Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Penetration Testing Consultant

$82.8k - $154.8k per year
Full-time
Application Deadline:

08/30/2026

Address:
VIRTUAL59 - REMOTE/TELETRAVAIL - ON - BMO

Job Family Group:

Technology

Join a team where your work goes beyond checklists protecting critical financial applications with real business and regulatory impac t. Why join this team?
  • High-impact, meaningful work
  • Directly influence the security of applications that matter to customers, regulators, and the business.
  • Depth over volume
    Focus on deep, manual penetration testing (web, mobile, APIs)-not automated, scanner-driven assessments.
  • Accelerated technical growth
    Work in complex, enterprise-scale environments that expose you to advanced architectures and evolving threats.
  • End-to-end ownership
    Engage across the full lifecycle: scoping → testing → reporting → remediation , with visibility and influence throughout.
  • Modern tools and techniques
    Use advanced testing tools to enhance testing depth and efficiency.
  • More meaningful engagements
    Experience fewer, higher-quality engagements versus consulting-style, high-volume work.
KEY SKILLS:

- Min of 3+ years experience with Manual Penetration Testing experience in Web or API. This includes strong exposure for testing Web applications in the following areas:
  • A solid grasp of protocols, headers, cookies, sessions, and CORS behavior within your web testing experience
  • Experience testing authentication and authorization mechanisms (OAuth, JWT, session flaws, IDOR/BOLA)-
  • Strong proficiency with Burp Suite Professional , OWASP ZAP, IBM's APP SCAN, (proxying, repeater, intruder, extensions)-
  • Deep practical knowledge of OWASP Top 10 (Web + API) and common vulnerabilities
- Ability to identify and exploit business logic vulnerabilities and multi-step attack paths

- Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. OSCP, GMOB, GWAPT, OSWE).

- Secure coding and architecture understanding

- Proficiency in at least one scripting language

- Proficiency in documenting reproducible steps for technical accurate findings -

CORE Responsibilities:
  • Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs
  • Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs.
  • Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.
  • Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.
  • Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.
Additional Information:

Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Leads the development of information security strategy by understanding business processes, policies, information and information systems. Builds exceptional relationships with internal and external stakeholders. Ensures that requirements and solutions align to a real business need, are approved by all relevant stakeholders, and meets essential information security standards. Provides thought leadership, promotes new processes and methodologies and emerging technologies, with the flexibility to align to the unique requirements of the business/group and deliverables.
  • Acts as a trusted advisor to assigned business/group.
  • Assists in the development of strategic plans.
  • Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.
  • Supports the execution of strategic initiatives in collaboration with internal and external stakeholders.
  • Helps determine business priorities and best sequence for execution of business/group strategy.
  • Breaks down strategic problems, and analyses data and information to provide insights and recommendations.
  • Acts as the day to day contact for vendors; supports the implementation, maintenance, and sustainment of vendor solutions.
  • Understands the strategy, plans, activities and needs of all stakeholders and translates those business needs into solutions and makes recommendations.
  • Provides advice, counsel and support on information security matters and recommends solutions to assigned business/group leaders on principles, frameworks, programs, approaches, trends, legislation and regulatory requirements including interpretation of policy and identification and management of risk.
  • Builds credibility and influences/negotiates effectively to drive business performance through development and delivery of information security solutions.
  • Tracks metrics and milestones, providing recommendations for resolution and escalating as appropriate when issues arise.
  • Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.
  • Promotes process improvements and methodologies; keeps emerging information security issues and trends in mind and ensures standards are followed.
  • Creates professional presentations and deliver them in a meaningful concise way.
  • Assesses information security impact to a project's benefits and risks when scope changes.
  • Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.
  • Gathers, examines and interprets data and information to extract meaningful insights, answer business questions and provide actionable recommendations.
  • Assists with continuous improvement activities and root cause analysis with the goal of strengthening information security capabilities.
  • Ensures consistent, high quality practices/work and the achievement of business results in alignment with business/group strategies and with productivity goals.
  • Focus is primarily on business/group within BMO; may have broader, enterprise-wide focus.
  • Provides specialized consulting, analytical and technical support.
  • Exercises judgment to identify, diagnose, and solve problems within given rules.
  • Works independently and regularly handles non-routine situations.
  • Broader work or accountabilities may be assigned as needed.
  • Take measured risks while protecting the bank by applying our Risk Management Framework in the execution of your role, in line with our Risk Culture and within our approved Risk Appetite, making sound and risk informed decisions that align to business strategy, protect assets, and adhere to applicable policy documents (Frameworks, Policies, Standards, Procedures and Supporting documents), laws and regulations.

