Cyber Security Consultant
BMO Financial Group · Chicago, IL
$88,800–$165,600from the description
Jul 22, 2026
Chicago, IL
Jul 24, 2026
What this job asks for AI summary
This role sits within a cybersecurity team focused on application security risk assessments, where the primary work involves conducting threat modeling exercises against application and technology designs to surface risks early in the software development lifecycle. Day-to-day responsibilities include producing threat modeling artifacts, communicating findings to stakeholders, tracking remediation, and helping mature the broader assessment program. It suits candidates with hands-on experience in threat modeling methodologies, application architecture analysis, and API security across on-premises and cloud environments.
Mid level · 3+ years · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The job location is not explicitly stated in the posting beyond BMO Financial Group context; it is listed as a hybrid role (minimum 2 days in office) but no specific city is named, so the CBSA could not be determined.
The title 'Application Security Threat Modeling Consultant' carries no seniority level word; advertised seniority is Unspecified. The 3+ years requirement and scope of work (individual contributor, team-embedded) support a Mid-level classification.
Threat modeling methodologies (STRIDE/MSTM, PASTA, Attack Trees) are listed together as interchangeable examples under the core required skills section; STRIDE is used as the primary name with the others as alternatives.
Prior software development experience (Java, JS, Python) is explicitly marked as 'preferred' in the posting.
Industry certifications (CISM, CISSP, GIAC, CEH) are listed in the core skills section but framed as desirable credentials rather than hard gates — the posting also accepts 'equivalent combination of education', so these are treated as preferred.
The degree requirement states 'Post-secondary degree… or an equivalent combination of education,' so no minimum formal degree is hard-required.
The alt SOC 15-1211 (Computer Systems Analysts) is noted as a runner-up given the strong architecture review and systems decomposition component of the role, though the primary security analysis focus makes 15-1212 the clear primary.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Architecture Risk Analysis.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.