Easter Seals Jobs

Job Information

BMO Financial Group Senior Red Team Operator in Virtual, New Hampshire

This role is highly involved in threat actor simulation exercises who works on a Red Team and is responsible for the execution and coordination of ethical hacking and adversary emulation campaigns to identify weaknesses in security controls, platforms and infrastructure hardening, application logic and physical security .

If you are passionate about offensive security, thrive in challenging environments, and want to make a real impact in a highly regulated, mission-critical industry, this is the opportunity for you!

Why join us ?

Be a Game Changer: Work at the forefront of cybersecurity, conducting cutting-edge red team operations that simulate real-world adversaries targeting our critical financial systems.

Innovate and Evolve : Leverage offensive security tools and tactics to outsmart emerging threats, collaborating with some of the best minds in cybersecurity.

Endless Growt h: Thrive in a culture of continuous learning, and career development opportunities.

Impact That Matters : Your work will directly contribute to strengthening the resilience of a global financial leader, protecting millions of customers and critical assets.

Collaborative Excellence : Join a highly skilled team that values innovation, creativity, and knowledge-sharing in tackling complex security challenges

This role is 100% remote

Main responsibilities:

Adversarial Operations Technical Execution – Plans, implements, and leads technical execution of Red Team operation phases. Leads planned Red Team activities with a high degree of trust and integrity, adhering strongly to rules of engagement and internal standard operating procedures. Familiar with modern adversarial tradecraft supported by threat intelligence and able to advise during the planning and execution of Red Team operations of tactics, techniques and procedures utilized by modern adversaries.

Team Leadership – Leads the execution of activities by specialized staff in Red Team campaigns aimed at identifying opportunities to enhance BMO security controls including malicious event detection, protection and response. Works with management and peers to foster the development of less experienced Red Team members

Secure Testing - Performs adversarial and TTP simulation testing according to a structured process, to include but not limited to; writing test plans, test cases and test reports. This may include oversight and/or execution of the configuration and deployment of security testing software and application of results to security analysis

Key Desired Skills:

• Min of 5+ years Red Team Operator (Offensive Security) experience and working in previous technical roles (penetration testing, manual application/web assessments, threat hunting, etc.)

• Min of 3+ years in threat actor simulation experience in a Red Team role. ( this is not referring to threat actor simulation in a Pen Testing role; its referring to threat actor simulation in a Red team role)

• Strong experience ( 5+ years) with building a MITRE ATTACK framework, and building a threat simulation plan using the Mitre Attack framework. Strong understanding of end-to-end attacks and multi-faceted exploits.

• Strong written and verbal skills with the ability to present complex technical observations to a non-technical audience.

• Demonstrates familiarity with adversarial tradecraft, threat intelligence ingestion and difference in value of penetration testing and red team assessments.

• Demonstrates leadership competency working with geographically separated teams of specialized cyber security professionals

• Experience with Threat intelligence activities and understanding threat actors, and understanding Threat Actor simulations

• Experience in Application security desired

• Experience in the military with signal intelligence (sigint) is strongly desired

If you are passionate about Red Teaming, thrive in challenging environments, and want to make a real impact in a highly regulated, mission-critical industry, this is the opportunity for you!

Additional Information:

Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Leads the development of information security strategy by understanding business processes, policies, information and information systems. Builds exceptional relationships with internal and external stakeholders. Ensures that requirements and solutions align to a real business need, are approved by all relevant stakeholders, and meets essential information security standards. Provides thought leadership, promotes new processes and methodologies and emerging technologies, with the flexibility to align to the unique requirements of the business/group and deliverables.

  • Provides strategic input into business decisions as a trusted advisor.

  • Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.

  • Acts as a subject matter expert on relevant regulations and policies.

  • Identifies and recommends opportunities to create/contribute to the tactical and strategic vision of the organization.

  • Supports the execution of strategic initiatives in collaboration with internal and external stakeholders.

  • Acts as the prime subject matter expert for internal/external stakeholders.

  • Breaks down strategic problems, and analyses data and information to provide insights and recommendations.

  • Presents data and information to all levels within IT and to business units.

  • Leads/oversees the management of vendor relationships and provides guidelines for execution; ensures that all agreements are met as per requirements.

  • Stays abreast of industry, information security and business trends through benchmarking and/or participation in professional associations.

  • Analyzes trends and stays current with industry events to proactively prevent information security issues.

  • Understands the strategy, plans, activities and needs of all stakeholders and translates those business needs into solutions and makes recommendations.

  • Provides advice, counsel and support on information security matters and recommends solutions to assigned business/group leaders on principles, frameworks, programs, approaches, trends, legislation and regulatory requirements including interpretation of policy and identification and management of risk.

  • Builds credibility and influences/negotiates effectively to drive business performance through development and delivery of information security solutions.

  • Tracks metrics and milestones, providing recommendations for resolution and escalating as appropriate when issues arise.

  • Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.

  • Promotes process improvements and methodologies; keeps emerging information security issues and trends in mind and ensures standards are followed.

  • Creates professional presentations and deliver them in a meaningful concise way.

  • Assesses information security impact to a project’s benefits and risks when scope changes.

  • Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.

  • Gathers, examines and interprets data and information to extract meaningful insights, answer business questions and provide actionable recommendations.

  • Assists with continuous improvement activities and root cause analysis with the goal of strengthening information security capabilities.

  • Ensures consistent, high quality practices/work and the achievement of business results in alignment with business/group strategies and with productivity goals.

  • Operates at a group/enterprise-wide level and serves as a specialist resource to senior leaders and stakeholders.

  • Applies expertise and thinks creatively to address unique or ambiguous situations and to find solutions to problems that can be complex and non-routine.

  • Implements changes in response to shifting trends.

  • Broader work or accountabilities may be assigned as needed. Qualifications:

  • Typically 7+ years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experience.

  • Multiple information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).Possesses an expert level of knowledge of information security processes, procedures and controls.

  • Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002 - In-depth/Expert.

  • Knowledge of business analysis, project delivery practices and standards across the project lifecycle - In-depth/Expert.

  • Demonstrates in depth knowledge of information security concepts, methodology, processes, procedures and controls.

  • Understanding and problem solving ability of information security issues across the bank - In-depth/Expert.

  • Understanding of information security risk and regulatory requirements - In-depth/Expert.

  • Knowledge of the technical/business environment and the corporate processes and procedures - In-depth/Expert.

  • Seasoned professional with a combination of education, experience and industry knowledge.

  • Verbal & written communication skills - In-depth / Expert.

  • Analytical and problem solving skills - In-depth / Expert.

  • Influence skills - In-depth / Expert.

  • Collaboration & team skills; with a focus on cross-group collaboration - In-depth / Expert.

  • Able to manage ambiguity.

  • Data driven decision making - In-depth / Expert.

Salary:

$120,000.00 - $222,600.00

Pay Type:

Salaried

The above represents BMO Financial Group’s pay range and type.

Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group’s expected target for the first year in this position.

BMO Financial Group’s total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit: https://jobs.bmo.com/global/en/Total-Rewards

About Us

At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.

As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset.

To find out more visit us at https://jobs.bmo.com/us/en

BMO is proud to be an equal employment opportunity employer. We evaluate applicants without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or any other legally protected characteristics. We also consider applicants with criminal histories, consistent with applicable federal, state and local law.

BMO is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please send an e-mail to BMOCareers.Support@bmo.com and let us know the nature of your request and your contact information.

Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.

DirectEmployers