    Qualifications:
  • Typically between 4 - 7 years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experience.
  • Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).
  • Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002, Payment Card Industry (PCI) Data Security Standard (DSS), etc. - In-depth.
  • Experience in information security concepts and methodology.
  • Knowledge of business analysis, project delivery practices and standards across the project lifecycle - In-depth.
  • Knowledge of information security processes, procedures and controls - In-depth.
  • Understanding of and problem solving ability for information security issues within their business group - Working.
  • Understanding of information security risk and regulatory requirements - Working.
  • Deep knowledge and technical proficiency gained through extensive education and business experience.
  • Verbal & written communication skills - In-depth.
  • Collaboration & team skills - In-depth.
  • Analytical and problem solving skills - In-depth.
  • Influence skills - In-depth.
  • Data driven decision making - In-depth.
Salary :

$82,800.00 - $154,800.00

Pay Type:

Salaried

The above represents BMO Financial Group's pay range and type.

Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group's expected target for the first year in this position.

BMO Financial Group's total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit:

About Us

At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.

As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one - for yourself and our customers. We'll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we'll help you gain valuable experience, and broaden your skillset.

To find out more visit us at .

BMO is committed to an inclusive, equitable and accessible workplace. By learning from each other's differences, we gain strength through our people and our perspectives. Accommodations are available on request for candidates taking part in all aspects of the selection process. To request accommodation, please contact your recruiter.

Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Penetration Testing Consultant in Ontario vacancy
  • This is a remote position. Dinepalace is a restaurant technology and digital marketing company helping restaurants grow through online ordering systems, website development, and marketing solutions. Responsibilities Identify and reach out to prospective...
    Suggested
    Part time
    Remote work

    DinePalace.com / Foodme.Mobi

    Ontario
    10 days ago
  • $120k - $200k per year

    Ready to CRUSH Your Sales Goals and Earn Big? Join the Winning Team at Lifestyle – Where High Performers Thrive! We’re not just hiring salespeople, we’re building a dream team of closers, go-getters, and goal-destroyers who know how to make things happen. Want to be part...
    Suggested
    Full time
    Afternoon shift
    1 day per week

    Lifestyle Home Products

    Ontario
    7 days ago
  •  ...role in bringing life-changing biologics and vaccines to patients worldwide? We’re looking for a CMC Strategy Senior Associate / Consultant who thrives in a dynamic, collaborative environment and is passionate about shaping global regulatory strategies. In this role, you’... 
    Suggested
    Remote job
    Long term contract
    Worldwide
    Ontario
    19 days ago
  •  ...pages. Click here to link to our careers page! Peoples Jewellers is a people-first company, and we recognize that our jewellery consultants are every bit as dynamic and brilliant as the jewellery we offer. They are the reason Peoples Jewellers has become the largest... 
    Suggested
    Full time
    Part time
    Seasonal work
    Flexible hours
    Night shift
    Weekend work

    Signet Jewelers

    Ontario
    more than 2 months ago
  •  ...SecDesign Generalist acts as an internal consultant, performing multiple security...  ...Security (session security, vulnerability/Pen Testing, input validation) Secure data transport...  ...) Experience conducting/reviewing penetration tests, dynamic/static vulnerability assessments... 
    Suggested
    Contract work
    Work at office

    Astra North Infoteck Inc.

