BMO

Cyber Security Consultant

Toronto, ON, CAN Full time

Application Deadline:

01/01/2026

Address:

100 King Street West

Job Family Group:

Technology

The Financial Crimes Unit (FCU) brings together our Cybersecurity, Fraud, Physical Security and Resilience Planning capabilities to address the ever-growing and increasingly complex global security environment. It is a highly collaborative effort that greatly enhances BMO’s ability

to rapidly prevent, detect, respond to, and recover from all security & crisis threats.

As an Application Security Threat Modeling Consultant, you will be part of Application Security Risk Assessments team within Cybersecurity. The Application Security Risk Assessment team performs assessments of applications and technology designs to identify threats and potential risks early in BMO Financial Group’s SDLC and risk management process. You will have an opportunity to take collaborative approach in maturing application security threat modeling practices, identify relevant security threats to business technology, help colleagues continuously improve security practices, secure and enable business objectives.

This is a HYBRID role.

  • Perform high quality application security assessments producing easy to understand threat modeling artifacts, communicate (written and verbal) potential risks effectively to stakeholders and follow through in tracking assessments and remediation activities.
  • Be integral in continuously maturing the threat modeling practices and application security risk assessment program.
  • Maintain an understanding of available security requirements, design patterns, and identify gaps that require improvement opportunities.
  • Keep abreast of new technology trends and associated risks in application development practices, frameworks, cloud services, modern data store platforms etc. and ability apply this knowledge and skills during threat modeling exercises.
  • Broader work or accountabilities may be assigned as needed.

Skills and experience:

  • Proficient level working knowledge of Threat Modeling methodologies (e.g. Attack Trees, MSTM/STRIDE, PASTA) or performing Architecture Risk Analysis.
  • 3+ years of relevant experience in Cybersecurity
  • Strong ability to decompose applications and system designs in hybrid cloud architectures to identify potential threats.
  • Proficient level working experience in application security and security risk management practices.
  • Working experience in Agile methodologies.
  • Knowledge of DevOps practices and ability to champion security first, DevSecOps culture and practices.
  • Prior experience in software development (e.g., Java, JS, Python) is preferred.
  • Advanced analytical skills along with proficient communication and negotiations skills, both verbal and written.
  • Is empathetic and loves to solve problems and always maintains high integrity.
  • Post-secondary degree in Computer Science, Engineering, or Information Systems or a related field of study or an equivalent combination of education
  • Industry certifications such as CISM, CISSP, GIAC, or CEH

Salary:

$82,800.00 - $154,800.00

Pay Type:

Salaried

The above represents BMO Financial Group’s pay range and type.

Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group’s expected target for the first year in this position.

BMO Financial Group’s total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit: https://jobs.bmo.com/global/en/Total-Rewards

About Us

At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.

As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset.

To find out more visit us at https://jobs.bmo.com/ca/en.

BMO is committed to an inclusive, equitable and accessible workplace. By learning from each other’s differences, we gain strength through our people and our perspectives. Accommodations are available on request for candidates taking part in all aspects of the selection process. To request accommodation, please contact your recruiter.

Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.