Penetration Testing Consultant
Core
Manual penetration testing of web, mobile, and API applications to protect critical financial infrastructure and ensure regulatory compliance.
Role type
Senior IC Penetration Testing Consultant
Builds
Secure web, mobile, and API applications for BMO Financial Group
Domain
Financial Services / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Manual penetration testing (Web/API), HTTP/S protocols, authentication/authorization mechanisms (OAuth, JWT, IDOR/BOLA), Burp Suite Professional, OWASP Top 10, business logic vulnerability exploitation, scripting languages, secure coding/architecture understanding
Preferred skills
OSCP, GMOB, GWAPT, OSWE certifications, NIST CSF, ISO 27001/27002, PCI DSS frameworks
Technologies
Burp Suite Professional, OWASP ZAP, IBM APP SCAN
Responsibilities
Execute deep manual penetration testing across the full lifecycle (scoping, testing, reporting, remediation), identify and exploit business logic vulnerabilities, liaise with stakeholders to understand business vision and risks, develop and champion information security best practices, document reproducible steps for technical findings
Seniority
Senior, hands-on IC