Remotery

Senior Network and Cloud Penetration Tester

atBMO U.S.RemoteUS flagTexasFull-timeQA Engineer (Quality Assurance)Senior$122.4k – $228k/year

Posted Jul 31

This is a fully remote position, open to applicants in Texas.

📋 Description

• Accountable for the implementation of security testing projects following a structured methodology, which encompasses the creation of test reports.

• This role may involve overseeing and/or executing the configuration and deployment of security testing software, as well as applying results to security analysis.

• Aids in conducting highly technical and analytical security assessments of Active Directory environments, network infrastructure, cloud settings, and AI technologies, using manual, custom, and recognized industry attack methods guided by a risk-based intelligence-led approach.

• Detects potential misuse scenarios.

• Provides guidance on secure development methodologies.

• Acts as a technical leader in business areas as a Security Testing subject matter expert.

• Supports the execution of security testing operations, which includes pre-engagement (scoping), engagement (testing), and post-engagement activities (reporting).

• Collaborates with management and colleagues to nurture the development of less experienced Security Testing Consultants.

• Partners with leadership to enhance the security testing team's capabilities, including reporting and remediation guidance in accordance with local and global regulatory standards.

• Identifies security vulnerabilities and deficiencies through risk assessments and recommends corrective actions for discovered weaknesses.

• Aids in the planning, testing, tracking, and provides advice on necessary risk acceptance for identified security risks.

• Conducts hands-on penetration testing for BMO and its various business divisions.

• Engages with stakeholders to comprehend issues and opportunities, enabling BMO to achieve its objectives by aligning with business vision, goals, and KPIs.

• Develops and promotes information security best practices while staying updated on industry trends through participation in professional associations.


⛳️ Requirements

• A minimum of 5+ years of experience in Manual Penetration Testing of Networks and Cloud Environments.

• Strong expertise in Active Directory Environments, including associated vulnerabilities and exploitation techniques.

• Extensive experience with Cloud Environments and the vulnerabilities associated with commonly used features in large multi-tenant and hybrid enterprise frameworks.

• Proficient in security testing tools and penetration testing Linux distributions such as Kali.

• In-depth practical knowledge of the Mitre Attack framework.

• Strong understanding of Network and Cloud architecture.

• Proficiency in at least one scripting language.

• Capability to document reproducible steps for technically accurate findings.

• Experience with security testing of agentic AI solutions is an advantage.

• Familiarity with security testing of CI/CD pipelines is a plus.

• Ability to identify and exploit vulnerabilities in Active Directory settings and Cloud workflows, as well as multi-step attack vectors.

• 5-8 years of experience in information systems, software development, and/or information security is preferred.

• Excellent written and verbal communication skills, with the ability to convey complex technical observations to a non-technical audience.

• Strong time management skills; capable of committing to and meeting time-sensitive deliverables.

• Ability to work remotely, independently or in a team, take direction, and demonstrate initiative as a self-starter.

• Competence in leading conference calls, serving as the main point of contact, overseeing report generation activities, and being the primary liaison with internal teams during engagements.

• Bachelor’s degree in Information Security, Information Technology, Information Systems Management, Computer Science, Engineering, or related fields, or equivalent demonstrated work experience.

• Preference will be given to candidates with at least one certification in a related field, particularly from reputable institutions in Information Security (e.g., OSCP, OSEP, HackTheBox Cloud security testing certificates, etc.).


🏝️ Benefits

• Health insurance

• Tuition reimbursement

• Accident and life insurance

• Retirement savings plans

People also viewed

IUNA AI14 hours ago

Werkstudent – AI Data Annotation, Quality Assurance

DE flagGermany OnlyPart-timeQA Engineer (Quality Assurance)
ApplyView job
TEKsystems17 hours ago

Clinical Quality Assurance Specialist

US flagIllinois OnlyFreelanceQA Engineer (Quality Assurance)$26 – $28/hour
ApplyView job
Quest Global17 hours ago

Supplier Quality Engineer

US flagArizona OnlyFull-timeQA Engineer (Quality Assurance)$70k – $80k/year
ApplyView job
McBride18 hours ago

QA Tester – Oracle Core Banking Cloud, Payments

US flagUnited States OnlyFull-timeQA Engineer (Quality Assurance)
ApplyView job
ScholarshipOwl20 hours ago

QA Engineer – Mobile

Anywhere in the WorldFull-timeQA Engineer (Quality Assurance)
ApplyView job
Xflow23 hours ago

Head of QA – Product Quality

IN flagIndia OnlyFull-timeQA Engineer (Quality Assurance)
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers