1,475 Remote Cybersecurity Jobs (September 2026) - Apply with AI

Explore remote cybersecurity jobs in September 2026 across core areas like security engineering, cloud security, application security, governance and risk, compliance, detection and response, and security operations. You can expect a mix of hands-on technical roles and policy-focused positions, with remote teams often asking for clear experience with security tools, incident workflows, and cross-functional collaboration. Create an account to explore the full feed and auto-apply with LiftmyCV AI Agent.

Live Status:
Sep 9, 2026
1,475+ Active Roles
Updated Daily
8

Information Security Engineer

Remote
8amRemote - Czech Republic

The Information Security Engineer at 8am focuses on maintaining the security and integrity of systems with an emphasis on cloud security operations, detection engineering, and incident response. The role involves hands-on technical work, operating and improving the detection and response stack, leading investigations of security events, and collaborating with engineering teams. The position is remote based in the Czech Republic and aligns with U.S. Central Time for collaboration with teams in the U.S.

Posted 1 week ago

Keyfactor, Inc.

Information Security Engineer

Remote
Keyfactor, Inc.United States; Remote (Cleveland or Atlanta preferred)

About Keyfactor Our mission is to securely connect the world: humans, machines, and AI. Keyfactor is the leader in trust infrastructure for AI and machines, helping the world's largest enterprises and government agencies take control of the cryptographic identities that safeguard every digital interaction. Behind the platform is a global team of people who care deeply about the work and each other. We move fast, think big, and show up for one another every day. If you're looking for work that matters and a team that brings out your best, we hope you'll trust your future with Keyfactor! Title: Information Security Engineer Location: USA; Remote ( Atlanta or Cleveland preferred) Experience: Mid-Level Job Function : Corporate IT Employment Type : Full-Time Industry: Computer Network Security About the position We are seeking an experienced Information Security Engineer with a strong background in implementing and managing general information security frameworks, including ISO 27001:2022 and SOC 2 Type II. This role involves designing, maintaining, and improving our security infrastructure to ensure compliance with regulatory standards and support continuous monitoring efforts. The ideal candidate will play a key role in safeguarding the organization’s data and infrastructure while driving adherence to evolving security best practices. Responsibilities Evaluate the security posture of systems, platforms, and cloud environments, establish appropriate security baselines, and drive implementation and hardening to close identified gaps. Quickly develop proficiency in new SIEM, EDR, and other security platforms as the environment evolves; configure, tune, and integrate these tools with SaaS applications and diverse data sources to expand visibility and detection coverage. Evaluate and optimize security playbooks, runbooks, and processes based on lessons learned, tooling changes, and evolving threats, ensuring documentation and workflows keep pace with the organization's security operations maturity. Experience conducting vulnerability assessments, system audits, and risk analysis using industry-standard scanning tools to support a proactive security posture. Manage and implement continuous monitoring processes to ensure the organization maintains compliance with a variety of information security frameworks, including ISO 27001:2022 and SOC 2 Type II. Experience with government compliance standards such as FedRAMP (NIST SP 800-53) and CMMC is preferred. This role focuses on ensuring robust security practices and adapting to evolving compliance requirements. Actively monitor, analyze, and respond to security alerts and incidents, performing investigations, incident handling, and recommending corrective actions. Minimum Qualifications, Education, and Skills 5+ years of experience in information security or a similar role Proficiency in vulnerability scanning tools (Nessus, Burpsuite, Tenable, etc…) and interpreting scan results for remediation. Strong knowledge of security standards Demonstrated experience in continuous monitoring, network security, firewalls, VPNs, IDS/IPS, and endpoint protection. Strong analytical skills and a meticulous approach to problem-solving Demonstrated capability to deliver results on-time and to a defined schedule. Relevant certifications (e.g., CISSP, CompTIA Security+, CAP) are strongly preferred Familiarity with cloud security principles Experience with security automation and continuous monitoring tools PKI knowledge a plus Knowledge of scripting languages (Python, PowerShell) to automate security processes Experience with government-regulated environments (AWS GovCloud, Azure Government) preferred #LI-NA1 Compensation Salary will be commensurate with experience. Culture, Career Opportunities and Benefits We build teams that continually strive to get better than the day before. You will be challenged daily and given opportunities to grow personally and professionally. We balance autonomy and structure to create an entrepreneurial environment to spur creativity and new ideas. Here are just some of the initiatives that make our culture special: Second Fridays (a company-wide day off on the second Friday of every month minus November and December due to the Holiday schedule). Please note that this benefit is subject to change. Comprehensive benefit coverage globally. Paid Parental Leave is available to new parents. Structure varies based on regional/government requirements. In regions where government-paid leave doesn’t exist, like in the U.S., the company offers generous paid parental leave, along with comprehensive adoption and fertility support. Competitive time off globally. Dedicated employee-focused ambassadors via Key Contributors Culture Committees. DIVERSE Commitment, a call to action for a more inclusive and diverse future in business, society, and technology. The Keyfactor Alliance Program to support DEIB efforts. Wellbeing resources, wellness allowance, mindfulness app free membership, Wellness Wednesdays. Global Volunteer Day, company non-profit matching, and 3 volunteer days off. Monthly Talent development and Cross Functional meetings to support professional development. Regular All Hands meetings – followed by group gatherings. Our Core Values Our core values are extremely important to how we run our business and what we look for in every team member: Trust is paramount. We deliver security software and solutions where trust and openness are of the highest importance for our customers. We are honest and a trusted partner in every aspect of business. Customers are core. We strategize, operate, and execute through a customer-centric view. We prioritize the security interests of our customers, and we act as if their data were our own. Innovation never stops, it only accelerates. The speed of change is accelerating. We are committed, through investment and focus, to stay ahead of the innovation curve. We deliver with agility . We thrive in high-paced and continually changing environments. We navigate through newly added variables, adjust accordingly, while driving towards our strategic goals. United by respect . Respect for all is what unites us. We promote diversity, inclusivity, equity, and acting with empathy and openness, both in our business and in our communities. Teams make “it” happen. Vision and goals are not individually achievable – they require teamwork. We pride ourselves in operating as a cohesive team, creating promoters and partners, and winning as one. Keyfactor is a proud equal opportunity employer including but not limited to veterans and individuals with disabilities. REASONABLE ACCOMMODATION: Applicants with disabilities may contact a member of Keyfactor’s People team via [email protected] and/or telephone at 1.216.785.2990 to request and arrange for accommodations at any time. Keyfactor Privacy Notice

