Skip to Main Content

Job Title


Senior Red Team Operator


Company : BMO Financial Group


Location : Edmonton, Alberta


Created : 2025-09-06


Job Type : Full Time


Job Description

Date limite pour prsenter sa candidature : 10/30/2025 Adresse : VIRTUAL59 - REMOTE/TELETRAVAIL - ON - BMO Groupe de famille d''''emploi : Technologie The Senior Red Team operator reports to the Sr. Manager of Red Team and provides execution and collaboration to a team of highly skilled offensive security engineers and is a subject matter expert to BMO businesses and functions on threat actor simulation exercises. This role will be responsible for the planning and execution of ethical hacking and adversary emulation campaigns to identify weaknesses in security controls, platforms and infrastructure hardening, application logic and physical security. The Senior Red Team Operator executes on strategic offensive security direction that is aligned with corporate business objectives, regulatory requirements and relevant attack scenarios. KEY Functions : Adversarial Operations Technical Execution - Plans, implements, and leads technical execution of Red Team operation phases. Leads planned Red Team activities with a high degree of trust and integrity, adhering strongly to rules of engagement and internal standard operating procedures. Familiar with modern adversarial tradecraft supported by threat intelligence and able to advise during the planning and execution of Red Team operations of tactics, techniques and procedures utilized by modern adversaries. Team Leadership - Leads the execution of activities by specialized staff in Red Team campaigns aimed at identifying opportunities to enhance BMO security controls including malicious event detection, protection and response. Works with management and peers to foster the development of less experienced Red Team members Subject Matter Expertise - Provides technical leadership as a Red and Purple Team subject matter expert to business areas, project teams and information security practitioners to apply and execute appropriate use of technology solutions. Leads efforts on the execution of Red Team operations to include pre-engagement, engagement and post-engagement activities. Advises on the efficacy of current processes for Red Team activities and challenges with regard to security standards and the impact of the technology. Secure Testing - Performs adversarial and TTP simulation testing according to a structured process, to include but not limited to; writing test plans, test cases and test reports. This may include oversight and/or execution of the configuration and deployment of security testing software and application of results to security analysis. Information Security Risk Management - Works with leadership to mature red team, reporting and remediation guidance in alignment with local and global regulatory requirements and internal governing enterprise risk management policies. Identifies security gaps and deficiencies by conducting risk assessments; able to recommend corrective action of identified vulnerabilities and weaknesses. Executes the planning, testing, tracking, and advisory of necessary risk acceptance for identified security risks. KEY Skill Requirements: 5+ years Offensive Security experience working in a technical role (penetration testing, manual application/web assessments, threat hunting, etc.) 3+ years Red Team (threat actor simulation) experience working in a technical role Strong written and verbal skills with the ability to present complex technical observations to a non-technical audience. Demonstrates familiarity with adversarial tradecraft, threat intelligence ingestion and difference in value of penetration testing and red team assessments. Demonstrates leadership competency working with geographically separated teams of specialized cyber security professionals. Preferred Qualifications: Zero Point Security Certified Red Team Operator (CRTO 2025 Edition) Offensive Security Experienced Penetration Tester (OSEP) Technical Knowledge Strong working knowledge of: Windows and Linux based platforms, applications and TCP/IP network security technologies Strong technical knowledge of multifaceted exploits and chained attacks. Demonstrated ability to execute attack emulations without detection. Information security concepts, principles and components of a comprehensive information security program Strong, demonstrable aptitude for and interest in offensive and application security. Strong understanding of vulnerability exploitation and an aptitude for identifying weaknesses in controls and infrastructure. Advanced knowledge and/or demonstrated experience in application penetration testing Strong knowledge of customer payload development Work Environment Characteristics Self-motivated and results-oriented, including ability to prioritize conflicting demands. Exceptional organizational skills to balance work and lead the execution of multiple projects. Strong initiative, consensus-building and ability to collaborate directly and build strong relationships with a variety of internal and external stakeholders (business, development, compliance Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Leads the development of information security strategy by understanding business processes, policies, information and information systems. Builds exceptional relationships with internal and external stakeholders. Ensures that requirements and solutions align to a real business need, are approved by all relevant stakeholders, and meets essential information security standards. Provides thought leadership, promotes new processes and methodologies and emerging technologies, with the flexibility to align to the unique requirements of the business/group and deliverables. Provides strategic input into business decisions as a trusted advisor. Understands and can explain to others the core processes, risks and mitigation techniques for designated areas. Acts as a subject matter expert on relevant regulations and policies. Identifies and recommends opportunities to create/contribute to the tactical and strategic vision of the organization. Supports the execution of strategic initiatives in collaboration with internal and external stakeholders. Acts as the prime subject matter expert for internal/external stakeholders. Breaks down strategic problems, and analyses data and information to provide insights and recommendations. Presents data and information to all levels within IT and to business units. Leads/oversees the management of vendor relationships and provides guidelines for execution; ensures that all