BMO Financial Group
Financial Services
ApplicationSecurityAutomationEngineer
Neural analysis suggests this role is
optimal for Mid candidates.
“Application Security Automation Engineer at BMO Financial Group. Skills: Application Security Testing, SAST, Automation, LLM Security. Lead SAST operations. Tune scan tools”
What You'll Achieve.
Reduce risk through secure coding practices; Reduce risk through actionable findings; Reduce risk through integrated controls; Meet business goals
Industry & Context.
Root-cause analysis; Risk-based assessment
Hybrid work model - 2 days/week in office
What They're Looking For.
Must Have
Bachelor's Degree in Computer Science, Engineering, Math, Cyber Security, 5-7 years of relevant experience as a SAST / Automation Engineer, 5+ years hands-on experience with static source code analysis (SAST) tools, 5+ years hands-on experience with dynamic application security (DAST) tools, knowledge of common coding languages (e.g. C#, JAVA, JavaScript, TypeScript, Python etc.), 5+ years scripting/automation experience (e.g. , Python, Node. js, Bash), Working knowledge of OWASP Top 10, Working knowledge of OWASP Testing Guide, Working knowledge of NIST Cyber Security Framework (CSF), Solid understanding of secure coding frameworks, Solid understanding of secure code reviews, Solid understanding of code scanning software, Solid understanding of vulnerability code scanning processes, Solid understanding of network protocols and connectivity, Solid understanding of risk-based assessment approach, Understanding of information security risk, Understanding of regulatory requirements
Nice to Have
Cybersecurity certification (CISSP, CISSLP, OSCP, GSEC etc.), Experience contributing to SOPs, Experience contributing to reusable templates, Experience contributing to security testing playbooks
What You'll Do.
Provide secure code review
Support development teams
Contribute to other testing programs
Integrate testing into CI/CD
Evaluate AI capabilities
Assess LLM security implications
Recommend corrective actions
Support risk acceptance processes
How You'll Work.
Team & Collaboration
Partner with application teams; Liaise with stakeholders; Work with development teams
Process & Methodology
Planning, Tracking, Risk acceptance processes
Full Job Description
Application Deadline: 06/29/2026 Address: 100 King Street West Job Family Group: Technology **Hybrid work model - 2 days/week in office** The Application Security Automation Engineer reports to the Senior Manager of automated security testing team and supports security testing activities for BMO applications. This role is responsible for leading and maturing the bank’s static application security testing (SAST) capabilities and partnering with application teams to reduce risk through secure coding practices, actionable findings, and integrated controls across the SDLC. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Participates in the execution of information security strategy. **Application Security Testing** * Lead end-to-end SAST operations, including intake/scoping, onboarding, configuration, execution, triage, and reporting across diverse technology stacks. * Tune scan tools to reduce false positives and improve signal quality; provide secure code review and root-cause analysis support to development teams. * Contribute to other testing programs (SCA, DAST) and integration into CI/CD workflows as needed to support scan readiness, coverage validation, and triage of results. * Evaluate and adopt AI-assisted capabilities in security scanning/testing tools to improve triage speed, consistency, and remediation guidance. * Assess the security implications of LLM-enabled features on application threat models and emerging risks, e.g. supply chain integrity, prompt-driven workflows, RAG pipelines. * Identify gaps through risk-based assessments; recommend corrective actions for vulnerabilities and weaknesses; and support planning, tracking, and risk acceptance processes in alignment with regulatory expectations. **What you need to succeed:** * Bachelor's Degree in a relevant discipline (Computer Science, Engineering, Math, Cyber Security) * Typically 5-7 years of
Applying for this Application Security Automation Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about BMO Financial Group?
Real rants from real employees. Read before you apply.