Posted 2 weeks ago

Mariner

Information Security Engineer

Remote
MarinerUnited States

Mariner seeks a hands-on Information Security Engineer to join its Security Engineering & Architecture team. This role involves implementing and operating security controls across networks, infrastructures, and applications aligned with zero trust principles. The ideal candidate will play a crucial role in building observability systems, securing new environments, and translating security standards into configurations and controls. Collaboration with engineering, infrastructure, and compliance teams is essential to protect client assets and sensitive data, making a significant impact on security challenges within a dynamic, acquisition-driven environment.

Posted 2 weeks ago

HG

Information Security Engineer

Remote
HSP GroupSpain - Remote, United States - Remote

HSP Group seeks a mid-level Information Security Engineer to enhance the security of their SaaS products and cloud environments. This remote role involves managing vulnerabilities, contributing to corporate security policies, and leading audit efforts. The ideal candidate should have 4-6 years of experience in information security, particularly within cloud settings, and possess strong communication skills to engage with technical and non-technical stakeholders. The role promises a collaborative environment focused on driving improvements in security posture.

Posted 3 weeks ago

City Lodge Hotels

Information Security Analyst

Remote
City Lodge HotelsSupport Ofiice Johannesburg, ZA

Position Detail Overall Purpose of the Job Supports the IT functionality of all business units and hotels by providing all internal users with secure solutions to their IT needs. Troubleshoots security issues and identifies security trends so as to ensure ongoing up time of systems. Provides insights into future security trends. Education (Formal Qualification Required) Minimum Grade 12. National Diploma: IT. N+. MCSA: Windows 10 and above. ITIL Foundations v4. Security +. Microsoft 365: Modern Desktop Administrator Associate. Computer literacy is essential particularly with proficiency in Microsoft Office Suite. Advantageous CEH. Legal Requirements (e.g. Driver’s License, etc.) Valid driver’s license. Experience (Minimum Experience Required - Number of years) Minimum Incumbent must have at least 4 years' experience in Incident Response, Intrusion Prevention, Cyber Security Techniques, Advanced Server, Advanced Network Support WAN and LAN, Operating Systems, Advanced Azure Support and Virtualisation. Advantageous IT experience in hospitality or related industry. People May hire new employees when authorised to do so up to the level of Information Systems Support Officer (Security). Is required to issue verbal/written warnings when necessary and in the event of company policy having been violated. After consultation with the Divisional Director: IT | Group IT Manager and the Divisional Director: HR | Group HR Manager, may terminate contracts of employment, where necessary and in the event of company policy having been gravely violated. Finance The job requires the handling of money and the authorisation to dispense and deposit company funds and is therefore subject to a fraud and credit check. Occasional Duties Carry out any duties as may be requested by the Divisional Director: IT and in line with expertise and role. Special Conditions May be required to work on a standby basis after hours, as per rotation schedule. May be required to be available 24/7 for emergencies. Own transport. This job requires prolonged sitting, maintaining a static posture, performing repetitive movements, undertaking manual handling that may involve awkward postures, managing visual strain, and coping with exposure to psychosocial and cognitive stressors. Competencies (Knowledge, Skills and Behavioural Attributes) Knowledge Penetration testing Active Directory Scripting Azure Cloud and Hybrid Email Security and Spam Filters Data handling and Encryption Voice Networks – routing and switching Virtualisation Antivirus and EDR Patch management Immutable Backups Secure Certificates Vulnerability Assessment Skills Time management Verbal and written communication Troubleshooting/problem solving Relationship management Cognitive (Memory/Insight/ Conceptualisation) Planning Clerical (documentation) Attention to detail Critical and creative thinking Learning agility Behavioural Attributes Customer centric Perseverance Self-starter Collaborative Stress tolerant and resilient Results orientated Accountable Position Requirements Detailed Description / Output Finds and supplies secure solutions to issues in an effective and efficient manner. Contributes necessary information for budgets. Contributes to cost savings drive by the division. Monitors and reports on the entire estate to ensure everything is secured correctly by attending to: Awareness Training PCIDSS Assessments GDPR/POPI Assessments Penetration Testing Vulnerability and Patch Management Incident Response Configures and maintains all deployed hardware to the required security standards considering the current functionality of the hardware and the capacity of the hardware measured against the needs of the business. Maintains software deployed on the hardware and networks. This includes operating systems and various other operational tools (such as backup tools, monitoring tools and security tools) and business and core CLH systems. Ensure that the WAN and LAN are correctly secured Builds and maintains relationship with 3 rd party suppliers. Manages escalations. Maintains security on all software applications and hardware devices and assists with the deployment of new or existing systems. Attends to security incidents. Monitors the strict adheres of the IT team and users to IT security requirements. Administers the change management process in a manner that ensures changes or new implementations do not affect business efficiency and continuity. Devises and maintains the necessary DR policies, plans and procedures. Manages the applicable DR solutions in place. Tests DR solutions, processes and procedures and reports on these, as well as on all other DR related activities. Develops, implements and maintains IT security policies and procedures. Be on the lookout for and be aware of any enhancements that could improve the security of the group’s infrastructure and to communicate such to the group. Maintains any differentiation, should it exist or be required, between the brands in relation to the applicable hardware/software authorised for use in those brands. Provides support to first line technicians on the more technical software, hardware, network and security related queries and resolve these within the agreed Service Level Agreements (SLAs). Provides incident management, problem management, event management, availability management, asset and configuration management and capacity management. Supports projects related to the deployment or upgrade of IT hardware, networks and software. Assists with testing of new and existing systems prior to deployment. Provides 24/7 support to the business to eliminate any system down time. Communicates effectively and timeously with different business units, suppliers and CLH IT. Builds and maintains relationships with key stakeholders which includes the different business units, suppliers, CLH IT and 3 rd party vendors. Participates in personal development activities to learn/enhance skillset. Participates in and manages ITs human resources function in accordance with the company’s human resource policies. Conducts/participates all legislative and operational training in line with group requirements and/or training department directives. Achieves and maintains good working relationships and cooperation with IT employees and company colleagues. In liaison with the training department of the HR division, provides users accessing core business applications with sufficient training and reference material in line with CLH policies and standard operating procedures.

