Penetration Testing Consultant

BMOVIRTUAL43 - HomeRes - TX, TX
$88,800 - $165,600Remote

About The Position

Join a team where your work goes beyond checklists protecting critical financial applications with real business and regulatory impact. This role focuses on deep, manual penetration testing (web, mobile, APIs) rather than automated, scanner-driven assessments. You will work in complex, enterprise-scale environments that expose you to advanced architectures and evolving threats. The role involves end-to-end ownership across the full lifecycle: scoping → testing → reporting → remediation, with visibility and influence throughout. You will use advanced testing tools to enhance testing depth and efficiency, experiencing fewer, higher-quality engagements versus consulting-style, high-volume work.

Requirements

  • Min of 3+ years experience with Manual Penetration Testing experience in Web or API.
  • Strong exposure for testing Web applications in the following areas: A solid grasp of HTTP/S protocols, headers, cookies, sessions, and CORS behavior within your web testing experience.
  • Experience testing authentication and authorization mechanisms (OAuth, JWT, session flaws, IDOR/BOLA).
  • Strong proficiency with Burp Suite Professional , OWASP ZAP, IBM’s APP SCAN, (proxying, repeater, intruder, extensions).
  • Deep practical knowledge of OWASP Top 10 (Web + API) and common vulnerabilities.
  • Ability to identify and exploit business logic vulnerabilities and multi-step attack paths.
  • Secure coding and architecture understanding.
  • Proficiency in at least one scripting language.
  • Proficiency in documenting reproducible steps for technical accurate findings.
  • Typically between 4 - 7 years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experience.
  • Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002, Payment Card Industry (PCI) Data Security Standard (DSS), etc. - In-depth.
  • Experience in information security concepts and methodology.
  • Knowledge of business analysis, project delivery practices and standards across the project lifecycle - In-depth.
  • Knowledge of information security processes, procedures and controls - In-depth.
  • Understanding of and problem solving ability for information security issues within their business group - Working.
  • Understanding of information security risk and regulatory requirements - Working.
  • Deep knowledge and technical proficiency gained through extensive education and business experience.
  • Verbal & written communication skills - In-depth.
  • Collaboration & team skills - In-depth.
  • Analytical and problem solving skills - In-depth.
  • Influence skills - In-depth.
  • Data driven decision making - In-depth.

Nice To Haves

  • Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. OSCP, GMOB, GWAPT, OSWE).
  • Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).

Responsibilities

  • Provides information security consulting services for BMO overall and businesses/groups.
  • Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs.
  • Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.
  • Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.
  • Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.
  • Leads the development of information security strategy by understanding business processes, policies, information and information systems.
  • Builds exceptional relationships with internal and external stakeholders.
  • Ensures that requirements and solutions align to a real business need, are approved by all relevant stakeholders, and meets essential information security standards.
  • Provides thought leadership, promotes new processes and methodologies and emerging technologies, with the flexibility to align to the unique requirements of the business/group and deliverables.
  • Acts as a trusted advisor to assigned business/group.
  • Assists in the development of strategic plans.
  • Supports the execution of strategic initiatives in collaboration with internal and external stakeholders.
  • Helps determine business priorities and best sequence for execution of business/group strategy.
  • Breaks down strategic problems, and analyses data and information to provide insights and recommendations.
  • Acts as the day to day contact for vendors; supports the implementation, maintenance, and sustainment of vendor solutions.
  • Understands the strategy, plans, activities and needs of all stakeholders and translates those business needs into solutions and makes recommendations.
  • Provides advice, counsel and support on information security matters and recommends solutions to assigned business/group leaders on principles, frameworks, programs, approaches, trends, legislation and regulatory requirements including interpretation of policy and identification and management of risk.
  • Builds credibility and influences/negotiates effectively to drive business performance through development and delivery of information security solutions.
  • Tracks metrics and milestones, providing recommendations for resolution and escalating as appropriate when issues arise.
  • Promotes process improvements and methodologies; keeps emerging information security issues and trends in mind and ensures standards are followed.
  • Creates professional presentations and deliver them in a meaningful concise way.
  • Assesses information security impact to a project’s benefits and risks when scope changes.
  • Gathers, examines and interprets data and information to extract meaningful insights, answer business questions and provide actionable recommendations.
  • Assists with continuous improvement activities and root cause analysis with the goal of strengthening information security capabilities.
  • Ensures consistent, high quality practices/work and the achievement of business results in alignment with business/group strategies and with productivity goals.
  • Provides specialized consulting, analytical and technical support.
  • Exercises judgment to identify, diagnose, and solve problems within given rules.
  • Works independently and regularly handles non-routine situations.
  • Broader work or accountabilities may be assigned as needed.
  • Take measured risks while protecting the bank by applying our Risk Management Framework in the execution of your role, in line with our Risk Culture and within our approved Risk Appetite, making sound and risk informed decisions that align to business strategy, protect assets, and adhere to applicable policy documents (Frameworks, Policies, Standards, Procedures and Supporting documents), laws and regulations.

Benefits

  • health insurance
  • tuition reimbursement
  • accident and life insurance
  • retirement savings plans
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service