BMO U.S.
Join to apply for the
Senior Red Team Operator
role at
BMO U.S.
The Senior Red Team Operator reports to the Sr. Manager of Red Team and provides execution and collaboration to a team of highly skilled offensive security engineers and is a subject matter expert to BMO businesses and functions on threat actor simulation exercises. This role will be responsible for the planning and execution of ethical hacking and adversary emulation campaigns to identify weaknesses in security controls, platforms and infrastructure hardening, application logic and physical security. The Senior Red Team Operator executes on strategic offensive security direction that is aligned with corporate business objectives, regulatory requirements and relevant attack scenarios.
Key Functions
Adversarial Operations Technical Execution – Plans, implements, and leads technical execution of Red Team operation phases. Leads planned Red Team activities with a high degree of trust and integrity, adhering strongly to rules of engagement and internal standard operating procedures. Familiar with modern adversarial tradecraft supported by threat intelligence and able to advise during the planning and execution of Red Team operations of tactics, techniques and procedures utilized by modern adversaries.
Team Leadership – Leads the execution of activities by specialized staff in Red Team campaigns aimed at identifying opportunities to enhance BMO security controls including malicious event detection, protection and response. Works with management and peers to foster the development of less experienced Red Team members
Subject Matter Expertise - Provides technical leadership as a Red and Purple Team subject matter expert to business areas, project teams and information security practitioners to apply and execute appropriate use of technology solutions. Leads efforts on the execution of Red Team operations to include pre-engagement, engagement and post-engagement activities. Advises on the efficacy of current processes for Red Team activities and challenges with regard to security standards and the impact of the technology.
Secure Testing - Performs adversarial and TTP simulation testing according to a structured process, to include but not limited to; writing test plans, test cases and test reports. This may include oversight and/or execution of the configuration and deployment of security testing software and application of results to security analysis.
Information Security Risk Management – Works with leadership to mature red team, reporting and remediation guidance in alignment with local and global regulatory requirements and internal governing enterprise risk management policies. Identifies security gaps and deficiencies by conducting risk assessments; able to recommend corrective action of identified vulnerabilities and weaknesses. Executes the planning, testing, tracking, and advisory of necessary risk acceptance for identified security risks.
Key Skill Requirements
5+ years Offensive Security experience working in a technical role (penetration testing, manual application/web assessments, threat hunting, etc.)
3+ years Red Team (threat actor simulation) experience working in a technical role
Strong written and verbal skills with the ability to present complex technical observations to a non-technical audience.
Demonstrates familiarity with adversarial tradecraft, threat intelligence ingestion and difference in value of penetration testing and red team assessments.
Demonstrates leadership competency working with geographically separated teams of specialized cyber security professionals.
Qualifications
Zero Point Security Certified Red Team Operator (CRTO 2025 Edition)
Offensive Security Experienced Penetration Tester (OSEP)
Typically 7+ years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or an equivalent combination of education and experience.
Multiple information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).
In-depth knowledge of NIST CSF, ISO 27001/27002, information security concepts and risk management.
Strong verbal and written communication, analytical and problem solving skills, and ability to influence with cross-group collaboration.
Able to manage ambiguity and make data-driven decisions.
Technical Knowledge
Strong working knowledge of Windows and Linux platforms, applications and TCP/IP network security technologies
Knowledge of multifaceted exploits, chained attacks, and attack emulations
Understanding of vulnerability exploitation and security control weaknesses
Application penetration testing knowledge
Customer payload development knowledge
Work Environment Characteristics
Self-motivated and results-oriented with the ability to prioritize conflicting demands
Strong organizational skills to balance and manage multiple projects
Collaborative with internal and external stakeholders
Salary:
$122,400.00 - $228,000.00
Pay Type:
Salaried
The above represents BMO Financial Group’s pay range and type. Salaries will vary based on location, skills, experience, education, and qualifications for the role. BMO offers health insurance, retirement plans, and other benefits. For details, visit the Total Rewards page.
About Us At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. We strive to help you make an impact from day one and support your growth with training, coaching, and opportunities.
Equal Employment Opportunity BMO is proud to be an equal employment opportunity employer. We evaluate applicants without regard to race, religion, color, national origin, sex, sexual orientation, gender identity, age, disability status, or any other legally protected characteristics. We also consider applicants with criminal histories, consistent with applicable laws. Reasonable accommodations are available on request.
Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. A recruiting agency must have a valid agreement to submit resumes.