Posted 2 weeks ago

Alteryx, Inc.

Information Security Analyst

Remote
Alteryx, Inc.United States - Remote

Alteryx is seeking an Information Security Analyst to join its Security Trust team. This role involves supporting security assurance workflows, including customer security reviews and third-party risk assessments. The ideal candidate will analyze security information, enhance processes, and leverage artificial intelligence tools. You will contribute to building customer trust and ensure compliance across security and privacy domains. This position offers an opportunity to grow in various aspects of security assurance while working in a dynamic environment focused on innovation and excellence.

Posted 2 weeks ago

Atlas Technica

Information Security Analyst

Remote
Atlas TechnicaKyiv, UA, Manila, PH

Title: Information Security Analyst Reports to: Chief Information Security Officer Department: Information Security Location: Kyiv, Ukraine – Remote Term: Full-time About Atlas Technica Atlas Technica’s mission is to shoulder IT management, user support, and cybersecurity for our clients, who are hedge funds and other investment firms. Founded in 2016, we have grown year over year through our uncompromising focus on service. We value ownership, execution, growth, intelligence, and camaraderie. We are looking for people who share our Core Values, thrive, and contribute to this environment while putting the customer first. At Atlas Technica, we offer a competitive salary, comprehensive benefits, and great perks to our global Team. We strive to maintain a professional yet friendly environment while promoting professional and career development for our Team Members. Join Atlas Technica now! Position Overview We are seeking an Information Security Analyst to join our growing Information Security team. This is a highly technical role focused on strengthening the security posture of Atlas Technica and our clients through vulnerability management, risk and compliance activities, security hardening, monitoring, and incident support. Working closely with the Chief Information Security Officer and cross-functional teams, the Information Security Analyst will identify security risks, coordinate remediation efforts, support due diligence and compliance initiatives, improve security configurations, and help develop scalable approaches to vulnerability and incident management. The successful candidate will combine strong cybersecurity fundamentals with analytical thinking, technical problem-solving, automation skills, clear communication, and the ability to work independently. As the Information Security function continues to evolve, this role will provide opportunities to take on greater responsibility and contribute to the development of Atlas Technica’s security practices and standards. Position Responsibilities: Review vulnerability reports, investigate findings, recommend scalable remediation approaches, and track remediation progress through completion Coordinate with Support, NOC, Engineering, and other technical teams to implement security remediations while minimizing client impact and appropriately planning maintenance activities Develop or support scripts, automation, and repeatable processes that improve vulnerability remediation across multiple client environments Address vulnerabilities identified through internal and third-party vulnerability management platforms and apply relevant remediation strategies across applicable client environments Complete Due Diligence Questionnaires (DDQs) and coordinate accurate, timely responses to security and risk-related information requests Review findings from risk assessments and penetration testing, identify appropriate remediation actions, and participate in Business Impact Analyses and tabletop exercises Measure and improve alignment with Microsoft security benchmarks, including Microsoft Intune configurations, while identifying opportunities to strengthen workstation, cloud, infrastructure, and security configurations Support system hardening initiatives across endpoints, cloud environments, identity, and other security technologies Support ongoing SOC 2 and security operations activities, including test restores, KnowBe4 phishing and training reviews, SIEM log reviews, and related security-control activities Assist with cybersecurity incident response, investigation, remediation, and follow-up activities Partner with the NOC and outsourced SOC resources to develop, maintain, and improve security remediation runbooks and response procedures Maintain accurate security documentation, tickets, remediation records, and supporting evidence while contributing to continuous improvement initiatives across the Information Security function Requirements: Strong understanding of cybersecurity principles, security controls, risk management, and industry security practices Experience with vulnerability management, vulnerability analysis, remediation, and tracking Familiarity with Microsoft Intune, Microsoft security benchmarks, and endpoint or cloud security configuration Experience working with security technologies such as SIEM platforms, IDS/IPS solutions, vulnerability scanners, or similar security tools Experience with RMM, SOAR, or other automation and security-orchestration platforms Scripting or automation experience with the ability to develop scalable approaches to security remediation and operational tasks Experience creating and maintaining technical documentation, security procedures, and remediation runbooks Strong analytical, troubleshooting, and problem-solving skills with the ability to investigate findings and recommend practical remediation strategies Strong written and verbal communication skills with the ability to collaborate effectively across technical and non-technical teams Ability to work effectively both independently and collaboratively within a remote, fast-paced environment while managing multiple security priorities Desirable Qualities: Experience working within a Managed Service Provider environment Experience supporting security or compliance activities in a multi-client or highly regulated environment Exposure to SOC 2, penetration testing, security assessments, due diligence, or related compliance initiatives Relevant cybersecurity, Microsoft, or cloud certifications such as AZ-500, SC-900, SC-300, CompTIA Security+, or similar credentials Atlas Technica is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender, sexual orientation, gender identity, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

Posted 2 weeks ago

EA

Senior Information Security Engineer

Remote
eMoney AdvisorRemote

The Senior Information Security Engineer at eMoney Advisor is responsible for the management and operational availability of a 24/7 infrastructure, ensuring the confidentiality and integrity of sensitive data. This hands-on role involves risk analysis, compliance monitoring, and collaboration with various business units to enhance security policies and procedures. The candidate will also support security software, facilitate audits, and respond to potential data breaches, contributing to the company’s commitment to security and data integrity.

