
Senior Network and Cloud Penetration Tester
Posted Jul 31

Posted Jul 31
This is a fully remote position, open to applicants in Texas.
• Accountable for the implementation of security testing projects following a defined process, including the creation of test reports.
• May involve overseeing and/or performing the setup and deployment of security testing software, as well as applying results for security analysis.
• Aids in conducting highly technical and analytical security assessments of Active Directory environments, network infrastructures, cloud platforms, and AI technologies, utilizing manual, custom, and industry-recognized attack methods based on a risk-informed, intelligence-led approach.
• Recognizes potential misuse scenarios and provides guidance on secure development practices.
• Acts as a Security Testing subject matter expert, offering technical leadership to various business areas.
• Supports the execution of security testing operations, which includes pre-engagement (scoping), engagement (testing), and post-engagement activities (reporting).
• Participates in security testing efforts focused on exploiting vulnerabilities to bolster the security of BMO's network, cloud, and AI technologies.
• Collaborates with management and colleagues to nurture the growth of less experienced Security Testing Consultants.
• Partners with leadership to enhance the capabilities of the security testing team, including reporting and remediation guidance in line with local and global regulatory standards.
• Detects security gaps and deficiencies through risk assessments and recommends corrective measures for identified vulnerabilities and weaknesses.
• Assists in the planning, testing, tracking, and advises on necessary risk acceptance for recognized security risks.
• Conducts hands-on penetration testing for BMO as a whole and for individual businesses/groups.
• Engages with stakeholders to comprehend problems and opportunities, enabling BMO to achieve its objectives by aligning with business vision, goals, and KPIs.
• Provides technical advice to business areas as a Security Testing subject matter expert.
• Understands and can articulate the core processes, risks, and mitigation techniques for identified security gaps to others.
• Develops and advocates for information security best practices while staying updated on industry trends through participation in professional associations.
• Facilitates discussions and employs a structured approach to plan, elicit, analyze, document, communicate, and manage initiatives and issues with stakeholders using various elicitation techniques to probe, challenge, and understand associated risks.
• At least 5+ years of experience in Manual Penetration Testing of Networks and Cloud Environments.
• Strong expertise in Active Directory Environments along with associated vulnerabilities and exploitation techniques.
• Extensive experience with Cloud Environments and the vulnerabilities related to commonly utilized features in large multi-tenant and hybrid enterprise settings.
• Proficient with security testing tools and penetration testing distributions such as Kali Linux.
• In-depth practical knowledge of the Mitre Attack framework.
• Significant understanding of Network and Cloud architecture.
• Proficient in at least one scripting language.
• Capable of documenting reproducible steps for technically accurate findings.
• Experience with security testing of agentic AI solutions is a plus.
• Familiarity with security testing of CI/CD pipelines is an advantage.
• Ability to identify and exploit vulnerabilities in Active Directory environments and Cloud workflows, including multi-step attack paths.
• 5-8 years of experience in information systems, software development, and/or information security is preferred.
• Excellent written and verbal communication skills, with the ability to convey complex technical observations to non-technical audiences.
• Strong time management abilities, with the capability to commit to and meet time-sensitive deliverables.
• Ability to work remotely, independently or collaboratively, take direction, and demonstrate initiative.
• Proficient in leading conference calls, acting as the main point of contact, managing report generation activities, and serving as the primary liaison with internal teams during engagements.
• Bachelor’s degree in Information Security, Information Technology, Information Systems Management, Computer Science, Engineering, or a related field, or equivalent work experience.
• Preference for candidates with at least one certification in a related field, particularly in Information Security certifications from recognized institutions (e.g., OSCP, OSEP, HackTheBox Cloud security testing certificates, etc.).
• Health insurance
• Tuition reimbursement
• Accident and life insurance
• Retirement savings plans
Xflow
Addus HomeCare
alt.bank
NMDP
Get handpicked remote jobs straight to your inbox weekly.