Software Engineer
Perform deep, manual penetration testing of enterprise network and cloud environments, including AI‑enabled services, to identify and remediate security gaps. Leverage tools like Kali Linux, Metasploit, and Python while working with AWS and other cloud platforms.
Application Deadline:
Address:
Job Family Group:
Join a team where your work goes beyond checklists protecting critical Network and Cloud environments with real business and regulatory impact. Why join this team?
High-impact, meaningful work
Directly influence the security of Network\Cloud environments and AI solutions that support applications that matter to customers, regulators, and the business.
Depth over volume
Focus on deep, manual penetration testing (Network, Cloud, and AI with human in the loop)—not automated, scanner-driven assessments.
Accelerated technical growth
Work in complex, enterprise-scale environments that expose you to advanced architectures and evolving threats.
End-to-end ownership
Engage across the full lifecycle: scoping → testing → reporting → remediation, with visibility and influence throughout.
Modern tools and techniques
Use advanced testing tools to enhance testing depth and efficiency.
More meaningful engagements
Experience fewer, higher-quality engagements versus consulting-style, high-volume work.
Ongoing training expensed
CORE Responsibilities:
The Penetration Tester reports to the Sr. Manager of Network and Strategic Penetration Testing and assists with the security testing activities for BMO network, cloud, and AI technologies. The role will be responsible for the execution and coordination of ethical hacking to identify weaknesses and areas for improvement.
Penetration Testing - Assists in delivery of security testing projects according to a structured process, to include writing test reports. This may include oversight and/or execution of the configuration and deployment of security testing software and application of results to security analysis. Assists with the execution of highly technical/analytical security assessments of Active Directory environments, network infrastructure, cloud environments, and AI technologies, including manual, custom and industry known attack methods using a risk-based intelligence-led methodology. Identifies potential misuse scenarios. Advises on secure development practices.
Subject Matter Expertise - Provides technical leadership to business areas as a Security Testing subject matter expert. Assists with efforts on the execution of security testing operations to include pre-engagement (scoping), engagement (testing) and post-engagement activities (reporting).
Information Security Risk Management - Works with leadership to mature security testing team capabilities including reporting and remediation guidance in alignment with local and global regulatory requirements. Identifies security gaps and deficiencies by conducting risk assessments; able to recommend correct
Posted June 26, 2026