Posted 4 days ago

O

Information Security Engineer (R14207)

Remote
OportunRemote - MX

ABOUT OPORTUN Oportun (Nasdaq: OPRT) is a mission-driven financial services company that puts its members' financial goals within reach. With intelligent borrowing, savings, and budgeting capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $21.3 billion in responsible and affordable credit, saved its members more than $2.5 billion in interest and fees, and helped its members set aside an average of more than $1,800 annually. WORKING AT OPORTUN Working at Oportun means enjoying a differentiated experience of being part of a team that fosters a diverse, equitable and inclusive culture where we all feel a sense of belonging and are encouraged to share our perspectives. This inclusive culture is directly connected to our organization's performance and ability to fulfill our mission of delivering affordable credit to those left out of the financial mainstream. We celebrate and nurture our inclusive culture through our employee resource groups. POSITION OVERVIEW The Information Security Engineer will lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments. This role is responsible for identifying, investigating, containing, and remediating security incidents while correlating data from SIEM, EDR, cloud, identity, and network security tools. The position partners closely with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents, communicate risk, and improve the organization’s security posture. The ideal candidate has hands-on experience with incident response, threat hunting, detection engineering, and digital threat protection, along with knowledge of Windows, Linux, AWS, Active Directory, networking, and modern identity-based attacks. This role also supports continuous improvement through automation, AI-assisted security workflows, detection tuning, playbook development. Experience with cloud security, Kubernetes, Wiz, SOAR, purple teaming, fraud investigations, and third-party takedowns is preferred. WHAT YOU’LL DO Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field, or 2-5 years of experience in Security Operations, Incident Response, Digital Threat Protection, Threat Intelligence, Cyber Forensics, or Detection Engineering. Experience leading and coordinating cybersecurity investigations from initial detection through containment and remediation. Experience with SIEM platforms such as Splunk for investigation, detection engineering, and threat hunting. Experience investigating incidents across cloud, endpoint, identity, SaaS, and network environments. Experience analyzing telemetry from EDR, firewalls, identity providers, proxies, cloud platforms, email security solutions, and authentication systems. Strong understanding of Windows, Linux, Active Directory, Entra ID (Azure AD), AWS IAM, and modern identity attacks. Working knowledge of networking fundamentals, including TCP/IP, DNS, HTTP/S, SMTP, VPNs, and common enterprise architectures. Experience performing root cause analysis and correlating activity across multiple security technologies. Ability to develop clear executive summaries and communicate technical findings to both technical and non-technical stakeholders. Experience collaborating across Engineering, Infrastructure, Fraud, Legal, , Communications, and Product teams during investigations. Strong documentation skills for investigations, incident timelines, playbooks, and lessons learned. Continuous learning, security automation, and process improvement. WHO YOU ARE / WHAT YOU BRING Experience leveraging AI-assisted security tools and workflow automation to improve investigation efficiency, threat hunting, detection engineering, and documentation Demonstrate ability to identify repetitive operational tasks suitable for automation and implement AI-enabled workflows that improve analyst productivity without reducing investigation quality Experience in conducting purple team exercises Coordinate external takedowns and threat remediation with third-party providers. Investigate suspicious activity in AWS, Kubernetes, GitHub, SaaS platforms, and identity systems. Experience using Wiz Cloud Native Application Protection Platform (CNAPP) Experience conducting Threat Hunting using the MITRE ATT CK framework. Experience developing, tuning, or maintaining security detections and SIEM use cases. Experience with SOAR platforms and security automation. Experience conducting fraud investigations or partnering with Fraud Operations. Experience investigating Account Takeover (ATO), payment fraud, synthetic identity fraud, or cyber-enabled fraud. Security certifications such as GCIH, GCTI, AWS Security Specialty, Security+, or equivalent. #LI-REMOTE #LI-GK1 We are proud to be an Equal Opportunity Employer and consider all qualified applicants for employment opportunities without regard to race, age, color, religion, gender, national origin, disability, sexual orientation, veteran status or any other category protected by the laws or regulations in the locations where we operate. California applicants can find a copy of Oportun's CCPA Notice here: https://oportun.com/privacy/california-privacy-notice/ . We will never request personal identifiable information (bank, credit card, etc.) before you are hired. We do not charge you for pre-employment fees such as background checks, training, or equipment. If you think you have been a victim of fraud by someone posing as us, please report your experience to the FBI’s Internet Crime Complaint Center (IC3).

