A security operations centre, the internal defence function most candidates picture
Photo by Evan Marvell on Unsplash
Back to the blog

Roles · City · 2026

Remote Security Engineer Jobs in 2026: Who Is Actually Hiring, and What They Pay

Standout Editorial Team13 min read ·

Remote security engineer jobs are openings for engineers who defend systems, build security products, or deliver security under contract, filled without a required office. Category matters more than count: on one deduplicated board, 64 of the 69 openings held by the six largest hirers sit at vendors, contractors or staffing firms. Five do not.

Snapshot, 2026-09-03Figure
Live remote listings, one deduplicated board833
Advertised salary band$133,000 to $195,000
Reported average total compensation$205,250
Top-hirer volume outside internal security teams64 of 69 openings
Projected employment growth, 2025 to 203521%
Median wage, information security analysts, May 2025$129,180

Sources: Haystack, Levels.fyi, BLS.

Three different jobs are wearing the same title

The six biggest hirers on that board are Check Point, SAIC, Zscaler, Apex Systems, AECOM and Upstart (Source: Haystack). Read that list slowly, because it is not a list of companies with unusually large security teams. It is a list of companies in three unrelated businesses.

A security engineer at a security vendor ships detection logic that other companies buy. The work is product engineering and success is measured in what customers deploy. A security engineer at a federal contractor works a contract vehicle where the compliance regime was written before anybody was hired, and the job is to satisfy it and evidence that it was satisfied. A security engineer at a product company argues with engineers who do not report to them about a risk that has not happened yet, and wins or loses on influence.

The interview loops diverge just as hard. Vendor interviews look like product engineering interviews with a domain layer on top, and the detection-writing exercise is the round that decides it. Contract-side loops weight certifications, clearance status and whether a candidate has worked inside an accreditation boundary, because those are contractually auditable and a hiring manager's opinion is not. Internal loops are the least standardised, and usually end on how a candidate would get an engineering team to do something inconvenient without escalating.

Most candidates typing this query are picturing the third job. The board mostly holds the first two.

Build security as a productDeliver security under contractDefend one company's systems
Who hires this waySecurity vendorsFederal and infrastructure contractors, and the staffing firms that supply themProduct and platform companies
Named on this boardCheck Point, ZscalerSAIC, AECOM, Apex SystemsUpstart
Measured onCustomer deployment, detection qualityCompliance satisfied and evidencedRisk reduced without authority
What the title buys nextVendor and product security rolesFurther cleared or contract workInternal security leadership

Before you read another listing: find out which of those three businesses the employer is in. It is answerable in about ninety seconds from the company's home page, and it determines the loop, the pay and what the next role after this one can be.

The composition, done as arithmetic nobody publishes

The counts are on the board. The addition is ours. Check Point holds 30 openings, SAIC 12, Zscaler 9, Apex Systems 7, AECOM 6 and Upstart 5, which totals 69 across the six largest hirers (Source: Haystack). Thirty-nine of those sit at two security vendors. Eighteen sit at two federal and infrastructure contractors. Seven sit at an IT staffing firm, which is the same contract work reaching the board through an intermediary. Five sit at the one product company on the list.

Sixty-four of sixty-nine.

Bound that properly before carrying it anywhere. It describes the head of the distribution, the six employers holding the most postings out of 833 live listings. The long tail is more product-company-heavy, because a company hiring one security engineer never appears on a top-hirers list. What the head tells you is where volume concentrates, and volume is what a candidate scrolling a board is exposed to.

The shape holds even though the names move. We captured the same board a day earlier, on 2026-09-02, and four of the six companies were different: DoorDash and Datadog each held six roles then and are off the list now, replaced by Apex Systems and Upstart. The vendor-and-contractor share was 57 of 69 on the first day and 64 of 69 on the second. The companies rotate weekly. What they are in business to do does not.

The federal weighting shows up in the metro data too. Dice's August 2026 report has Baltimore leading every US metro at 50% year-over-year growth in tech postings, attributed to defense and federal-adjacent cybersecurity work in the Baltimore-Washington corridor, with New York second at 32%. Vulnerability Management Engineer was among the titles growing more than 150% month-over-month (Source: Dice). The strongest security demand in the country is clustered around a procurement corridor.

Board totals are worth exactly one sentence of your attention: the same query returns 833 on this deduplicated board (Source: Haystack) and more than 9,000 on the largest aggregator, because they count reposts and syndicated rows differently.

The move here: count employers before you count postings. Six employers explain most of what you are seeing.

What the band says, and why the average sits above its ceiling

Advertised pay on that board runs $133,000 to $195,000 (Source: Haystack). The reported average total compensation for a security software engineer in the United States is $205,250 (Source: Levels.fyi). Put the two figures side by side and the ceiling loses. The average sits above the top of the advertised range, by roughly $10,000.

