
Senior Network and Cloud Penetration Tester
Posted Jul 31

Posted Jul 31
This is a fully remote position, open to applicants in Texas.
• Accountable for the implementation of security testing projects following a structured methodology, which encompasses the creation of test reports.
• This role may involve overseeing and/or executing the configuration and deployment of security testing software, as well as applying results to security analysis.
• Aids in conducting highly technical and analytical security assessments of Active Directory environments, network infrastructure, cloud settings, and AI technologies, using manual, custom, and recognized industry attack methods guided by a risk-based intelligence-led approach.
• Detects potential misuse scenarios.
• Provides guidance on secure development methodologies.
• Acts as a technical leader in business areas as a Security Testing subject matter expert.
• Supports the execution of security testing operations, which includes pre-engagement (scoping), engagement (testing), and post-engagement activities (reporting).
• Collaborates with management and colleagues to nurture the development of less experienced Security Testing Consultants.
• Partners with leadership to enhance the security testing team's capabilities, including reporting and remediation guidance in accordance with local and global regulatory standards.
• Identifies security vulnerabilities and deficiencies through risk assessments and recommends corrective actions for discovered weaknesses.
• Aids in the planning, testing, tracking, and provides advice on necessary risk acceptance for identified security risks.
• Conducts hands-on penetration testing for BMO and its various business divisions.
• Engages with stakeholders to comprehend issues and opportunities, enabling BMO to achieve its objectives by aligning with business vision, goals, and KPIs.
• Develops and promotes information security best practices while staying updated on industry trends through participation in professional associations.
• A minimum of 5+ years of experience in Manual Penetration Testing of Networks and Cloud Environments.
• Strong expertise in Active Directory Environments, including associated vulnerabilities and exploitation techniques.
• Extensive experience with Cloud Environments and the vulnerabilities associated with commonly used features in large multi-tenant and hybrid enterprise frameworks.
• Proficient in security testing tools and penetration testing Linux distributions such as Kali.
• In-depth practical knowledge of the Mitre Attack framework.
• Strong understanding of Network and Cloud architecture.
• Proficiency in at least one scripting language.
• Capability to document reproducible steps for technically accurate findings.
• Experience with security testing of agentic AI solutions is an advantage.
• Familiarity with security testing of CI/CD pipelines is a plus.
• Ability to identify and exploit vulnerabilities in Active Directory settings and Cloud workflows, as well as multi-step attack vectors.
• 5-8 years of experience in information systems, software development, and/or information security is preferred.
• Excellent written and verbal communication skills, with the ability to convey complex technical observations to a non-technical audience.
• Strong time management skills; capable of committing to and meeting time-sensitive deliverables.
• Ability to work remotely, independently or in a team, take direction, and demonstrate initiative as a self-starter.
• Competence in leading conference calls, serving as the main point of contact, overseeing report generation activities, and being the primary liaison with internal teams during engagements.
• Bachelor’s degree in Information Security, Information Technology, Information Systems Management, Computer Science, Engineering, or related fields, or equivalent demonstrated work experience.
• Preference will be given to candidates with at least one certification in a related field, particularly from reputable institutions in Information Security (e.g., OSCP, OSEP, HackTheBox Cloud security testing certificates, etc.).
• Health insurance
• Tuition reimbursement
• Accident and life insurance
• Retirement savings plans
IUNA AI
TEKsystems
Quest Global
McBride
Get handpicked remote jobs straight to your inbox weekly.