Enable job alerts via email!

Senior Cybersecurity Consultant – Application Security

BMO Financial Group

Irving (TX)

Hybrid

USD 120,000 - 223,000

Full time

3 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join BMO Financial Group as a Senior Cybersecurity Consultant – Application Security, where you will lead threat modeling initiatives and help in designing secure applications. With over 8 years of experience required, this hybrid role allows you to influence technology risk decisions and mentor others in a collaborative team environment.

Benefits

Health insurance
Tuition reimbursement
Accident and life insurance
Retirement savings plans

Qualifications

  • 8+ years of experience in cybersecurity, with 5+ years in application security.
  • Advanced knowledge of hybrid cloud application architectures.
  • Expertise in OWASP, CWE, and MITRE Att&ck frameworks.

Responsibilities

  • Lead threat modeling initiatives and provide consulting for secure applications.
  • Deliver high quality security assessment artifacts.
  • Mentor other team members and evangelize security practices across the organization.

Skills

Application security
Threat modeling
Cybersecurity
Collaboration
Analytical skills

Education

Post-secondary degree in Computer Science, Engineering, or Information System

Tools

Kubernetes
AWS
Azure
Generative AI
Large Language Models

Job description

Senior Cybersecurity Consultant – Application Security

Join a forward-thinking Cybersecurity team where your expertise directly shapes the safety and resilience of next-generation technologies. As a Senior Cybersecurity Consultant – Application Security, you’ll operate at the intersection of cutting-edge application design and world-class security strategy—leading threat modeling initiatives that influence designing secure core business technologies across hybrid cloud and next generation platforms.

At the heart of our culture is continuous learning, integrity, and a shared mission: to drive secure innovation. If you’re a problem-solver who thrives on ownership, collaboration, and making a measurable impact, this is your opportunity to lead from the front.

What You’ll Gain:

The chance to influence technology risk decisions

Exposure to the latest in application architecture environment

A collaborative, metrics-driven team that values your voice

A platform to grow your leadership presence through mentoring and evangelizing secure development practices

Bring your integrity, technical depth, and vision. We’ll give you the platform to make a difference.

***This is a HYBRID role***

As a Senior Cybersecurity Consultant, you will be part of Application Security Risk Assessments team within Cybersecurity. The Application Security Risk Assessment team performs threat modelling of applications and technology designs as part of SDLC and risk management process. This individual will also provide consulting to technology groups as needed to build secure applications and associated technologies in hybrid cloud environments. As a senior member of the team, you will have an opportunity to take collaborative approach in maturing threat modeling practices, identify relevant security threats, associated risks to business technologies and help enable secure business objectives. In addition, you will play a key role to ensure the function is aligning with industry leading practices and look for opportunities to enhance the function via tooling and refining methodologies and processes through automation along with force multiplier duties such as the following:

  • Perform and deliver high quality security assessment/threat modeling artifacts.
  • Continuously keep apprised of business technology practices and relevant threats, current and emerging and work with other Cybersecurity and technology teams to identify appropriate controls and mentor other team members.
  • Conduct product/capability evaluations as needed and lead initiatives to improve internally developed tooling.
  • Lead initiatives to present and evangelize security practices across technology organization.
  • Thrives in cross-functional collaboration with other Cybersecurity areas and key technology groups to identify common controls, potential risk reducing opportunities in technology projects and contribute to improve application security posture.
  • Continuously keep abreast of new industry technology trends, associated risks and their mitigation practices in new, frameworks, cloud services, generative AI application designs, various language models, modern data store platforms etc.

Skills and Experience:

  • Minimum of 8+ years of relevant experience in cybersecurity with 5+ years in application security or security architecture
  • Advanced level working knowledge in application architectures in hybrid cloud environments(e.g., SPA, microservices, Kubernetes, AWS, Azure) and performing their security design reviews using threat modeling methodology or performing related architecture risk analysis.
  • Advanced knowledge of OWASP, CWE or MITRE Att&ck and its applicability to performing security assessments and recommending defensive strategies.
  • Expert level working experience with modern authentication and authorization frameworks, protocols (e.g., OAuth/OIDC, WebAuthn), security risk management practices, writing/building effective artifacts as well as communicating to stake holders.
  • Practical knowledge of securing applications using Generative AI and Large Language Models.
  • Expert level analytical skills along with communication and negotiations skills, both verbal and written.
  • Working experience in agile methodologies, as well as prior experience in software development or automating solutions using code.
  • Is empathetic and has passion to solve problems and always maintains high integrity.
  • Prior experience in 2 or more other security domains, e.g., ethical hacking, cloud security, security architecture domains (e.g., Application, Network, Platform) is preferred.
  • Industry certifications such as CISM, CISSP, GIAC
  • Post-secondary degree in Computer Science, Engineering, or Information System

Application Deadline:

08/24/2025

Address:

300 E John Carpenter Freeway

Job Family Group:

Technology

Shape the Future of Secure Innovation.

Join a forward-thinking Cybersecurity team where your expertise directly shapes the safety and resilience of next-generation technologies. As a Senior Cybersecurity Consultant – Application Security, you’ll operate at the intersection of cutting-edge application design and world-class security strategy—leading threat modeling initiatives that influence designing secure core business technologies across hybrid cloud and next generation platforms.

At the heart of our culture is continuous learning, integrity, and a shared mission: to drive secure innovation. If you’re a problem-solver who thrives on ownership, collaboration, and making a measurable impact, this is your opportunity to lead from the front.

What You’ll Gain:

  • The chance to influence technology risk decisions

  • Exposure to the latest in application architecture environment

  • A collaborative, metrics-driven team that values your voice

  • A platform to grow your leadership presence through mentoring and evangelizing secure development practices

Bring your integrity, technical depth, and vision. We’ll give you the platform to make a difference.

