Skip to main content
Post your resume and find your next job on Indeed!

Bmo IT Security jobs

Sort by: -
    • Solid understanding of network security, identity security, and application security.
    • Strong knowledge of security architecture, cloud security frameworks, and…
    • Serve as the primary security contact for technical integrations across the organization.
    • Experience with security challenges and controls in OT/ICS…
    • Solid understanding of security and compliance practices within regulated industries (financial services preferred).
    • Occasional travel may be required.
    • Lead adoption of emerging AI-enabled security paradigms to strengthen BCAA’s security posture.
    • D evelop , document and maintain an enterprise security…
    • Minimum of five years’ experience in security architecture, including enterprise-level security design and implementation.
    • OPTION PERIOD OF UP TO 5 YEARS.
    • Detailed knowledge of CIRO Dealer Rules, provincial securities legislation, and account supervision requirements applicable to mutual fund dealers and…
    • Drives sales results for designated mutual fund/ETF products through non-affiliated or third-party Advisory intermediaries and within BMO Advisory channels.
    • Ensure all code and configurations meet security, performance, logging, and error-handling standards .
    • This role is a unique blend of engineering leadership,…
    • Implement Azure security best practices (Zero Trust, RBAC, Defender for Cloud).
    • Deep and broad general IT engineering knowledge as well as hands-on experience…
    • Maintains control of security collateral including preparation and registration.
    • In-depth understanding of loan and security documentation, including…
    • We are seeking a Senior Compliance Manager – Regulatory Engagement with strong expertise in CIRO rules, securities regulation, and technology‑driven change…
    • Expertise in cloud security patterns including private endpoints, customer-managed keys, and network isolation for AI/ML services.
    • Supports system design, provides advice on security requirements and debugs business systems and service applications.
    • Prior experience as an Approved Person or working at a securities regulator.
    • Have a strong understanding of Private Wealth, and of applicable CIRO rules and the…
    • Drives sales results for designated mutual fund/ETF products through non-affiliated or third-party Advisory intermediaries and within BMO Advisory channels.
Get e-mail updates for the latest Bmo IT Security jobs

By creating a job alert, you agree to our Terms . You can change your consent settings at any time by unsubscribing or as detailed in our terms.

People also searched:

it help desk

Career Resources:

Job Post Details

Business Development Bank of Canada logo

CYBERSECURITY TECHNICAL LEAD - job post

Business Development Bank of Canada
3.8 out of 5 stars
Montréal, QC H3B 5E7Hybrid work
Full-time
You must create an Indeed account before continuing to the company website to apply

Job details

Job type

  • Full-time

Location

Montréal, QC H3B 5E7Hybrid work

Benefits

Pulled from the full job description

  • Paid vacation

Full job description

We are banking at another level.

Choosing BDC as your employer means working in a healthy, inclusive, and skilled workplace that puts forward the best conditions to bring together unique teams where employees are empowered to act. It also means being at the centre of ambitious economic and financial projects to see further and to do things differently, to fuel the success of Canadian entrepreneurs.

Choosing BDC as your employer also means:

  • Flexible and competitive benefits, including an Employee Savings and Investment Plan where BDC matches part of your voluntary contributions, a Defined Benefit Pension Plan, a $750 wellness and health care spending account, to name a few

  • In addition to paid vacation each year, five personal days, sick days as necessary, and our offices are closed from December 25 to January 1

  • A hybrid work model that truly balances work and personal life

  • Opportunities for learning, training and development, and much more...

Explore the BDC Way in our Culture Book


POSITION OVERVIEW


The Cybersecurity Technical Lead is a senior member of the Business and Product Security Posture (BPSP) team, this role provides technical leadership in driving security‑by‑design, provides consistent and risk‑based guidance, mentors Squad members, and influences technology decisions across the organization.

The Cybersecurity Technical Lead plays a key role in strengthening BDC’s cloud and platform security posture across the main Cloud providers (public and privet Cloud), ensuring that solutions are designed, built, and maintained following industry‑leading security standards.

This role collaborates closely with Software Development teams, Solution Architects, CloudOps, Platform Engineering, Product Owners, and business stakeholders to drive a secure-by-design approach across cloud and on-premises environments. Operating within an Agile framework, the Technical Lead contributes to Quarterly Planning and Quarterly Alignment exercises, providing technical and security leadership to ensure strategic priorities, architectural direction, and risk considerations are aligned with business objectives, product roadmaps, and delivery commitments.

Primary accountability: industrialize security controls across cloud platforms, CI/CD pipelines and Kubernetes-based environments by defining and implementing automated guardrails, Policy-as-Code controls, IaC security validations, security gates and secure-by-default deployment patterns.

The Cybersecurity Technical Lead is also responsible for supporting applied AI security initiatives—including LLM risk management, AI governance integration, safe AI enablement, and secure Copilot usage.

In this capacity, Technical Lead complements the existing AppSec/SSDLC Technical Lead, enabling BPSP to deliver comprehensive, end-to-end product and platform security expertise across the organization. Reporting to a Product Owner, the Technical Lead will be responsible for translating business priorities and product objectives into secure and scalable technical solutions. The role will work closely with stakeholders across business, technology, and security functions to ensure that security and technology decisions align with product strategy, delivery roadmaps, and organizational objectives, embedding security throughout the product lifecycle.


CHALLENGES TO BE MET

1. Leadership & Collaboration

  • Design and implement an end-to-end security posture by defining a structured approach and establishing the monitoring and oversight mechanisms required to maintain and measure the organization's security posture.
  • Mentor engineers in CloudSec, PlatformSec, and Applied AI security practices.
  • Represent BPSP in architecture reviews, cloud design sessions, and AI enablement initiatives.
  • Provide support to the Product Manager regarding product and platform security capabilities alongside the SSDLC/AppSec Tech Lead (complementary domains).
  • Drive measurable maturity improvements by reducing manual control dependency and enabling continuous compliance through automated, reusable security patterns.


2. Cloud Security

  • Support the definition and implementation of cloud security architecture, standards, and guardrails across enterprise cloud environments.
  • Provide security advisory and operational governance support to environment owners to help maintain secure and well-controlled cloud environments.
  • Strengthen foundational cloud security capabilities, including identity and access management, data protection, secrets management, encryption, and certificate lifecycle practices.
  • Promote secure design patterns for hybrid, cloud, containerized, and platform-based services where applicable.
  • Support the implementation and continuous improvement of security monitoring, logging, posture management, and control validation capabilities.
  • Partner with platform, infrastructure, and engineering teams to define secure baselines for shared technology environments.
  • Reduce configuration drift and improve resilience through reusable guardrails, automation, infrastructure validation, and continuous control practices.
  • Define and support security checkpoints and deployment guardrails to help prevent non-compliant changes before production release.


3.
Platform & Kubernetes Security

  • Establish and promote secure platform standards for containerized and platform-based workloads, including access control, workload isolation, image integrity, and runtime protection.
  • Define and maintain reusable secure templates, policy controls, infrastructure validation practices, and deployment guardrails for platform workloads.
  • Collaborate with platform engineering, product, and technology teams to embed secure-by-default capabilities across key enterprise platforms, including server, database, application, middleware, and integration platforms where applicable.


4. Artificial Intelligence Security

  • Support the safe adoption of M365 Copilot and Azure OpenAI services (oversharing prevention, data boundaries, classification).
  • Identify LLM‑related risks (prompt injection, output manipulation, data leakage) and recommend mitigations.
  • Integrate AI Governance requirements (model inventory, risk assessments) into SSDLC processes in partnership with AAAI/Data Governance.
  • Collaborate with AAAI and Engineering teams to embed practical guardrails for AI initiatives (non‑research, applied focus).


5. Supporting Responsibility – Penetration Testing & Vulnerability Assessment

  • Support penetration testing and vulnerability assessment activities by defining scope, scenarios, and priorities based on threat models and risk, while keeping the role’s primary focus on Cloud DevSecOps and platform security industrialization.
  • Validate findings, ensure accurate severity rating, and track remediation.
  • Provide expertise to interpret and communicate results to technical and non-technical stakeholders.


6. Supporting Responsibility – Governance & Advisory

  • Provide targeted expert security advisory to IT, product, and business teams where it supports cloud, platform, SSDLC, and AI security outcomes.
  • Contribute to security risk assessments and threat modeling exercises, with emphasis on translating findings into automated and repeatable technical controls.
  • Review and validate compliance evidence for internal controls, audits, and regulatory requirements.
  • Develop and promote security policies, standards, and guidelines
  • Define and produce metrics


WHAT WE ARE LOOKING FOR

Technical Expertise

  • 10+ years in Information Security with a focus on cloud and platform security.
  • Strong expertise in Azure and AWS security (primary BDC clouds) and familiarity with GCP security concepts.
  • Solid experience with Kubernetes securityEKS and Tanzu/RTF.
  • Hands-on experience with IaC: Terraform (primary) and CloudFormation (secondary); Policy-as-Code using OPA/Conftest; IaC security scanning; and CI/CD security automation.
  • Understanding of applied AI security and enterprise AI governance (non‑research).
  • Strong knowledge of security architecture, cloud security frameworks, and secure design patterns.
  • Solid understanding of network security, identity security, and application security.
  • Hands-on experience with vulnerability scanning tools (e.g., Qualys).
  • Strong understanding of CI/CD pipelines, DevSecOps practices, automated security gates, secrets management, and code security tools (SAST/DAST/SCA), including tuning, triage, and false-positive reduction.
  • Experience with penetration testing methodologies (OWASP, PTES).
  • Familiarity with secure configuration benchmarks (CIS, NIST).
  • Experience with threat modeling (STRIDE) is an asset.
  • undefined

Experience

  • Team spirit and interpersonal skills
  • Sense of priorities and understanding of problems, of criticality and of the impact
  • Ability to translate complex security issues into clear guidance for technical and business audiences.
  • Strong influencing skills; able to lead without direct authority.
  • Excellent analytical and problem-solving skills.
  • Collaboration with CloudOps, Platform/DevOps, Data/AAAI, and Architecture.
  • Ability to prioritize risks and manage multiple workstreams.
  • Comfortable coaching security analysts
  • Ability to share information with peers and transfer knowledge
  • Ability to manage multiple requests and priorities head-on
  • Ability to translate theoretical aspects into tactical realities and specificities of IT operations and to integrate these theoretical elements into this reality
  • Ability to communicate effectively in both official languages (French and English)


Education/Certifications

  • Certifications such as CISSP, CCSP, OSCP, GWAPT, or Azure/AWS Security certifications are strong assets.


#INDHP


Proudly one of Canada’s Top 100 Employers and one of Canada’s Best Diversity Employers, we are committed to fostering a diverse, equitable, inclusive and accessible environment where all employees can thrive and feel empowered to bring their whole selves to work. If you require an accommodation to complete your application, please do not hesitate to contact us at accessibility@bdc.ca.

While we appreciate all applications, we advise that only the candidates selected to participate in the recruitment process will be contacted.

Let Employers Find YouUpload Your Resume