Penetration Testing Consultant at BMO conducting extensive manual security assessments for critical financial applications. Collaborating with stakeholders to enhance security strategies and practices.
Responsibilities
Provides information security consulting services for BMO overall and businesses/groups
Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs
Understands and can explain to others the core processes, risks and mitigation techniques for designated areas
Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations
Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks
Requirements
Typically between 4 - 7 years of relevant experience
post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experience
Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS)
Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002, Payment Card Industry (PCI) Data Security Standard (DSS), etc. - In-depth
Experience in information security concepts and methodology
Knowledge of business analysis, project delivery practices and standards across the project lifecycle - In-depth
Knowledge of information security processes, procedures and controls - In-depth
Understanding of and problem solving ability for information security issues within their business group - Working
Understanding of information security risk and regulatory requirements - Working
Security Analyst I supporting security operations and security engineering initiatives at Varicent. Collaborating across teams to strengthen security posture through operational excellence and risk - based decision - making.
Expert in application cybersecurity analyzing web components and supporting secure development practices within a dynamic team. Collaborate on cloud application security based in Quebec, Canada.
Information Security Consultant leading Risk Control Self Assessments and risk governance at Manulife. Collaborating on technology, data, and operational risk management while ensuring strong governance.
Software Specialist at Xona developing secure software for the Pulsar ecosystem. Collaborating with teams to integrate security features in partner hardware.
Cybersecurity Intern at FloSports assisting in identity, cloud, and endpoint security. Work in a hybrid setup at the Waterloo office focusing on real - world cybersecurity practices.