BMO Financial Group Jobs

Mobile bmo Logo

Job Information

BMO Financial Group Security Testing Consultant (Penetration Testing) in Chicago, Illinois


200 W Adams Street

Job Family Group:


Security Testing Consultant

Summary of Responsibilities:

The Security Testing Consultant reports to the Sr. Manager of Penetration Testing and leads the security testing activities for BMO based applications and technologies. The role will be responsible for the execution and coordination of ethical hacking to identify weaknesses and areas for improvement. The Security Testing Consultant executes on a scheduled project plan that is aligned with corporate business objectives and regulatory requirements.

Essential Functions

  • Team Leadership – Executes security testing activities aimed at exploiting vulnerabilities in order to enhance the security of BMO applications and technologies. Works with management and peers to foster the development of less experienced Security Testing Consultants.

  • Subject Matter Expertise - Provides technical leadership to business areas as a Security Testing subject matter expert. Leads efforts on the execution of security testing operations to include pre-engagement (scoping), engagement (testing) and post-engagement activities (reporting).

  • Secure Testing - Provides team leadership to assist in delivery of security testing projects according to a structured process, to include writing test reports. This may include oversight and/or execution of the configuration and deployment of security testing software and application of results to security analysis.

  • Information Security Risk Management - Works with leadership to mature security testing team capabilities including reporting and remediation guidance in alignment with local and global regulatory requirements. Identifies security gaps and deficiencies by conducting risk assessments; able to recommend corrective action of identified vulnerabilities and weaknesses. Leads the execution of planning, testing, tracking, and advises on necessary risk acceptance for identified security risks.

  • Secure Application Development - Leads the execution of highly technical/analytical security assessments of custom web applications, mid-tier application services, backend mainframe applications and databases, including manual, custom and industry known attack methods using a risk-based intelligence-led methodology. Identifies potential misuse scenarios. Advises on secure development practices.

Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Leads the development of information security strategy by understanding business processes, policies, information and information systems. Builds exceptional relationships with internal and external stakeholders. Ensures that requirements and solutions align to a real business need, are approved by all relevant stakeholders, and meets essential information security standards. Provides thought leadership, promotes new processes and methodologies and emerging technologies, with the flexibility to align to the unique requirements of the business/group and deliverables.

  • Acts as a trusted advisor to assigned business/group.

  • Assists in the development of strategic plans.

  • Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.

  • Supports the execution of strategic initiatives in collaboration with internal and external stakeholders.

  • Helps determine business priorities and best sequence for execution of business/group strategy.

  • Breaks down strategic problems, and analyses data and information to provide insights and recommendations.

  • Acts as the day to day contact for vendors; supports the implementation, maintenance, and sustainment of vendor solutions.

  • Understands the strategy, plans, activities and needs of all stakeholders and translates those business needs into solutions and makes recommendations.

  • Provides advice, counsel and support on information security matters and recommends solutions to assigned business/group leaders on principles, frameworks, programs, approaches, trends, legislation and regulatory requirements including interpretation of policy and identification and management of risk.

  • Builds credibility and influences/negotiates effectively to drive business performance through development and delivery of information security solutions.

  • Tracks metrics and milestones, providing recommendations for resolution and escalating as appropriate when issues arise.

  • Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.

  • Promotes process improvements and methodologies; keeps emerging information security issues and trends in mind and ensures standards are followed.

  • Creates professional presentations and deliver them in a meaningful concise way.

  • Assesses information security impact to a project’s benefits and risks when scope changes.

  • Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.

  • Gathers, examines and interprets data and information to extract meaningful insights, answer business questions and provide actionable recommendations.

  • Assists with continuous improvement activities and root cause analysis with the goal of strengthening information security capabilities.

  • Ensures consistent, high quality practices/work and the achievement of business results in alignment with business/group strategies and with productivity goals.

  • Focus is primarily on business/group within BMO; may have broader, enterprise-wide focus.

  • Provides specialized consulting, analytical and technical support.

  • Exercises judgment to identify, diagnose, and solve problems within given rules.

  • Works independently and regularly handles non-routine situations.

  • Broader work or accountabilities may be assigned as needed.


  • Typically between 4 - 7 years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experience.

  • Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).

  • Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002, Payment Card Industry (PCI) Data Security Standard (DSS), etc. - In-depth.

  • Experience in information security concepts and methodology.

  • Knowledge of business analysis, project delivery practices and standards across the project lifecycle - In-depth.

  • Knowledge of information security processes, procedures and controls - In-depth.

  • Understanding of and problem solving ability for information security issues within their business group - Working.

  • Understanding of information security risk and regulatory requirements - Working.

  • Deep knowledge and technical proficiency gained through extensive education and business experience.

  • Verbal & written communication skills - In-depth.

  • Collaboration & team skills - In-depth.

  • Analytical and problem solving skills - In-depth.

  • Influence skills - In-depth.

  • Data driven decision making - In-depth.

We’re here to help

At BMO Harris Bank we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.

As a member of the BMO Harris Bank team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset.

To find out more visit us at

BMO Harris Bank is committed to an inclusive, equitable and accessible workplace. By learning from each other’s differences, we gain strength through our people and our perspectives. BMO Harris Bank N.A. is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. Accommodations are available on request for candidates taking part in all aspects of the selection process. To request accommodation, please contact your recruiter.

BMO Financial Group Serving customers for 200 years and counting, BMO is a highly diversified financial services provider – the 8th largest bank, by assets, in North America. With total assets of $728 billion as of October 31, 2018, and a team of diverse and highly engaged employees, BMO provides a broad range of personal and commercial banking, wealth management and investment banking products and services to more than 12 million customers and conducts business through three operating groups: Personal and Commercial Banking, BMO Wealth Management and BMO Capital Markets.We serve Canadian clients through BMO Bank of Montreal®, our personal and commercial banking business, BMO Nesbitt Burns®*, one of Canada's leading wealth management firms, and BMO Capital Markets™, our North American investment and corporate banking division.In the United States, clients are served through BMO Harris Bank, a major U.S. Midwest personal and commercial bank, and BMO Private Bank, with wealth management offices across the United States, as well as BMO Capital Markets™, our North American investment and corporate banking division.We help our customers make money make sense by delivering the broadest range of financial services through a single point of contact. Our financial service professionals provide access to any services our customers require across the entire enterprise.