Those are not the same quantity, and the gap should be read for direction. An advertised band is what an employer types into a listing field, usually a base salary, usually set to be defensible across a wide population. The compensation figure is crowdsourced from people reporting their own packages, it includes equity, and the page carries no sample size and no date range, so treat the six-figure precision as a rounding of a self-selected sample rather than a measurement.

The direction survives the mismatch anyway. When an advertised ceiling for a whole board lands below the reported market average, the board is describing its own composition. Bands are how a company hiring thirty people at once controls cost and satisfies pay-transparency law. Equity-heavy product companies hiring one or two people are underrepresented in exactly the listings that set that ceiling.

There is a second reason the ceiling sits low. An employer posting thirty roles at once publishes one band covering all of them, which pulls the advertised top toward what the median hire in that batch will be paid. A company hiring a single staff-level security engineer negotiates on its own terms and frequently publishes no number at all.

Figure
Advertised floor, remote board$133,000
Advertised ceiling, remote board$195,000
Reported average total compensation$205,250
BLS median wage, information security analysts, May 2025$129,180

Read the employer before you read the range: the same posted number means different things at a vendor and at a Series C product company, and the second one is usually understating itself.

When a company briefs us on a security hire, the listing is frequently the least accurate document in the conversation. The band on the page was set by a compensation policy. What the hiring manager describes in ten minutes is a specific person with a specific history, and the number moves once that is on the table.

Racked server infrastructure, the systems a security vendor builds products against
Photo by Domaintechnik on Unsplash

The shortage you were promised was withdrawn by the people who measured it

For years, ISC2 published an estimate of the global cybersecurity workforce gap, and that number did more to shape how candidates think about this field than any other statistic in it. In the 2025 Cybersecurity Workforce Study it stopped. The organisation stated that it has not included an estimate of the workforce gap this year, because respondents now treat the need for critical skills as more important than the need for more people (Source: ISC2).

The figures in the same study explain the withdrawal. Fifty-nine percent of teams cite critical or significant skills needs, up from 44% the year before, and 95% report at least one skills need. At the same time 39% faced hiring freezes, 36% budget cuts and 24% layoffs, 33% say they lack the budget to staff their teams adequately, and 29% cannot afford to hire people with the skills they need (Source: ISC2).

That is not a labour market with more openings than people. It is a market with a great deal of unmet need and no money attached to it, which produces the experience candidates keep describing: a field supposedly desperate for them, and a search that goes nowhere. The demand is genuine and the budget is not approved.

Two limits on those numbers. The study surveyed 16,029 practitioners and decision-makers across North America, Latin America, Asia-Pacific and Europe, the Middle East and Africa, so it is a global picture being read here for a US market, and the US slice may sit either side of the average. It is also a survey of people who chose to respond. The withdrawal of the gap estimate carries none of that uncertainty. That was an editorial decision by the body that owned the number.

What that changes about your search: stop treating a posting as evidence that money exists. Ask, early and directly, whether the role is funded for this fiscal period and whether it survived the last budget cycle.

The freshness number on a job board is not measuring hiring

The board reported 464 of 809 listings added in the prior seven days when we captured it on 2026-09-02, and 191 of 833 when we captured it again on 2026-09-03 (Source: Haystack). The first reads as 57% of the board turning over in a week. The second reads as 23%.

We are not going to give you a weekly churn rate for this market, because the honest version of that number moved thirty-four points in twenty-four hours and the total listing count went up by 24 in the same window. Those two movements cannot both describe employer behaviour. Roughly 273 listings left the seven-day window on a single day while the board grew, which is the signature of bulk indexing rather than of hiring. The counter measures when the board ingested rows. Employer intent never enters into it.

That matters because the freshness sort is the one every candidate uses. Set it against what is known about posting quality. Greenhouse reported in December 2024 that in any given quarter, 18% to 22% of jobs posted on its platform are classified as ghost jobs, positions advertised with no intent to hire, and that three in five candidates say they suspect they have encountered one (Source: Greenhouse). That 18% to 22% is one platform's classification of its own inventory rather than an industry rate, the survey behind the second figure covers 2,500 workers across three countries including the UK and Germany, and the report is now two years old.

Combine them. A board where the newest rows are an indexing artifact, in a market with a known ghost-posting floor, means sorting by newest optimises for listings that nobody has confirmed are funded, including the board itself. Dice's August 2026 data makes the same case at market level: US tech postings were down 10% month-over-month and up 10% year-over-year (Source: Dice). Short-window movement here is noise at a scale that swamps the trend.

Reposts are detectable without special tooling. Search the job title plus the company name and count the distinct listing pages, then check whether the company's own careers page carries the role with an older date than the aggregator's. A role relisted three times in a quarter has an internal problem.

