Remotery

Senior Network and Cloud Penetration Tester

atBMO U.S.RemoteCA flagCanadaFull-timeQA Engineer (Quality Assurance)SeniorC$103.2k – C$192k/year

Posted Jul 31

This is a fully remote position, open to applicants in Canada.

📋 Description

• Oversee the implementation of security testing projects following a structured methodology, including the preparation of test reports.

• This role may involve managing and/or executing the setup and deployment of security testing software, as well as analyzing results for security evaluations.

• Contribute to the execution of complex technical and analytical security assessments for Active Directory environments, network infrastructure, cloud settings, and AI technologies, utilizing both manual and widely recognized attack techniques through a risk-based, intelligence-led approach.

• Detect potential misuse scenarios.

• Provide guidance on secure development practices.

• Act as a technical leader within business units, serving as a Security Testing subject matter expert.

• Support the execution of security testing operations encompassing pre-engagement (scoping), engagement (testing), and post-engagement activities (reporting).

• Assist in security testing efforts aimed at exploiting vulnerabilities to bolster the security of BMO's network, cloud, and AI technologies.

• Collaborate with management and colleagues to mentor less experienced Security Testing Consultants.

• Partner with leadership to enhance the capabilities of the security testing team, including reporting and remediation guidance aligned with local and global regulatory standards.

• Identify security vulnerabilities and weaknesses through risk assessments and recommend corrective actions.

• Aid in the planning, testing, tracking, and advising on necessary risk acceptance for identified security threats.

• Conduct hands-on penetration testing for BMO and its various businesses/groups.

• Engage with stakeholders to grasp challenges and opportunities, enabling BMO to achieve its objectives by understanding business vision, goals, and KPIs.

• Offer technical consultation to business units as a Security Testing expert.

• Comprehend and articulate the core processes, risks, and mitigation strategies for identified security vulnerabilities.

• Advocate for information security best practices, keeping informed about industry trends and developments through participation in professional associations.

• Facilitate discussions and maintain a structured approach to planning, eliciting, analyzing, documenting, communicating, and managing initiatives and issues with stakeholders, utilizing various elicitation techniques to explore, challenge, and understand associated risks.


⛳️ Requirements

• At least 5+ years of experience in Manual Penetration Testing of Networks and Cloud Environments.

• Strong knowledge of Active Directory Environments and related vulnerabilities and exploitation techniques.

• Extensive experience with Cloud Environments and associated vulnerabilities in commonly utilized features in large multi-tenant and hybrid enterprise settings.

• Proficient with security testing tools and penetration testing Linux distributions such as Kali.

• In-depth practical understanding of applying the Mitre Attack framework.

• Strong grasp of Network and Cloud architecture.

• Proficient in at least one scripting language.

• Ability to document reproducible steps for technically accurate findings.

• Experience with security testing of agentic AI solutions is an advantage.

• Familiarity with security testing of CI/CD pipelines is a plus.

• Capable of identifying and exploiting vulnerabilities in Active Directory environments and Cloud workflows, as well as navigating multi-step attack paths.

• 5-8 years of experience in information systems, software development, and/or information security is preferred.

• Excellent written and verbal communication skills, with the ability to convey complex technical observations to a non-technical audience.

• Strong time management skills; ability to commit to and meet time-sensitive deliverables.

• Capacity to work remotely, independently or collaboratively, take direction, and be a proactive self-starter.

• Ability to lead conference calls, serve as the primary point of contact, drive report generation activities, and interface with internal teams on engagements.

• Bachelor’s degree in Information Security, Information Technology, Information Systems Management, Computer Science, Engineering, or a related field, or equivalent demonstrated experience.

• Preference for candidates holding at least one relevant certification, with a strong preference for recognized information security certifications (e.g., OSCP, OSEP, HackTheBox Cloud security testing certificates, etc.).


🏝️ Benefits

• Health insurance

• Tuition reimbursement

• Accident and life insurance

• Retirement savings plans

People also viewed

IUNA AI14 hours ago

Werkstudent – AI Data Annotation, Quality Assurance

DE flagGermany OnlyPart-timeQA Engineer (Quality Assurance)
ApplyView job
TEKsystems17 hours ago

Clinical Quality Assurance Specialist

US flagIllinois OnlyFreelanceQA Engineer (Quality Assurance)$26 – $28/hour
ApplyView job
Quest Global17 hours ago

Supplier Quality Engineer

US flagArizona OnlyFull-timeQA Engineer (Quality Assurance)$70k – $80k/year
ApplyView job
McBride18 hours ago

QA Tester – Oracle Core Banking Cloud, Payments

US flagUnited States OnlyFull-timeQA Engineer (Quality Assurance)
ApplyView job
ScholarshipOwl20 hours ago

QA Engineer – Mobile

Anywhere in the WorldFull-timeQA Engineer (Quality Assurance)
ApplyView job
Xflow23 hours ago

Head of QA – Product Quality

IN flagIndia OnlyFull-timeQA Engineer (Quality Assurance)
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers