Cyber Security Consultant – Application Security Threat Modeling
Job Overview
Apply locations : Toronto, ON, CAN
Time type : Full time
Posted on : Posted 2 Days Ago
Job Requisition ID : R250001433
Application Deadline : 04 / 29 / 2025
Address : 4100 Gordon Baker Road
Job Family Group : Technology
As a Cyber Security Consultant, you will be part of the Application Security Risk Assessments team within Cyber Security. The team performs Threat Modelling of applications and technology designs to identify threats early in BMO Financial Group’s SDLC and risk management process. You will have an opportunity to take a collaborative approach in maturing threat modeling practices, identifying relevant security threats and flaws, helping colleagues continuously improve security practices, and enabling business objectives.
What you will do :
- Be integral in continuously maturing the threat modeling practices and application security risk assessment program.
- Ensure security threats and countermeasures are identified in projects / initiatives as part of the SDLC process.
- Maintain an understanding of available security design patterns and identify gaps that require improvement opportunities.
- Produce high-quality threat modeling artifacts and track assessments and remediation activities.
- Keep apprised of business technology practices and relevant threats, working with Security Architect to identify appropriate controls.
- Advocate for Cybersecurity company standards and industry best practices.
- Help build and improve threat libraries and controls, standardizing threat modeling practices.
- Collaborate with the larger Security Assessment and Testing group in socializing identified threats.
- Stay informed of new technology trends and associated risks in application development practices.
Skills and Experience we are looking for :
Competent knowledge in Threat Modeling methodologies (e.g., Attack Trees, MSTM / STRIDE, PASTA).Working experience in Agile methodologies.Knowledge of DevOps practices and ability to champion a security-first, DevSecOps culture.Ability to decompose applications and system designs in hybrid cloud architectures.Proficient communication and negotiation skills, both verbal and written.Empathetic and eager to solve problems, driven to learn new skills, and maintains high integrity.Prior experience in software development (e.g., Java, JS, Python) is preferred.Prior experience in 2 or more other security domains is preferred.Typically, 2-3 years of relevant experience and a post-secondary degree in a related field or an equivalent combination of education.Salary
65,400.00 - $121,800.00
J-18808-Ljbffr