Do this before your next application: check the company's own careers page for the posting date and ignore the board's.

What we settle before we introduce a security engineer

The first thing we settle with a company hiring a security engineer is not seniority and it is not stack. It is what the security function is for. Is security a product this company sells, a compliance regime it has to satisfy, or an attack surface it has to defend. Companies answer that differently from how their own listing reads more often than in any other role we work on, because all three versions are legitimately called Security Engineer and the listing template has no field for it.

The question we ask to settle it is deliberately blunt: who does this person's work make safer, your customers or you. A vendor answers customers without hesitating. A contractor answers whoever the contract names. A product company answers us, and then usually spends a minute revising its own job description out loud.

The cost of that collision is paid at the last round. A detection-engineering team at a vendor passes on a candidate whose entire career is internal incident response, and everyone involved experiences it as a skills verdict. It is a category mismatch neither side could see, because both documents used the same two words. The candidate spent four rounds being evaluated against a job they were never told they had applied for.

Concretely: we resolve the category before an introduction goes out, which is the difference between a candidate being assessed and a candidate being sorted. You can see how our matching works and what we do for candidates if you want the mechanics.

A federal government building, the procurement corridor where security demand concentrates
Photo by Harold Mendoza on Unsplash

Who the remote security board is actually good for

If you want vendor-side detection, product security or research, the board is genuinely good. That is where the volume is, two vendors alone account for 39 of the 69 openings at the top of it, and the roles are real product engineering jobs. Go and use it.

If you hold a clearance, or would take a contract role to get one, the federal tail is the least contested part of this market. The demand is concentrated, geographically legible and growing. Most candidates route around it because contract work reads as a downgrade. At current volumes that is a mistake.

If what you want is an internal security function at a product company, the board is a poor instrument and no amount of application volume will fix it. Five of sixty-nine at the head is a composition problem, and a composition problem does not respond to effort. Those roles exist, they are just not concentrated anywhere you can scroll. They are filled through people who already know the hiring manager.

If you are changing careers into security or applying at entry level, this is a bad moment and you should hear it plainly. Thirty-nine percent hiring freezes and 29% of teams unable to afford the skills they need is a market that buys proven specialists and has stopped paying to train anyone. The 21% ten-year growth projection is real and it will not help you this quarter (Source: BLS). Build a demonstrable specialism first.

ProfileIs the board good for youWhat to do instead
Vendor-side detection, product securityYes, this is where volume sitsApply directly, target the two largest hirers
Cleared or clearance-eligibleYes, least contested segmentLook at the Baltimore-Washington corridor
Wants internal security at a product companyNoGet introduced, do not apply
Career-changer or entry levelNoBuild a specialism, revisit in two quarters

One limit worth stating: we work with US companies only, across the Bay Area, New York, Austin, LA and remote-US (Source: Standout). If you are searching from outside the US, this page has told you what the board looks like and we are not the answer to it.

The practical consequence: three of these four profiles are better served by being introduced than by applying, and only one of them is well served by the board this article is about.

FAQ

How many remote security engineer jobs are there?

One deduplicated board showed 833 live remote security engineer roles on 2026-09-03 (Source: Haystack). Totals vary by an order of magnitude across boards, from roughly 1,000 to more than 9,000, because they differ in how they handle reposts and syndicated listings.

What does a remote security engineer make?

Advertised bands on the remote board run $133,000 to $195,000 (Source: Haystack). Crowdsourced average total compensation for a security software engineer is $205,250, which includes equity (Source: Levels.fyi). The BLS median wage for information security analysts was $129,180 as of May 2025, a broader occupation that includes non-engineering roles (Source: BLS).

Is there still a cybersecurity talent shortage in 2026?

Not in the form candidates were told. The body that published the workforce gap estimate stopped publishing it in 2025, saying skills needs now outrank headcount needs. Fifty-nine percent of teams globally report critical or significant skills gaps while 39% are under a hiring freeze (Source: ISC2).

Who hires the most remote security engineers?

Security vendors and federal contractors lead by volume. On one board the largest hirers were Check Point with 30 openings, SAIC with 12 and Zscaler with 9 (Source: Haystack).

Is a security clearance required for remote security engineer jobs?

Not for most, but a meaningful share of the federal-adjacent volume carries clearance, citizenship or US-timezone requirements that the listing itself does not surface. Ask before the second round, not after the fourth.

The title is doing more work than the filter

Everything that makes this search hard is contained in the two words before "remote." Security engineer is one label stretched across three businesses that share a vocabulary and share nothing else, and the board sorts by neither. Read the employer first and the posting second.

[Get matched instead of applying at standout.work](https://standout.work)

We match US tech professionals with companies and introduce you directly to the founder. Free for candidates, first matches within a few hours of finishing your profile.

Field notes

Read more from the Standout blog.

Back to all articles