agreements are met as per requirements. Stays abreast of industry, information security and business trends through benchmarking and/or participation in professional associations. Analyzes trends and stays current with industry events to proactively prevent information security issues. Understands the strategy, plans, activities and needs of all stakeholders and translates those business needs into solutions and makes recommendations. Provides advice, counsel and support on information security matters and recommends solutions to assigned business/group leaders on principles, frameworks, programs, approaches, trends, legislation and regulatory requirements including interpretation of policy and identification and management of risk. Builds credibility and influences/negotiates effectively to drive business performance through development and delivery of information security solutions. Tracks metrics and milestones, providing recommendations for resolution and escalating as appropriate when issues arise. Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks. Promotes process improvements and methodologies; keeps emerging information security issues and trends in mind and ensures standards are followed. Creates professional presentations and deliver them in a meaningful concise way. Assesses information security impact to a projects benefits and risks when scope changes. Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations. Gathers, examines and interprets data and information to extract meaningful insights, answer business questions and provide actionable recommendations. Assists with continuous improvement activities and root cause analysis with the goal of strengthening information security capabilities. Ensures consistent, high quality practices/work and the achievement of business results in alignment with business/group strategies and with productivity goals. Operates at a group/enterprise-wide level and serves as a specialist resource to senior leaders and stakeholders. Applies expertise and thinks creatively to address unique or ambiguous situations and to find solutions to problems that can be complex and non-routine. Implements changes in response to shifting trends. Broader work or accountabilities may be assigned as needed. Qualifications: Typically 7+ years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experience. Multiple information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).Possesses an expert level of knowledge of information security processes, procedures and controls. Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002 - In-depth/Expert. Knowledge of business analysis, project delivery practices and standards across the project lifecycle - In-depth/Expert. Demonstrates in depth knowledge of information security concepts, methodology, processes, procedures and controls. Understanding and problem solving ability of information security issues across the bank - In-depth/Expert. Understanding of information security risk and regulatory requirements - In-depth/Expert. Knowledge of the technical/business environment and the corporate processes and procedures - In-depth/Expert. Seasoned professional with a combination of education, experience and industry knowledge. Verbal & written communication skills - In-depth / Expert. Analytical and problem solving skills - In-depth / Expert. Influence skills - In-depth / Expert. Collaboration & team skills; with a focus on cross-group collaboration - In-depth / Expert. Able to manage ambiguity. Data driven decision making - In-depth / Expert. Salaire : $103,200.00 - $192,000.00 Type de rmunration : Salaire Ce qui prcde reprsente la fourchette et le type de rmunration de BMO Groupe financier. Les salaires varieront en fonction de facteurs comme lemplacement, les comptences, lexprience, les tudes et les qualifications pour le poste et pourront inclure une structure de commissions. Les salaires pour les postes temps partiel seront calculs au prorata du nombre dheures travailles rgulirement. Pour les rles commission, le salaire susmentionn reprsente la cible de BMO Groupe financier pour la premire anne au poste. La rmunration totale offerte par BMO variera selon le type de rmunration associ au poste et peut comprendre des primes de rendement, des primes discrtionnaires ainsi que dautres avantages et rcompenses. BMO offre galement une assurance sant, le remboursement des frais de scolarit, une assurance accident et une assurance vie, ainsi que des rgimes dpargne-retraite. Pour en savoir plus sur nos avantages sociaux, consultez le site : https://jobs.bmo.com/ca/fr/R%C3%A9mun%C3%A9ration-globale propos de nous BMO, nous sommes anims par une raison dtre commune : Avoir le cran de faire une diffrence dans la vie, comme en affaires. Cette raison dtre nous invite entraner des changements positifs et durables pour nos clients, nos collectivits et nos gens. En travaillant ensemble, en innovant et en repoussant les limites, nous transformons des vies et des entreprises et favorisons la croissance conomique partout dans le monde. En tant que membre de l''''quipe de BMO, vous tes valoris, respect et entendu, et vous avez plus de moyens pour progresser et obtenir des rsultats. Nous nous efforons de vous aider obtenir des rsultats ds le premier jour, pour vous-mme et nos clients. Nous vous offrirons les outils et les ressources dont vous avez besoin pour franchir de nouvelles tapes, car vous aidez nos clients franchir les leurs. Au moyen de formation et de coaching approfondis ainsi que de soutien de la direction et d''''occasions de rseautage, nous vous aiderons acqurir une exprience enrichissante et largir votre groupe de comptences. Pour en savoir plus, visitez-nous l''''adresse https://jobs.bmo.com/ca/fr . BMO s''''engage offrir un milieu de travail inclusif, quitable et accessible. Nous apprenons de nos diffrences et tirons notre force des gens et de leurs diffrents points de vue. Des mesures dadaptation sont disponibles sur demande pour les candidats qui participent tous les aspects du processus de slection. Pour demander des mesures dadaptation, veuillez communiquer avec votre recruteur. Remarque aux recruteurs : BMO naccepte pas les curriculum vit non sollicits provenant de toute source autre que le candidat directement. Tout curriculum vit non sollicit envoy BMO, directement ou indirectement, sera considr comme la proprit de BMO. BMO ne paiera aucuns frais pour les placements dcoulant de la rception dun curriculum vit non sollicit. Une agence de recrutement doit dabord dtenir une entente de service crite valide et dment signe avant denvoyer des curriculum vit.