BMO Financial Group Jobs

bmo home

Job Information

BMO Financial Group Third Party Cyber Security Lead (Virtual- Remote) in Virtual, Iowa

At BMO, sustaining consumer confidence and trust by ensuring the security, privacy and integrity of our business information is a priority. To manage risk and respond to evolving regulatory requirements, we must carefully evaluate the cyber security controls that our service providers and suppliers have in place. As a leader on the Third Party Risk Cybersecurity team, you'll play a critical role in maturing the function. You'll collaborate with team members, senior management, and stakeholders across the company to drive process improvements and ensure consistency. You’ll be part of the Cybersecurity Third Party Risk team, composed of a large team of professionals that cover the entire third party life cycle. The team works closely with counterparts in Procurement, other risk functions, business leaders, and third parties. This is a fantastic opportunity to work with leaders across the bank, and work closely with cybersecurity colleagues to further champion and evangelize third party security. You will have a fundamental role in driving high-visibility improvements to the overall program.

KEY Accountabilities:

  • Maintaining awareness of the current and emerging threats in the cybersecurity supply chain. Identify threats, model risk, and lead efforts to respond.

  • Coach, mentor and review the assessments of junior third party assessors.

  • Lead and occasionally perform assessments of high risk third parties.

  • Work with software development teams to improve, replace, and/or further integrate GRC, monitoring, and other tooling in the TPRM stack.

  • Improve the assessment process by updating and strengthening how control assurance is obtained. Collaborate with other internal cybersecurity domains to ensure the third party assessment process aligns with the latest internal policies and standards.

  • Improve continuous monitoring practices and further integrate OSINT into the program.

  • Lead initiatives to evangelize third party security.

  • Build relationships and consensus with internal and external stakeholders. Work with stakeholders to understand problems and opportunities, and negotiate outcomes.

  • Keep abreast of new technology trends and associated risks, including leading security practices, frameworks, cloud services (AWS, GCP, Azure), and networking (zero trust, SASE). Lead in aligning the program to these trends.

  • Create professional presentations that are meaningful, concise and persuasive.

  • Review and challenge the work performed by other assessment team members, setting the “tone” for the quality and rigor of assessments. Should feel comfortable working with colleagues to provide feedback, and serving as a coach/mentor.

  • Lead wide-ranging high visibility projects to mature and improve the third party program. You will be directly involved in developing these projects from idea/conception to implementation. This role is expected to collaborate regularly with leadership to foster new ideas and problem solve.

  • This is a leadership role, and will be a member of leadership meetings. While this role is not a direct manager or a people- leader role, this role will have significant influence in the organization, including be a delegate/deputy for other managers on the team.

Other duties: Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Leads the development of information security strategy by understanding business processes, policies, information and information systems. Builds exceptional relationships with internal and external stakeholders. Ensures that requirements and solutions align to a real business need, are approved by all relevant stakeholders, and meets essential information security standards. Provides thought leadership, promotes new processes and methodologies and emerging technologies, with the flexibility to align to the unique requirements of the business/group and deliverables.

  • Provides strategic input into business decisions as a trusted advisor.

  • Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.

  • Acts as a subject matter expert on relevant regulations and policies.

  • Identifies and recommends opportunities to create/contribute to the tactical and strategic vision of the organization.

  • Supports the execution of strategic initiatives in collaboration with internal and external stakeholders.

  • Acts as the prime subject matter expert for internal/external stakeholders.

  • Breaks down strategic problems, and analyses data and information to provide insights and recommendations.

  • Presents data and information to all levels within IT and to business units.

  • Leads/oversees the management of vendor relationships and provides guidelines for execution; ensures that all agreements are met as per requirements.

  • Stays abreast of industry, information security and business trends through benchmarking and/or participation in professional associations.

  • Analyzes trends and stays current with industry events to proactively prevent information security issues.

  • Understands the strategy, plans, activities and needs of all stakeholders and translates those business needs into solutions and makes recommendations.

  • Provides advice, counsel and support on information security matters and recommends solutions to assigned business/group leaders on principles, frameworks, programs, approaches, trends, legislation and regulatory requirements including interpretation of policy and identification and management of risk.