#J-18808-Ljbffr
Senior Red Team Operator
role at
BMO U.S.
The Senior Red Team Operator reports to the Sr. Manager of Red Team and provides execution and collaboration to a team of highly skilled offensive security engineers and is a subject matter expert to BMO businesses and functions on threat actor simulation exercises. This role will be responsible for the planning and execution of ethical hacking and adversary emulation campaigns to identify weaknesses in security controls, platforms and infrastructure hardening, application logic and physical security. The Senior Red Team Operator executes on strategic offensive security direction that is aligned with corporate business objectives, regulatory requirements and relevant attack scenarios.
Key Functions
Adversarial Operations Technical Execution – Plans, implements, and leads technical execution of Red Team operation phases. Leads planned Red Team activities with a high degree of trust and integrity, adhering strongly to rules of engagement and internal standard operating procedures. Familiar with modern adversarial tradecraft supported by threat intelligence and able to advise during the planning and execution of Red Team operations of tactics, techniques and procedures utilized by modern adversaries.
Team Leadership – Leads the execution of activities by specialized staff in Red Team campaigns aimed at identifying opportunities to enhance BMO security controls including malicious event detection, protection and response. Works with management and peers to foster the development of less experienced Red Team members
Subject Matter Expertise - Provides technical leadership as a Red and Purple Team subject matter expert to business areas, project teams and information security practitioners to apply and execute appropriate use of technology solutions. Leads efforts on the execution of Red Team operations to include pre-engagement, engagement and post-engagement activities. Advises on the efficacy of current processes for Red Team activities and challenges with regard to security standards and the impact of the technology.
Secure Testing - Performs adversarial and TTP simulation testing according to a structured process, to include but not limited to; writing test plans, test cases and test reports. This may include oversight and/or execution of the configuration and deployment of security testing software and application of results to security analysis.
Information Security Risk Management – Works with leadership to mature red team, reporting and remediation guidance in alignment with local and global regulatory requirements and internal governing enterprise risk management policies. Identifies security gaps and deficiencies by conducting risk assessments; able to recommend corrective action of identified vulnerabilities and weaknesses. Executes the planning, testing, tracking, and advisory of necessary risk acceptance for identified security risks.
Key Skill Requirements
5+ years Offensive Security experience working in a technical role (penetration testing, manual application/web assessments, threat hunting, etc.)
3+ years Red Team (threat actor simulation) experience working in a technical role
Strong written and verbal skills with the ability to present complex technical observations to a non-technical audience.
Demonstrates familiarity with adversarial tradecraft, threat intelligence ingestion and difference in value of penetration testing and red team assessments.
Demonstrates leadership competency working with geographically separated teams of specialized cyber security professionals.
Qualifications
Zero Point Security Certified Red Team Operator (CRTO 2025 Edition)
Offensive Security Experienced Penetration Tester (OSEP)
Typically 7+ years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or an equivalent combination of education and experience.
Multiple information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).
In-depth knowledge of NIST CSF, ISO 27001/27002, information security concepts and risk management.
Strong verbal and written communication, analytical and problem solving skills, and ability to influence with cross-group collaboration.
Able to manage ambiguity and make data-driven decisions.
Technical Knowledge
Strong working knowledge of Windows and Linux platforms, applications and TCP/IP network security technologies
Knowledge of multifaceted exploits, chained attacks, and attack emulations
Understanding of vulnerability exploitation and security control weaknesses
Application penetration testing knowledge
Customer payload development knowledge
Work Environment Characteristics
Self-motivated and results-oriented with the ability to prioritize conflicting demands
Strong organizational skills to balance and manage multiple projects
Collaborative with internal and external stakeholders
Salary:
$122,400.00 - $228,000.00
Pay Type:
Salaried
The above represents BMO Financial Group’s pay range and type. Salaries will vary based on location, skills, experience, education, and qualifications for the role. BMO offers health insurance, retirement plans, and other benefits. For details, visit the Total Rewards page.
About Us At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. We strive to help you make an impact from day one and support your growth with training, coaching, and opportunities.
Equal Employment Opportunity BMO is proud to be an equal employment opportunity employer. We evaluate applicants without regard to race, religion, color, national origin, sex, sexual orientation, gender identity, age, disability status, or any other legally protected characteristics. We also consider applicants with criminal histories, consistent with applicable laws. Reasonable accommodations are available on request.
Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. A recruiting agency must have a valid agreement to submit resumes.
#J-18808-Ljbffr