Posted 1 week ago

KPA

Senior Information Security Engineer

Remote
KPALafayette, CO

Position Description: KPA is seeking a Senior Information Security Engineer to serve as the senior technical counterpart to the Director of Security Technology. This role owns KPA's security platforms, cloud security, identity, automation, and technical security initiatives. The ideal candidate is a hands-on security engineer with strong cloud and infrastructure experience who can independently lead complex security projects, partner effectively with IT Operations and DevOps, and continuously improve KPA's security posture. Responsibilities: Own KPA's enterprise security platforms, including CrowdStrike, Rapid7 (InsightIDR, InsightVM, InsightAppSec, MDR), Cisco Umbrella, Cisco Duo, KnowBe4, and related technologies. Lead vulnerability management and remediation, endpoint security, identity security, privileged access, penetration testing, and security hardening initiatives. Lead security incident response, investigations, containment, remediation, and post-incident reviews. Own the ongoing operation of SOC 2 controls, security audit requirements, and technical compliance initiatives. Own Cisco Meraki security, VPN infrastructure, network security controls, and secure cloud connectivity. Secure Azure, AWS, Microsoft 365, Entra ID, AWS Identity Center, Auth0, and cloud-native workloads using modern security best practices. Administer and improve identity governance across Microsoft Entra ID, Cisco Duo, AWS Identity Center, Auth0, SSO, SCIM, Conditional Access, PIM, privileged accounts, service accounts, and authentication architecture. Partner with DevOps to integrate security into CI/CD pipelines, Infrastructure as Code, containers, Kubernetes, and cloud workloads, including SAST, DAST, Snyk, and other application security technologies. Own and continually improve KPA's cloud security posture management, workload protection, identity controls, logging, alerting, detection engineering, and remediation processes. Own email security across Microsoft 365, SendGrid, Amazon SES, SPF, DKIM, DMARC, and phishing protection. Build security automation using PowerShell, Python, Microsoft Graph, REST APIs, and AI-assisted development. Lead security assessments for new vendors, SaaS platforms, cloud services, and third-party integrations; administer third party vendor management (TPVM) and support ongoing vendor risk management. Administer and improve KPA's security awareness program, security policies, standards, and technical procedures. Support AI security and governance initiatives, including ChatGPT Enterprise, Claude, MCP, and emerging AI technologies. Support security architecture reviews for new cloud services, platforms, integrations, and technical initiatives. Proactively identify security gaps, technical debt, and opportunities to improve KPA's security posture through automation, AI, and modern engineering practices. Qualifications: 5+ years of experience in security engineering, cloud security, infrastructure security, or a related senior technical role. Strong knowledge of identity security, endpoint security, vulnerability management, network security, incident response, and zero trust principles. Experience securing Azure, AWS, Microsoft 365, Entra ID, Windows, and Linux. Familiarity with CI/CD pipelines, Kubernetes, container security, application security scanning, and DevSecOps practices. Scripting and automation experience using PowerShell, Python, REST APIs, or similar technologies. Experience supporting SOC 2 NIST CSF or comparable security and compliance frameworks. Relevant certifications such as CompTIA Security+, CISSP, CCSP, AWS Certified Security, or equivalent certifications are preferred. Excellent communication, documentation, project leadership, and problem-solving skills. Bachelor's degree in Computer Science, Information Technology or Cybersecurity or equivalent experience. Success Criteria: Work ethic that aligns with KPA's core values: Trust: earning trust through integrity, expertise, and acting in the client's best interest. Innovation: continuously seeking out ways to better serve clients. Excellence: holding ourselves to high standards in everything we do. Results: moving with purpose to deliver meaningful outcomes. Owns and continually improves KPA's enterprise security platforms and technical security controls. Improves KPA's security posture across endpoints, identity, networking, cloud, and DevOps environments. Delivers complex security initiatives with strong planning, communication, documentation, testing, and post-implementation validation. Reduces manual security work through automation and modern engineering practices. Serves as the senior escalation point for complex security incidents and technical security issues. Partners effectively with IT Operations and DevOps to embed security into operational and development workflows. Physical Requirements: Physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Working at a computer typing and view a screen - Constantly Stationary sitting or standing - Constantly Visual Recognition - Constantly Hearing/Listening - Occasionally Communicating verbally and/or in writing - Occasionally Travel - Seldom Compensation: Annual base salary range between $110-150k commensurate with experience. Bonus potential of 10% annually. This is a full time, exempt position.

Posted 2 weeks ago

UpGuard Inc.

