
AI Penetration Tester
Posted 19 hours ago

Posted 19 hours ago
This is a fully remote position, open to applicants in North Carolina.
• Conduct security evaluations of AI systems, large language models (LLMs), AI agents, and machine learning applications.
• Implement adversarial testing techniques such as prompt injection, jailbreaks, model manipulation, and abuse-case assessments.
• Carry out application, API, and cloud security assessments for AI-enhanced solutions.
• Create standardized AI security testing methodologies, tools, and automation processes.
• Collaborate with development and engineering teams to validate findings and implement remediations.
• Generate technical reports and executive summaries that communicate risks and recommendations.
• Investigate emerging AI threats and attack methodologies.
• Assist in red team exercises that involve AI-driven attack scenarios.
• Offer analysis and reporting services to business groups and BMO.
• Build relationships with stakeholders, identify challenges and opportunities, and propose solutions.
• Analyze data and produce documents and plans for internal stakeholders.
• Ensure that requirements align with business needs, obtain stakeholder approval, and uphold quality standards.
• Engage in or facilitate user acceptance testing.
• Provide support for information security processes, applications, and infrastructure.
• Contribute strategic insights and specialized analytical support to senior management.
• Serve as a subject matter expert on regulations, policies, information security, and associated processes.
• Define analytics and reporting needs while analyzing trends to mitigate issues.
• Communicate and present information to IT and business-unit stakeholders, including senior leaders.
• Prepare reference materials and training resources for end-users.
• Troubleshoot information security challenges and collaborate with vendors as necessary.
• Collect, document, validate, and manage requirements for audits, reports, and projects.
• Mentor team members, share knowledge, and foster information security communities of practice.
• Gather, organize, cleanse, analyze, and distribute complex data.
• Develop data collection systems and strategies to enhance efficiency and data integrity.
• Document and maintain processes, procedures, and requirements.
• Suggest enhancements to streamline and integrate information security processes.
• Monitor new technologies and threats and identify mitigation strategies.
• Implement BMO's Risk Management Framework and make risk-informed decisions in accordance with policies, laws, regulations, and business strategy.
• Typically requires 7+ years of relevant experience.
• Bachelor’s degree in Information Security, Computer Science, Engineering, Information Systems, Business, or a related field, or an equivalent combination of education and experience.
• Multiple Information Security certifications from reputable institutions, such as (ISC)2, ISACA, or SANS.
• Extensive experience in information security, technology, business requirements gathering, and reporting within a financial services environment.
• Proficient in data manipulation and analysis.
• In-depth knowledge of Information Security processes, procedures, and controls.
• Strong understanding and problem-solving skills regarding Information Security issues across the organization.
• Comprehensive understanding of NIST CSF, ISO 27001, and ISO 27002.
• Profound knowledge of Information Security risk and regulatory requirements.
• Awareness of computing-environment complexities and security-platform implications.
• Exceptional verbal and written communication abilities.
• Strong analytical and problem-solving skills.
• Excellent influencing and collaboration skills.
• Ability to navigate ambiguity effectively.
• Data-driven decision-making expertise.
• Advanced experience in penetration testing across web applications, APIs, and cloud environments.
• Practical experience in assessing AI/LLM technologies, AI agents, ML models, or Generative AI applications.
• Solid understanding of offensive security methodologies and adversarial attack techniques.
• Experience with Python scripting and the development/automation of security tools.
• Familiarity with OWASP Top 10, API Security Top 10, and emerging OWASP LLM Security risks.
• Experience in threat modeling and security assessments.
• Strong grasp of authentication, authorization, identity, and cloud security principles.
• Capability to document findings and remediation suggestions clearly.
• Authorization to work/reside in the USA within EST or CST time zones.
• Performance-based incentives.
• Discretionary bonuses.
• Health insurance.
• Tuition reimbursement.
• Accident insurance.
• Life insurance.
• Retirement savings plans.
• Comprehensive training and coaching.
• Support from management.
• Opportunities for network building.
• Flexible remote work options within EST or CST time zones.
Accelerated
In All Media
Virtual Colleague Philippines
TRAC Recruiting
Get handpicked remote jobs straight to your inbox weekly.