    Ontario
    9 days ago
  •  ...Responsibilities: Cond ucts penetration tests, vulnerability assessments, code reviews, threat hunting, network vulnerability assessments and red team exercises in all environments or applications related to the OPP and OPS province wide I&IT infrastructure and information... 
    Work at office

    Maarut

    Toronto, ON
    4 days ago
  •  ...how Clearspace prices commercial fit-outs end-to-end — from early test fits and feasibility budgets through to full project estimates...  ...and verbal communication skills — you’ll be writing to clients, consultants, vendors, and internal teams regularly. — A learning mindset and... 
    Full time
    For contractors
    Work at office

    Clearspace

    Ontario
    4 days ago
  •  ...Committees of Council and the Department. Facilitating public consultation and responding to inquiries. Preparing presentations to...  ...will be required for the successful candidate. Pre-employment testing may consist of written and oral assessments. How to Apply... 
    Work at office
    Immediate start
    Flexible hours

    Municipality of Clarington

    Ontario
    2 days ago
  •  ...strategy •    Making broker calls with a planned and well-prepared purpose focused on promoting our products and services to increase penetration •    Identify opportunities through local relationships, proactively seeking renewal and new account opportunities adding to the... 
    Apprenticeship
    Work at office
    Local area
    Worldwide

    Zurich

    Ontario
    12 days ago
  •  ...the NetSuite Systems Administrator you will act as an internal consultant to our teams applying your problem solving and analytical skills...  ...and upgrades. Report and dashboard development Configure, test, deploy and own system customizations Provide training and ongoing... 
    Work at office
    Remote work
    Work from home
    Monday to friday
    Flexible hours

    eSentire

    Ontario
    3 days ago
  •  ...Monitor accounts receivable and follow up on overdue accounts in consultation with Director of Finance Complete month-end close activities...  ...Conduct 6-8 project audits annually Complete audit testing, documentation, and member communications as required Supervise... 
    Contract work
    Remote work
    Ontario
    12 days ago
  •  ...Indigo Slate, our sister Studio, who specialize in marketing and consultancy. Together, we bring digital transformation programs to life for...  ...and evaluative research (e.g. one-to-one interviews, usability testing, surveys, etc), as well as synthesis of data and reporting.... 
    Contract work
    Internship
    Remote work

    Indigo Slate

    Ontario
    13 days ago
  • Penetration Tester / Red Team Consultant – Public Sector Location: Ottawa, Ontario About the Role We are seeking a Penetration Tester / Red Team Consultant...  ...Candidates must have experience conducting penetration testing and security assessments within Government, Crown... 

    NavitasPartners

    Rockland, ON
    3 days ago
  • Penetration Tester / Red Team Consultant – BFSI Location: Ottawa, OntarioAbout the Role We are seeking a Penetration Tester / Red Team Consultant to...  ...Wealth Management, or FinTech organizations. Experience testing applications handling sensitive financial data and... 

    NavitasPartners

    Rockland, ON
    3 days ago
  • $60k - $65k per year

     ...placement maximizing distribution objectives Maximize display and merchandising opportunities Maximize on-premise and consumer penetration of brands Know features and benefits of our brands as well as competitor brands Develop and maintain overall beverage alcohol... 
    Contract work
    Fixed term contract
    Work at office
    Weekend work
    Afternoon shift

    Beam Suntory, Inc

    Ontario
    5 days ago
  •  ...helps visionaries change the world. We are a global IT services and consulting company that brings together enterprise and start-up innovation....  ...JavaScript, Python, or Node.js. Familiarity with automated testing practices. We offer: Culture of Relentless Performance:... 
    Full time
    Internship
    Remote work
    Relocation

    Miratech

    Ontario
    27 days ago
  • $105.33k - $131.67k per year

     ...environmental scanning, best practice identification, community consultation and stakeholder analysis. 5. Demonstrated ability to...  ...required to provide immunization records, which may include TB testing prior to the start of employment to meet the requirements of Policy... 
    Permanent employment
    Full time
    Temporary work
    Work at office
    Local area
    Flexible hours

    City of Hamilton

    Ontario
    3 days ago
  • $75k - $105k per year

     ...building science or envelope design and consulting. P.Eng Designation (or eligibility for...  ...investigation tools and performance testing (e.g., thermography, air leakage testing...  ...junior staff and coordinating with external consultants where needed. Maintaining a client-... 
    Ontario
    more than 2 months ago
  •  ...cooperation, and enterprise resilience. Our offensive security consultants test the systems behind cutting-edge defensive technologies,...  ...your craft meets purpose. The Opportunity We're seeking a Penetration Tester to deliver hands-on offensive security engagements across... 
    Full time
    Shift work

    Malleum

    Ottawa, ON
    20 days ago
  •  ...management of acute and chronic conditions.  ~ Conduct patient consultations, physical examinations, and medical assessments.  ~ Develop...  ...and lifestyle counseling.  ~ Order and interpret diagnostic tests (e.g., bloodwork, imaging, ECGs).  ~ Collaborate with... 
    Full time
    Contract work
    Part time
    Locum

    Medicentres Canada Inc.