***This is a HYBRID role***

As a Senior Cybersecurity Consultant, you will be part of Application Security Risk Assessments team within Cybersecurity. The Application Security Risk Assessment team performs threat modelling of applications and technology designs as part of SDLC and risk management process. This individual will also provide consulting to technology groups as needed to build secure applications and associated technologies in hybrid cloud environments. As a senior member of the team, you will have an opportunity to take collaborative approach in maturing threat modeling practices, identify relevant security threats, associated risks to business technologies and help enable secure business objectives. In addition, you will play a key role to ensure the function is aligning with industry leading practices and look for opportunities to enhance the function via tooling and refining methodologies and processes through automation along with force multiplier duties such as the following:

  • Perform and deliver high quality security assessment/threat modeling artifacts.
  • Continuously keep apprised of business technology practices and relevant threats, current and emerging and work with other Cybersecurity and technology teams to identify appropriate controls and mentor other team members.
  • Conduct product/capability evaluations as needed and lead initiatives to improve internally developed tooling.
  • Lead initiatives to present and evangelize security practices across technology organization.
  • Thrives in cross-functional collaboration with other Cybersecurity areas and key technology groups to identify common controls, potential risk reducing opportunities in technology projects and contribute to improve application security posture.
  • Continuously keep abreast of new industry technology trends, associated risks and their mitigation practices in new, frameworks, cloud services, generative AI application designs, various language models, modern data store platforms etc.

Skills and Experience:

  • Minimum of 8+ years of relevant experience in cybersecurity with 5+ years in application security or security architecture
  • Advanced level working knowledge in application architectures in hybrid cloud environments(e.g., SPA, microservices, Kubernetes, AWS, Azure) and performing their security design reviews using threat modeling methodology or performing related architecture risk analysis.
  • Advanced knowledge of OWASP, CWE or MITRE Att&ck and its applicability to performing security assessments and recommending defensive strategies.
  • Expert level working experience with modern authentication and authorization frameworks, protocols (e.g., OAuth/OIDC, WebAuthn), security risk management practices, writing/building effective artifacts as well as communicating to stake holders.
  • Practical knowledge of securing applications using Generative AI and Large Language Models.
  • Expert level analytical skills along with communication and negotiations skills, both verbal and written.
  • Working experience in agile methodologies, as well as prior experience in software development or automating solutions using code.
  • Is empathetic and has passion to solve problems and always maintains high integrity.
  • Prior experience in 2 or more other security domains, e.g., ethical hacking, cloud security, security architecture domains (e.g., Application, Network, Platform) is preferred.
  • Industry certifications such as CISM, CISSP, GIAC
  • Post-secondary degree in Computer Science, Engineering, or Information System

Salary :

$120 000,00 - $222 600,00

Pay Type:

Salaried

The above represents BMO Financial Group’s pay range and type.

Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group’s expected target for the first year in this position.

BMO Financial Group’s total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit: https://jobs.bmo.com/global/en/Total-Rewards

About Us

At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.

As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset.

To find out more visit us at http://jobs.bmo.com/us/en

BMO is proud to be an equal employment opportunity employer. We evaluate applicants without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or any other legally protected characteristics. We also consider applicants with criminal histories, consistent with applicable federal, state and local law.

BMO is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please send an e-mail to BMOCareers.Support@bmo.com and let us know the nature of your request and your contact information.

Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.

About the company

The Bank of Montreal is a Canadian multinational investment bank and financial services company.

Notice

Talentify is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Talentify provides reasonable accommodations to qualified applicants with disabilities, including disabled veterans. Request assistance at accessibility@talentify.io or 407-000-0000.

Federal law requires every new hire to complete Form I-9 and present proof of identity and U.S. work eligibility.

An Automated Employment Decision Tool (AEDT) will score your job-related skills and responses. Bias-audit & data-use details: www.talentify.io/bias-audit-report . NYC applicants may request an alternative process or accommodation at aedt@talentify.io or 407-000-0000.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Cybersecurity Consultant – Application Security

Bank of Montreal

Irving null

Hybrid

Hybrid

USD 120,000 - 223,000

Full time

2 days ago
Be an early applicant

Senior Cybersecurity Consultant – Application Security

BMO U.S.

Irving null

Hybrid

Hybrid

USD 120,000 - 223,000

Full time

3 days ago
Be an early applicant

Sr. Information Security Analyst

McKesson’s Corporate

Irving null

Remote

Remote

USD 104,000 - 180,000

Full time

2 days ago
Be an early applicant

Senior Software Engineer (Multiple Positions Available)

MedStar Health

Irving null

Remote

Remote

USD 149,000 - 209,000

Full time

Yesterday
Be an early applicant

Senior Software Engineer (Multiple Positions Available)

McKesson’s Corporate

Irving null

Remote

Remote

USD 149,000 - 209,000

Full time

2 days ago
Be an early applicant

Senior Software Engineer (Multiple Positions Available)

McKesson

Irving null

Remote

Remote

USD 149,000 - 209,000

Full time

3 days ago
Be an early applicant

Senior Software Engineer (Multiple Positions Available)

McKesson

Irving null

Remote

Remote

USD 150,000 - 209,000

Full time

2 days ago
Be an early applicant

Senior Software Engineer

Milliman Ireland

Irving null

Remote

Remote

USD 93,000 - 186,000

Full time

3 days ago
Be an early applicant

Sr. Network Security Engineer

McKesson’s Corporate

Irving null

Remote

Remote

USD 144,000 - 241,000

Full time

8 days ago