Cyber Security Consultant

 

Description:


As an Application Security Threat Modeling Consultant, you will be part of Application Security Risk Assessments team within Cybersecurity. The Application Security Risk Assessment team performs assessments of applications and technology designs to identify threats and potential risks early in BMO Financial Group’s SDLC and risk management process. You will have an opportunity to take collaborative approach in maturing application security threat modeling practices, identify relevant security threats to business technology, help colleagues continuously improve security practices, secure and enable business objectives.

This is a HYBRID role with a current requirement of at least 2 days in the office

KEY Responsibilities:
 

  • Perform high quality application security assessments producing easy to understand threat modeling artifacts, communicate (written and verbal) potential risks effectively to stakeholders and follow through in tracking assessments and remediation activities.
  • Be integral in continuously maturing the threat modeling practices and application security risk assessment program.
  • Maintain an understanding of available security requirements, design patterns, and identify gaps that require improvement opportunities.
  • Keep abreast of new technology trends and associated risks in application development practices, frameworks, cloud services, modern data store platforms etc. and ability apply this knowledge and skills during threat modeling exercises.
  • Broader work or accountabilities may be assigned as needed.

     

CORE Skills and Experience:
 

  • Demonstrated experience with Threat Modeling methodologies (e.g. Attack Trees, MSTM/STRIDE, PASTA) and/or performing Architecture Risk Analysis.
  • Proven experience with Software Application architecture risk analysis, threat modeling,
  • Deep experience with decomposing applications and system designs in on-prem and hybrid cloud architectures to identify potential threats.
  • Proven experience with API Security, Review & decompose solution designs to identify potential threats.
  • More than 3 years of relevant experience in Cybersecurity
  • Proficient level working experience in application security and security risk management practices.
  • Working experience in Agile methodologies.
  • Knowledge of DevOps practices and ability to champion security first, DevSecOps culture and practices.
  • Prior experience in software development (e.g., Java, JS, Python) is preferred.
  • Advanced analytical skills along with proficient communication and negotiations skills, both verbal and written.
  • Is empathetic and loves to solve problems and always maintains high integrity.
  • Post-secondary degree in Computer Science, Engineering, or Information Systems or a related field of study or an equivalent combination of education
  • Industry certifications such as CISM, CISSP, GIAC, or CEH.
     

Organization BMO U.S.
Industry Consultant Jobs
Occupational Category Cyber Security Consultant
Job Location Irving,USA
Shift Type Morning
Job Type Full Time
Gender No Preference
Career Level Intermediate
Experience 2 Years
Posted at 2026-07-22 3:55 pm
Expires on 2026-09-05