    Ontario
    more than 2 months ago
  • $30.8 - $45.48 per hour

     ...required Excellent English verbal and written communication skills CPR Certification Current immunization record including 2 step TB test To protect our patients, we require a current vulnerable sector check and a clear background check CarePartners In Your... 
    Hourly pay
    Full time
    Flexible hours

    CarePartners

    Ontario
    12 days ago
  •  ...as incident response runbooks, threat hunting queries, and penetration testing reports. Annotate, label, and validate data across cybersecurity...  ...in cybersecurity at an enterprise organization, MSSP, consultancy, or government/defense environment. ~ Background in... 
    Remote job
    Hourly pay
    Contract work
    Part time
    Summer work

    Mercor

    Toronto, ON
    5 days ago
  •  ...health status, deals with these personally or by referral to or in consultation with the other centre of community specialists, programs, or...  ...regulations), and interprets the results of screening and diagnostic tests. Keeps complete, accurate, legible and timely records of... 
    Permanent employment
    Full time
    Live out
    Work at office
    Flexible hours
    Ontario
    more than 2 months ago
  •  ...particularly hormone replacement therapy (HRT). You'll provide virtual consultations, assess patients, prescribe and manage HRT treatments, and...  ...therapies) Order and review bloodwork and diagnostic tests as needed Monitor patients on HRT for efficacy, side effects... 
    Remote job
    Long term contract
    Remplacement
    For contractors
    Casual work

    Cloudcure

    Ontario
    a month ago
  •  ...interested in blending traditional deep-dive testing and cutting-edge research into the...  ...: Direct and execute end-to-end penetration tests across internal and external networks,...  ...Remediation Oversight: In key accounts, act as a consultant to oversee the implementation of fixes,... 
    Permanent employment
    Toronto, ON
    more than 2 months ago
  • $60.52k - $91k per year

     ...offering customs brokerage, international trade consulting, compliance and freight forwarding...  ...coordination, and execution of User Acceptance Testing to ensure business requirements are met...  ...stakeholder alignment, effective test execution, and transparent reporting of testing... 
    Long term contract
    Full time
    Flexible hours

    Livingston International

    Toronto, ON
    15 hours ago
  •  ...them. We're looking for security-minded professionals to stress-test, probe, and harden cutting-edge AI models. If you enjoy finding...  ...of cybersecurity concepts — threat modeling, attack vectors, or penetration testing Hands-on experience with AI/ML systems, large language... 
    Hourly pay
    Ongoing contract
    Contract work
    Remote work
    Worldwide

    Alignerr

    Toronto, ON
    20 days ago
  • $105k - $135k per year

     ...and smarter mobility worldwide, connecting cities as we reduce carbon and replace cars.     Could you be the full-time Industrial Test Lead in Kingston, ON we’re looking for? Your future role Take on a new challenge and apply your testing and technical expertise... 
    Long term contract
    Full time
    Local area
    Worldwide
    Flexible hours

    Alstom

    Kingston, ON
    1 day ago
  • $4102 per week

     ...payment. Represent the unit on discussions and negotiation with customers, stakeholders and suppliers. Be a technical resource and consultant on transmission/distribution asset management matters. Promote acceptance to corporate proposals and generally work to ally fears,... 
    Contract work

    Hydro One Networks Inc

    Ontario
    15 hours ago
  • $22.92 - $34.46 per hour

     ...the constantly changing world of international trade. Livingston is a market leader offering customs brokerage, international trade consulting, compliance and freight forwarding services around the world. Livingston has over 3,000 employees at more than 90 key border crossings... 
    Long term contract
    Full time
    Home office
    Flexible hours

    Livingston International

    Ontario
    15 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Penetration Testing Consultant. Be the first to apply!