Chief Information Security Officer

Remote
UpGuard Inc.Sydney

Who are we? At UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we are scaling our infrastructure to process 100 billion risk signals daily. This isn’t just growth; it’s a total reimagining of how the world manages cyber risk. We build the Cyber Risk Posture Management (CRPM) platform that security teams actually love. By integrating security ratings, threat intel, and agentic AI, we empower organisations to stay ahead of an ever evolving attack surface. We aren’t just building another tool; we’re defining a category. We provide the autonomy to ship world-class technology and the resources to do it at a global scale. Where does this role fit in? This is not a conventional CISO role, and we'd rather say that up front than have you discover it in week three. You will own the entire enterprise technology stack — security and infrastructure, identity, end user compute, networking, cloud platform, and the technology and physical security services behind our workspaces. Security is the substrate, or underlay, for that stack - not a separate function that reviews someone else's work. If you have run infrastructure or operations at scale and layered security over it, this remit will feel natural. If your background is governance-first, it won't. The environment you're inheriting has been run deliberately lean for through start-up and scale-up, and it is opinionated by design. There is no Microsoft directory, productivity, or desktop footprint anywhere in the estate — Google Workspace, Okta, macOS and ChromeOS, managed browser for BYOD. Attack surface has been controlled by refusing to acquire it. We want that philosophy continued and extended, not unwound. You'll lead a team - currently nine FTE in size, across four functions: IT Operations, Security Operations, Cloud Platform Engineering and GRC. Your first structural job is maturing security operations to serve both enterprise and product systems — deeper investment in Google SecOps and our n8n automation platform to lift analytics, orchestration and response well beyond what a team this size would normally reach. And because our product is the leading Cyber Risk Posture Management platform, you are customer zero. You and your team run UpGuard Cyber Risk harder than any of our customers do, turning what you learn into use cases Sales and Customer Success can take to market and signal Product can build on. That is a real, recurring part of the job, not a nice-to-have. You'll report directly to the CEO, with a defined transition period alongside the outgoing CISO. Details of the remit are below. What will you do? Own the full technology and security remit. Enterprise infrastructure, security, identity, applications, and workplace technology under a single accountability. No handoffs, no shared ownership of outcomes Lead and grow three functions. IT Security Operations, Cloud Platform Engineering, and GRC. Coach the existing leaders, set the technical bar, and build the team you need beneath you — while holding the line on lean Mature security operations. Build detection, analytics, orchestration and response capability that covers both enterprise and product systems. Drive investment into Google SecOps and n8n so that automation, not headcount, carries the load Own identity end to end. IAM across our GCP project estate and identity governance and administration for the entire global workforce — joiner/mover/leaver, entitlement review, privileged access, and OAuth consent risk (which, fittingly, we control with our own User Risk product) Own the network and cloud perimeter. ZTNA as the strategic access model, GCP perimeter security and networking Own end user compute globally. A predominantly macOS fleet with selective use of ChromeOS and enterprise managed browser services for BYOD. Device provisioning and retrieval across all operating regions Own the workspaces. Technology and physical security services for our offices — two today, potentially four by the end of 2027 across Australia and the US Own the compliance program. [Delegated to the Infosec GRC Lead] SOC-2 Type II today, with ISO 27001 targeted to facilitate European growth. Own the enterprise risk register, and the security function's inputs into vendor management and procurement Be customer zero. Use our own platform to its full extent and beyond, integrating with external systems via our Risk Automations product, feeding real operating experience back into Product, with co-creation of the cases and proof points that Sales and Customer Success will turn into new deals and expands Communicate at executive level. Brief the executive team, the Steering Committee and the Board, and be credible in front of customers and prospects when their security teams want to talk to ours What will you bring? We care far more about your track record than your tenure. The bar is a leader who has personally built and operated technology at scale, with security as the discipline layered over it. An infrastructure and operations foundation. You have run a data centre, an infrastructure function, or a substantial operations function — and security became your remit because you were already accountable for the systems. Architecture is where you're strongest Process discipline learned somewhere consequential. You've operated in an environment where failure had real consequences and process was the answer — financial services is a strong example of the discipline we mean, though not the only one. You know how to defend, operate, and structure A demonstrated ability to do a lot with a little. You have built and scaled capability without heavy resourcing, and you reach for automation before headcount. This is the single most important thing we're selecting for. If your effectiveness has depended on a large team, this role will frustrate you Genuine comfort owning infrastructure, security, applications and identity together. Not as a stretch, but as your natural shape Hands-on credibility. You are a leader, not a manager. You can architect a control, review a Terraform change, or lead an incident yourself — and you set the technical bar by example, not from the org chart Cloud-native depth. Substantial GCP experience strongly preferred; deep AWS or Azure experience considered where the architectural instincts transfer. Zero trust access, identity-centric security models, and modern SaaS estate management Ownership of a compliance program. You have carried SOC 2, ISO 27001, or equivalent as the accountable owner — through audit, not just through policy authoring The ability to absorb context at speed. You'll have a structured handover and then it's yours. We need someone who is oriented in weeks, not quarters Personal drive that doesn't need to be managed. High-energy, self-directed, and relentless about the work. You'll be given full ownership from day one, and we expect you to use it Comfort operating in a fast-paced, high-growth, remote-first environment What's in it for you? Monthly Lifestyle subsidy: Use this for financial, physical, and mental well-being WFH set-up allowance: To ensure you have the right environment to work in, we will help you get set up within your first 3 months at UpGuard $1500 USD annual Learning Development allowance: To support your career development, all team members will be able to expense development opportunities against this allowance Annual leave: PTO plus two additional UpGuardian leave days to give you time to recharge your batteries. 18 weeks paid Parental Leave: Irrespective of parenting role Personal Leave Allowance: This includes sick carer’s leave Fully remote working environment: While we have physical offices in Sydney Hobart, we do not mandate compulsory attendance Top-spec hardware: All team members will be provided with top-spec laptops for their role Generative AI subsidy: UpGuard provides paid subscriptions for all team members to access generative AI tools to support their work UpGuard is a Certified Great Place to Work® in the US, Australia, UK and India, establishing its position as a leading global technology employer. 99% of team members agree that UpGuard is a great place to work! Apply now to find out why! As an Equal Employment Opportunity and Affirmative Action Employer, qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. For applications to positions in the United States, please note, at this time, we can only support hiring in the following US states: CA, MD, MA, IL, OR, WA, CO, TX, FL, PA, LA, MO, or DC . Before starting work with us, you will need to undertake a national police history check and reference checks. Also, please note that at this time, we cannot support candidates requiring visa sponsorship or relocation.

