AI Penetration Tester
Job Description
Location
Florida (remote). Work remotely within the EST or CST time zones.
Responsibilities
- Conduct security assessments of AI systems, LLMs, AI agents, and machine learning applications.
- Perform adversarial testing including prompt injections, jailbreaks, model manipulation, and abuse-case testing.
- Execute application, API, and cloud security testing supporting AI-enabled solutions.
- Develop repeatable AI security testing methodologies, tools, and automation.
- Partner with development and engineering teams to validate and remediate findings.
- Produce technical reports and executive summaries communicating risks and recommendations.
- Research emerging AI threats and attack techniques.
- Support red team exercises involving AI-enabled attack scenarios.
Requirements
- Advanced penetration testing experience across web applications, APIs, and cloud environments.
- Hands-on experience assessing AI/LLM technologies, AI agents, ML models, or GenAI applications.
- Strong understanding of offensive security methodologies and adversarial attack techniques.
- Experience with Python scripting and security tool development/automation.
- Knowledge of OWASP Top 10, API Security Top 10, and emerging OWASP LLM Security risks.
- Experience performing threat modeling and security assessments.
- Strong understanding of authentication, authorization, identity, and cloud security concepts.
- Ability to clearly document findings and remediation recommendations.
- Typically 7+ years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, Information Systems, Business or related field, or an equivalent combination of education and experience.
- Multiple Information Security certifications from recognized institutions (e.g., ISC2, ISACA, SANS).
- Expert knowledge of information security, requirements gathering, and reporting in a financial services setting.
- Data manipulation and analysis skills with the ability to organize and analyze significant information with accuracy.
- Knowledge of information security processes, procedures, and controls.
- Understanding of information security issues across the bank and related regulatory requirements.
- Understanding of industry standards and frameworks such as NIST CSF and ISO 27001/27002.
- Ability to navigate complex computing environments and understand how security platforms impact them.
- Strong verbal and written communication, analytical, problem-solving, and cross-team collaboration skills.
- Ability to manage ambiguity and make data-driven decisions.
Technologies
- Python
Benefits
- Health insurance
- Tuition reimbursement
- Accident insurance
- Life insurance
- Retirement savings plans
- Performance bonuses
- Discretionary bonuses
- Other benefits and rewards
Compensation
Salary: USD 122,400 – 228,000 per year. Salaries vary by location, skills, experience, and education, and may include incentive structures. Part-time roles are pro-rated. For roles with commissions, the stated salary represents the first-year target.
Application Deadline
10/30/2026
Location Details
VIRTUAL09 - HomeRes - FL
What makes this role unique?
- Build something new by creating and maturing a first-of-its-kind AI Security Testing capability within BMO's Security Testing Team.
- Work with emerging technology to evaluate LLMs, AI agents, GenAI platforms, and ML systems using advanced adversarial testing techniques.
- Drive enterprise impact by shaping security outcomes for strategic AI initiatives before they reach production.
- Design and develop new AI adversarial testing methodologies that become part of BMO's long-term security strategy.
- Expand expertise through leading security testing exercises, AI threat research, and simulating emerging attack techniques targeting AI systems.
- Collaborate with leading security practitioners, AI engineers, architects, and governance teams to solve complex challenges.
- Enjoy flexible remote work within EST or CST time zones.