon shift- ...Schedule: 6:30PM - 7:00AM PRIMARY PURPOSE Serves as a lactation consultant in the Women & Family Education department within the WISH and... ...right to change/cancel exam dates and delays the release of test results. In instances when the staff member's exam date is...Full timeTemporary work
- ...GRC Consultant Downey, CA - Remote 12+ months Description:... ...analysis, application-level vulnerability testing, and security code reviews; develop and... ...control assessment engagements and regular penetration testing • Experience with business...Remote work
$89.6k - $194k
...RMF/ATO Consultant - U.S. Citizenship Required Category: Business Consulting, Strategy... ..., evidence collection, interviews, and testing. • Perform internal control reviews... ...findings from vulnerability scans, penetration tests, and audit actions. • Coordinate...Full timeContract workWork at officeLocal area2 days per week- ...Position: Zsclar Consultant Location: Downey, CA Duration: 12+ months Skills Required: Information... ...analysis; developing mitigation plans; and performing penetration testing, password protection testing and application security testing...Remote work
- ...etc.) Must be a US CITIZEN. Master of the OSINT concept Knowledge of TCP/IP, web, and network security Knowledge/experience in penetration testing and vulnerability assessment and actively participated in penetration tests Importance of reporting and documentation...Remote workWorldwide
- ...national leader in geotechnical engineering, environmental consulting, and materials testing and inspection, we collaborate on transformative... ...visits to collect precise field measurements, including penetrations, drains, and existing conditions. Inspect building envelope...Contract workFor contractorsLive inWork at office
$50 - $60 per hour
Industrial Cybersecurity Consultant STSI is looking for a Cyber Security Consultant who is detail oriented with a willingness to... ...Consultant supports the execution of projects consisting of network penetration testing, web application security testing, cybersecurity...Full timeContract workLocal areaMonday to Friday$70k - $90k
Job Category : Technologists / Consultants Locations Seattle, WA 98103, USA Description The... ...documenting observations and field-testing results. Provide recommendations for all... ...detailing and identify area of risk for water penetration, air leakage, and/or condensation....Full timeContract workFor contractorsWork at officeShift work- ...Association is in search for an experienced Epidemiological Consultant to support a national review of incidence and prevalence... ...certified and undergoes annual external audits and third‑party penetration testing, ensuring ongoing compliance with international information...
- ...Thomas Group (STG) is currently looking to add to our team of consultants under our Workforce Management Practice . As part of... ...clocks Complete setup and integration with WorkForce Manager Testing each time clock using a sample employee profile to ensure all...Remote work
$59k - $86.65k
...levels in an organization Recommended Skills: Client-Centric, Effective Communication, Information Security, Innovation, Network Penetration Testing, Security Information and Event Management (SIEM), Security Tools, Technical Proficiency, Time Management, Vulnerability...Work at office3 days per week$10,000 per month
...a partner company. We are currently looking for a Paid Search Consultant in United States. This role is a foundational opportunity to... ...ROAS, CPL, CAC, and pipeline metrics. Develop structured testing frameworks across keywords, audiences, creatives, bidding strategies...Remote jobFull time$100k - $122k
...partner company. We are currently looking for a Bureau Solution Consultant in the United States. This role sits at the intersection of... ..., resolve questions, and validate delivered configurations. Test and validate bureau content to ensure accuracy, compliance, and...Remote jobContract workTemporary workWork at officeFlexible hours$86k - $148k
...behalf of a partner company. We are currently looking for a Senior Consultant, SOC 2 Assessment in United States. This role sits at the... ...and assessments, including planning, evidence review, control testing, and client interviews, while also supporting SOC 1, C5, and...Remote jobFull timeFlexible hours$75k - $119k
...systems Asset integrity programs — evaluation of inspection, testing and maintenance (ITM) strategies, including preventive,... ...practical, cost-effective loss prevention recommendations. Consultant Engineers apply FM Property Loss Prevention Data Sheets and communicate...Full timeLive inHome officeFlexible hoursNight shift$71k - $122.69k
...on behalf of a partner company. We are currently looking for a Consultant, FedRAMP Assessment in the United States. This role sits at... ...and client environments Validate security controls through testing procedures, evidence inspection, and risk-based evaluation...Remote jobFull timeFlexible hours$128.09k - $192.14k
...looking for a Workday Absence & Time Tracking Senior Principal Consultant based in the United States. This role is a senior... ...Tracking subject matter expert across design, configuration, testing, and implementation Lead client design sessions and guide configuration...Remote jobFull timeTemporary work- ...Infosys is seeking a Senior 09 Consultant with a strong background in supply chain solutions, and you will anchor different phases of... ...requirements specifications, consulting on functionalities implemented, testing of deployed planning process with the objective of providing...Full timeTemporary workRelocation
$115.47k - $143.58k
...Nurse Practitioner or Physician Assistant to join our Cardiology Consultant Team. ChristianaCare Cardiology Consultants is a large... ...discharge. The job also requires monitoring outpatient stress testing, as well as interpretation of EKGs and applying diagnostic studies...Local areaShift work- ...financial modelers, technologists, former bankers, and longtime consultants—to address immediate risks and drive tangible benefits. The... ...credit risk, valuation, capital planning, and stress-testing, liquidity, resolution planning, and model risk management. Functional...Work experience placementWork at officeImmediate start
- ...expert for Workday Core HCM .Lead the design, configuration, testing, deployment, and optimization of Workday Core HR functionality... ...in a multinational or global organizati on.Previous consulting experience with a major consulting firm, Workday partner, or system...Local area
$112k - $130k
...clear, defensible findings. We are seeking a dynamic Building Consultant in the tri-state area with estimating experience in the... ...will be required to participate in any necessary respirator fit testing, training, and medical evaluations in accordance with OSHA standards...Work experience placementImmediate startFlexible hoursNight shift$50 - $55 per hour
...Trident Consulting is seeking a " Senior Java Consultant ” for one of our clients in " Charlotte, NC " Job Title: Senior Java Consultant... ...code developed by team. Participate in peer reviews and testing activities. Review / approve merge requests. Assist with...Contract workLocal area- ...About the Job NextReg is seeking a proactive, tech-savvy Senior Consultant to join our dynamic team. In this role, you will act as a... ...client's unique business model (RIA, BD, or dual-registrant). Testing, Audits & Exams : Execute ongoing compliance testing and lead...Work at office
- ...Job Title: Filenet Consultant Location: Phoenix, AZ Interview: Video Interview Description: Skill Set Required: - IBM... ...complex system/components and game planning. - Perform Smoke Testing on deployed code/configurations to ensure success of deployment...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Testing Consultant. Be the first to apply!
- sailpoint consultant United States
- lead analytics consultant United States
- iam consultant United States
- sox consultant United States
- consultant part time United States
- lean consultant United States
- power bi consultant United States
- therapy consultant United States
- loss control consultant United States
- ocm consultant United States






