
AI Penetration Tester
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Florida.
• Conduct security evaluations of AI systems, large language models (LLMs), AI agents, and machine learning applications.
• Carry out adversarial testing, which includes prompt injection, jailbreaks, model manipulation, and abuse-case evaluations.
• Implement security testing for applications, APIs, and cloud environments for AI-driven solutions.
• Create repeatable methodologies, tools, and automation for AI security testing.
• Collaborate with development and engineering teams to verify and address identified issues.
• Generate technical reports and executive summaries that convey risks and recommendations.
• Investigate emerging threats and attack techniques in the AI domain.
• Assist in red team exercises that involve AI-based attack scenarios.
• Provide analytical and reporting services for business units and BMO.
• Establish relationships with stakeholders, comprehend challenges and opportunities, and propose solutions.
• Analyze data and prepare documents and strategies for internal stakeholders.
• Engage in or facilitate user acceptance testing.
• Deliver customer support related to information security processes, applications, and infrastructure.
• Offer strategic insights as a trusted advisor and provide specialized analytical support to senior management.
• Serve as a subject matter expert on regulations, policies, and information security.
• Communicate and present across IT and business units; prepare presentations for senior leadership.
• Lead the creation of end-user reference and training materials.
• Collaborate with vendors to resolve issues as needed.
• Address information security challenges within designated business units.
• Gather and document requirements for audits, reports, and projects.
• Facilitate discussions on requirements and manage them through structured analysis.
• Collect, organize, analyze, and disseminate information; identify trends and data quality concerns.
• Develop systems and strategies for data collection.
• Maintain documentation for processes, procedures, and requirements.
• Suggest methods to enhance and integrate information security processes.
• Keep abreast of emerging information security technologies and threats, determining appropriate mitigation strategies.
• Support technical development, mentorship, communities of practice, and information security networks.
• Apply BMO's Risk Management Framework and make risk-informed decisions that align with policies, laws, and regulations.
• Additional responsibilities or accountabilities may be assigned as required.
• Typically requires over 7 years of relevant experience.
• A post-secondary degree in Information Security, Computer Science, Engineering, Information Systems, Business, or a related field, or an equivalent combination of education and experience.
• Multiple recognized Information Security certifications from reputable institutions (e.g., (ISC)2, ISACA, SANS).
• Extensive experience in information security, technology, business requirements gathering, and reporting within a financial services context.
• Proficient in data manipulation and analysis.
• Deep understanding of information security processes, procedures, and controls.
• Strong problem-solving skills concerning information security issues across the organization.
• Comprehensive understanding of the NIST Cyber Security Framework (CSF), ISO 27001, and ISO 27002.
• In-depth knowledge of information security risk and regulatory standards.
• Familiarity with the complexities of computing environments and their security implications.
• Superior verbal and written communication skills.
• Advanced analytical and problem-solving abilities.
• Strong influence and collaboration skills.
• Ability to navigate ambiguity effectively.
• Proficient in data-driven decision-making.
• Advanced experience in penetration testing across web applications, APIs, and cloud infrastructures.
• Hands-on experience assessing AI/LLM technologies, AI agents, machine learning models, or generative AI applications.
• Strong knowledge of offensive security methodologies and adversarial attack strategies.
• Experience with Python scripting and the development/automation of security tools.
• Familiarity with OWASP Top 10, API Security Top 10, and emerging OWASP LLM Security risks.
• Experience in performing threat modeling and security evaluations.
• Strong grasp of authentication, authorization, identity, and cloud security principles.
• Ability to document findings and remediation recommendations clearly.
• Must be able to work remotely in the USA within the EST or CST time zones.
• Health insurance.
• Tuition reimbursement.
• Accident and life insurance.
• Retirement savings plans.
• Performance-based incentives.
• Discretionary bonuses.
• Comprehensive training and coaching.
• Support from management.
• Opportunities for networking.
• Reasonable accommodations for individuals with disabilities.
Accelerated
In All Media
Virtual Colleague Philippines
TRAC Recruiting
Get handpicked remote jobs straight to your inbox weekly.