Posted 3 weeks ago

Vibrant Emotional Health

Information Security Analyst I

Remote
Vibrant Emotional HealthRemote United States

#xa; Position Title: Information Security Analyst I Department: Technology Reports to: Information Security Manager Location: Remote Salary Range: $76,700 - $101,000 Vibrant Emotional Health’s groundbreaking solutions have delivered high quality services and support, when, where and how people need it for over 50 years. Through our state-of-the-art technology-enabled services, community wellness programs, and advocacy and education work, we are building a society in which emotional wellness can be a reality for everyone. Formerly the Mental Health Association of New York City (MHA-NYC), Vibrant Emotional Health’s groundbreaking solutions have delivered high quality services and support, when, where and how people need it for over 50 years. Through our state-of-the-art technology-enabled services, community wellness programs, and advocacy and education work, we are building a society in which emotional wellness can be a reality for everyone. Position Overview: The Information Security Analyst I is responsible for cloud, infrastructure and application security, incident response, auditing, and other relevant aspects of the program, as required. This role is involved in day-to-day operations of the in-place security solutions. The position plays a key role in protecting the confidentiality, integrity, and availability of all company data and systems. This may include the identification, investigation, and resolution of security incidents detected by those systems. Projects may include the implementation of new security solutions, participation in the creation and/or maintenance of policies, standards, baselines, guidelines, and procedures, as well as conducting vulnerability audits and assessments, and working with technology teams to update and maintain system security. The Security Analyst is expected to be fully aware of the enterprise’s security goals as established by its stated policies, procedures, and guidelines and to actively work towards upholding those goals. Duties/Responsibilities: Perform the deployment, integration, and initial configuration of all new security solutions and of any enhancements to existing security solutions in accordance with standard best operating procedures generically and the enterprise’s security documents specifically. Maintain up-to-date detailed knowledge of the Cybersecurity industry including awareness of new or revised security solutions, improved security processes, and the development of new attacks and threat vectors. Assist with recommending additional security solutions or enhancements to existing security solutions to improve overall enterprise security. Review existing cloud, on-prem, and end-user system configurations, and make recommendations to improve security posture Monitor all in-place security solutions for efficient and appropriate operations. Review logs and reports of all in-place devices, whether they be under direct control (i.e. security tools) or not (e.g. workstations, servers, network devices). Interpret the implications of that activity and devise plans for appropriate resolution. Respond to tickets for addressing security concerns, vulnerabilities, and end-user reported issues. Participate in investigations into problematic activity. Participate in the design and execution of vulnerability assessments, penetration tests, and security audits. Maintain up-to-date baselines using industry standard frameworks such as CIS and CSA for the secure configuration and operations of all in-place devices, whether they be under direct control (i.e. security tools) or not (e.g. workstations, servers, network devices). Maintain operational configurations of all in-place security solutions as per the established baselines and industry best practices. Provide on-call support for end users for all in-place security solutions. Partner with AppDev to identify and remediate vulnerabilities in applications Participate in the planning and design of enterprise security architecture. Participate in the creation of enterprise security documents (policies, standards, baselines, guidelines, and procedures). Participate in the planning and design of an enterprise business continuity plan and disaster recovery plan. Additional duties as assigned. Required Skills/Abilities: Proven analytical, troubleshooting and problem-solving abilities. Ability to effectively prioritize and execute tasks in a high-pressure environment. Good written, oral, and interpersonal communication skills. Ability to conduct research into IT security issues and products as required. Ability to present ideas in business-friendly and user-friendly language. Highly self-motivated and directed. Keen attention to detail. Team-oriented and skilled in working within a collaborative environment. Familiar with cloud security principles and best practices. Experience working with AWS IAM, infrastructure, security services, logging, and other serverless services. Familiar with AWS Security Hub Experience working with and implementing security controls and system configurations for technologies such as: AWS, Azure, GCP, Microsoft AD, Linux. Working technical knowledge of Cloud and SaaS security solutions and tools. Familiar with DevSecOps, Application Security, or other secure software development lifecycle methodologies. Some scripting experience with bash or Python Some experience with Incident Response or Penetration Testing as a nice to have Familiar with threat modeling methodologies General knowledge of security frameworks and controls such as: NIST (CSF, SP 800-53, SP 800-171), CIS, CSA, ISO27000. Some experience with security systems and tools that may include: Firewalls, WAF, SIEM, SOAR, MDR, IAM, PAM/PIM, Network Packet sniffers, Nmap, IDS/IPS, Vulnerability Management tools, SAST/DAST Burp Suite. Some experience with Encryption, Antivirus/Malware, Penetration Testing, Source Code Scanning. Basic understanding of IP, TCP/IP, and other network administration protocols. Required Qualifications: College diploma or university degree in Cybersecurity or other computer technology degree and/or two years equivalent work experience. One or more of the following certifications: Any AWS Certified Associate level certifications, AWS Certified Security - Specialty, GIAC Cloud Security Essentials (GCLD), CompTIA Security+, GIAC Security Essentials (GSEC). 2+ years of technical experience working in cloud, application, infrastructure, and/or network security required 1+ year of experience with AWS required 1+ year of experience with Cloud-based security technologies required 1+ year of experience with Linux operating systems required Physical Requirements: Must be able to remain in a stationary position 50% of the time Will constantly operate a computer and other office productivity machinery, such as a calculator, copy machine, and computer printer Will frequently communicate over video calls with internal and external stakeholders #xa; We determine base pay through a comprehensive review of skills, experience, education, certifications, geographic location, and other relevant factors. The range listed reflects the compensation parameters for the role and does not represent the full compensation package. A complete overview of compensation and benefits will be provided by the Talent Acquisition team during the hiring process. Full time employees will be eligible for excellent comprehensive benefits, including medical, dental, vision, supplemental income insurance, employer paid disability insurance, employer paid life insurance, pre-tax FSA for medical and dependent care, and 401K available. Studies have shown that women and people of color are less likely to apply for jobs unless they believe they are able to perform every task in the job description. We are most interested in finding the best candidate for the job, and that candidate may be one who comes from a less traditional background. Vibrant will consider any equivalent combination of knowledge, skills, education and experience to meet minimum qualifications. If you are interested in applying, we encourage you to think broadly about your background and skill set for the role. Vibrant Emotional Health is an equal opportunity employer. Applicants are considered for positions without regard to veteran status, uniformed service member status, race, creed, color, religion, gender, gender identity, sex, sexual orientation, citizenship status, national origin, marital status, age, physical or mental disability, genetic information, caregiver status or any other category protected by applicable federal, state or local laws. Please be aware that fictitious job openings, consulting engagements, solicitations, or employment offers may be circulated on the Internet in an attempt to obtain privileged information, or to induce you to pay a fee for services related to recruitment or training. Vibrant does NOT charge any application, processing, or training fee at any stage of the recruitment or hiring process. All genuine job openings will be posted on our careers page and all communications from the Vibrant recruiting team and/or hiring managers will be from an @vibrant.org email address.

Posted 1 week ago

How LiftmyCV Helps with Cybersecurity Jobs Search

LiftmyCV combines AI matching, resume generation, and auto-apply to streamline every step of your cybersecurity jobs job search-from discovery to interview.

Discover Cybersecurity Jobs Across 1,475+ Openings

AI scans millions of listings across 10+ job boards and surfaces the most relevant roles for your profile.

Learn more →

Create Job-Specific Materials for Cybersecurity Jobs Roles

Auto-generates tailored resumes and cover letters matched to each job description and ATS requirements.

Learn more →

Auto-Apply and Automate Cybersecurity Jobs Applications

Set your preferences and let the AI agent apply to matching jobs automatically, with full tracking and control.

Learn more →
Marina Galkina

Marina Galkina

Senior HR Manager, Lead Tech Recruiter, and Career Consultant

Remote Cybersecurity Salary Data (September 2026)

This section summarizes salary information from remote cybersecurity job postings listed on the page in September 2026. It reflects pay details where employers included them and can be read alongside 1,475+ active remote cybersecurity openings.