  • Builds credibility and influences/negotiates effectively to drive business performance through development and delivery of information security solutions.

  • Tracks metrics and milestones, providing recommendations for resolution and escalating as appropriate when issues arise.

  • Facilitates discussions and follows a disciplined approach to plan, elicit, analyze, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.

  • Promotes process improvements and methodologies; keeps emerging information security issues and trends in mind and ensures standards are followed.

  • Creates professional presentations and deliver them in a meaningful concise way.

  • Assesses information security impact to a project’s benefits and risks when scope changes.

  • Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.

  • Gathers, examines and interprets data and information to extract meaningful insights, answer business questions and provide actionable recommendations.

  • Assists with continuous improvement activities and root cause analysis with the goal of strengthening information security capabilities.

  • Ensures consistent, high quality practices/work and the achievement of business results in alignment with business/group strategies and with productivity goals.

  • Operates at a group/enterprise-wide level and serves as a specialist resource to senior leaders and stakeholders.

  • Applies expertise and thinks creatively to address unique or ambiguous situations and to find solutions to problems that can be complex and non-routine.

  • Implements changes in response to shifting trends.

  • Broader work or accountabilities may be assigned as needed.


  • Min of 5 – 10 years of deep experience in 3rd Party Risk Assessment and governance, likely with substantial experience with using standards like NIST, ISO, and CIS to perform audits. Alternatively, a history of diverse experience across many information security roles could be a replacement for significant risk assessment experience.

  • Must have significant history in risk assessment and third party Cyber Risk management.

  • Mandatory hands-on experience with Cloud risk assessments ( MUST HAVE experience with AWS Admin Console or other Cloud services like Azure or Google Cloud)

  • Hands-on experience with information security or technology, for example, through work experiences or training. For example, prefer someone that has actually logged into the AWS Admin Console rather than just watched a video about.

  • Passion for information security. Should enjoy reading about it in their free time, and would be excited to bring ideas into the office about sec urity.

  • Very strong PowerPoint skills

  • Familiarity with all or most security domains through direct work experience and/or certifications from a well-recognized institutions (e.g. (ISC)2, ISACA, SANS, CISM, CISSP, GIAC, CEH).

  • Understanding of industry standards and frameworks from organizations like NIST, ISO and CIS (e.g. Cyber Security Framework (CSF), 800-53, ISO27001/27002, CIS18).

  • Typically 7+ years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experience.

  • Multiple information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).Possesses an expert level of knowledge of information security processes, procedures and controls.

  • Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002 - In-depth/Expert.

  • Knowledge of business analysis, project delivery practices and standards across the project lifecycle - In-depth/Expert.

  • Demonstrates in depth knowledge of information security concepts, methodology, processes, procedures and controls.

  • Understanding and problem solving ability of information security issues across the bank - In-depth/Expert.

  • Understanding of information security risk and regulatory requirements - In-depth/Expert.

  • Knowledge of the technical/business environment and the corporate processes and procedures - In-depth/Expert.

  • Seasoned professional with a combination of education, experience and industry knowledge.

  • Verbal & written communication skills - In-depth / Expert.

  • Analytical and problem solving skills - In-depth / Expert.

  • Influence skills - In-depth / Expert.

  • Collaboration & team skills; with a focus on cross-group collaboration - In-depth / Expert.

  • Able to manage ambiguity.

  • Data driven decision making - In-depth / Expert.


We’re here to help

At BMO Harris Bank we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.

As a member of the BMO Harris Bank team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset.

To find out more visit us at

BMO Harris Bank is committed to an inclusive, equitable and accessible workplace. By learning from each other’s differences, we gain strength through our people and our perspectives. BMO Harris Bank N.A. is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. Accommodations are available on request for candidates taking part in all aspects of the selection process. To request accommodation, please contact your recruiter.

Note to Recruiters: BMO Harris Bank does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO Harris Bank, directly or indirectly, will be considered BMO Harris Bank property. BMO Harris Bank will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.