Average Salary

$127k

$158k

$190k

25th

50th

75th

Based on 1,475 roles currently tracked by LiftmyCV. Last updated on Aug 26, 2026

Salary Distribution

Entry43 jobs
$66k$93K$118k
Mid606 jobs
$118k$137K$183k
Senior827 jobs
$140k$173K$200k

Based on 1,475 roles currently tracked by LiftmyCV. Last updated on Aug 26, 2026

Cybersecurity Jobs salary ranges based on 1,475 job listings tracked by LiftmyCV
Experience Level25th PercentileMedian (50th)75th PercentileSample Size
Overall$126,950$157,500$190,0001,475
Entry-Level$65,612.5$93,250$117,8026
Mid-Level$117,500$137,220$183,20385
Senior-Level$140,000$172,850$200,250116

"Remote cybersecurity hiring in 2026 tends to split into a few clear lanes: cloud security, detection and response, application security, GRC, and security engineering tied to platform or infrastructure work. What changes in remote searches is not just location flexibility. Teams often screen harder for written communication, async judgment, and the ability to work across engineering, IT, and compliance without constant oversight. Candidates who show that mix usually move more cleanly through remote hiring loops."

Marina's Market Take

Senior HR Leader & Lead Tech Recruiter

How to Land a Remote Cybersecurity Job in 2026

Remote cybersecurity hiring usually moves by lane, so the first step is to position yourself inside a clear track by September 2026. A cloud security applicant should lead with AWS, Azure, IAM, CSPM, or container security work. An application security candidate should foreground secure SDLC, code review, SAST or DAST, and developer-facing work. A SOC or detection-focused candidate needs to show SIEM use, alert triage, incident response, log analysis, and the ability to write or tune detections. GRC, risk, and compliance applicants should be explicit about frameworks, audit support, policy ownership, and evidence collection.

For remote cybersecurity jobs, hiring teams often screen for proof that you can operate without heavy supervision. That means showing outcomes tied to remote-friendly work: documented investigations, runbooks, ticket handling, threat modeling notes, control mapping, vulnerability prioritization, or cross-functional security reviews completed across distributed teams. If you’ve worked across time zones, supported asynchronous incident response, or partnered with engineering, IT, legal, or compliance in a remote setup, say so plainly.

Your application should mirror the lane of the posting, not just the word cybersecurity. If a role centers on Okta, Sentinel, Splunk, EDR, PCI, FedRAMP, Kubernetes, phishing response, or third-party risk, put that exact environment near the top of your experience. Remote employers also filter hard on scope. Be specific about whether you handled endpoint security, identity, cloud posture, governance, product security, or security operations.

Search strategy matters too. Save separate searches for SOC, cloud security, GRC, application security, and security engineering roles, because remote listings often look similar until the tooling and ownership details show up. LiftmyCV fits naturally here by filtering remote cybersecurity roles by lane and prioritizing listings that match your actual tools, security domain, and level before you apply.

Required Skills

security operations
incident response
threat detection
vulnerability management
SIEM
threat intelligence
cloud security
network security
identity management
access control
security monitoring
risk assessment
security compliance
penetration testing
security engineering
application security
endpoint security
IAM
log analysis
firewall management
documentation
remote collaboration

Resume Tips

For remote cybersecurity jobs, lead with the work that proves you can secure systems without sitting in the same office as the team. Put security operations, cloud security, incident response, IAM, vulnerability management, GRC, or application security near the top if you’ve done it. Name the tools and platforms directly: SIEM products like Splunk or Microsoft Sentinel, EDR tools like CrowdStrike, cloud platforms like AWS or Azure, ticketing and case workflows in Jira or ServiceNow, and frameworks such as NIST, ISO 27001, SOC 2, or CIS Controls. If you hold Security+, CISSP, CISM, CySA+, or cloud security certs, don’t bury them.

Cut generic IT bullets that read like help desk work unless they clearly connect to access control, logging, hardening, phishing defense, audit evidence, or security monitoring. Remote cybersecurity resumes usually read better when each bullet shows scope, system, and result. Include distributed-team signals too: follow-the-sun response, async incident handoffs, remote audits, cross-time-zone coordination, or securing SaaS environments used by remote staff.

  • Weak: Responsible for monitoring security alerts and helping with incidents.
  • Strong: Monitored Splunk alerts across AWS and Okta, triaged phishing and endpoint incidents, and reduced repeat account-compromise cases by tightening MFA and conditional access policies in 2026.

If your background leans GRC instead of SOC work, swap detection language for audits, control testing, policy ownership, vendor reviews, and evidence collection. For application security, show code scanning, threat modeling, CI/CD checks, and developer remediation work rather than general software delivery.

How to Prepare for Interviews

Remote cybersecurity interviews usually test how you think through risk, not just what tools you've used. Expect a mix of technical screens, incident-response scenarios, and communication questions built around remote work. For security engineering or cloud security roles, be ready to explain how you’d harden AWS or Azure environments, investigate a suspicious login trail, or tune SIEM alerts without flooding the team with noise.

Common formats in 2026 include live troubleshooting, take-home labs, and scenario prompts such as, “Walk me through your response to a phishing-led credential compromise affecting remote employees.” If the role leans toward GRC, compliance, or security operations, prepare examples that show policy judgment, audit support, access review decisions, or how you handled exceptions across distributed teams.

Use a few detailed stories with scope, tools, and outcomes: what you detected, how you prioritized severity, which controls you changed, and what improved after remediation. For remote cybersecurity jobs, interviewers often pay close attention to documentation, escalation habits, and how clearly you explain technical risk in writing and on calls.

FAQ

Related Jobs

Land Your Next Cybersecurity Job with LiftmyCV's AI Agent

Use LiftmyCV to match with remote cybersecurity roles, tailor your resume to each opening, and auto-apply without repeating the same steps for every application. It helps you focus on better-fit jobs while handling the routine parts of the search.