TL;DR — Our index held 661 live remote security engineering roles on 20 September 2026, and 20.0% published a salary range — one of the highest rates of any role family we track. The work is remote-friendly but unusually US-restricted: 31.5% name the United States. Certifications matter less than their marketing suggests: in a 2026 analysis of cybersecurity postings, fewer than one in fourteen required one.
The numbers first
Counted across live remote postings in our index on 20 September 2026, from companies' own careers pages.
| What we counted (20 September 2026) | Number |
| Live remote security engineering roles | 661 |
| Of those, roles that publish a salary range | 20.0% |
| Roles that name the United States among their hiring regions | 31.5% |
| Live remote postings in the index overall | 37,811 |
| Postings that publish a salary range (all roles) | 15.6% |
| Postings restricted to the United States only | 18.7% (7,089) |
Recognisable employers hiring remote security engineers include OpenAI, Elastic and Anthropic. The pay-transparency number is the cheerful one: at 20.0%, security postings are noticeably more likely to state a range than the market's 15.6%, partly because so many of them are subject to US state pay-transparency laws — which is also a hint about the second number.
Why security is a remote-friendly field — and where that stops
The day-to-day is portable. You read logs, write detections, review code, tune cloud policy, run an incident bridge, argue about a risk register. None of it needs a building. Security teams also cover incidents around the clock, so spread across time zones is an operational advantage rather than a concession: a follow-the-sun rota is easier to staff when people are genuinely in different time zones.
Three things pull in the other direction, and they explain why 31.5% of these postings name the US:
- Clearances and citizenship. Government, defence and their contractors need cleared staff, which means residency and citizenship requirements no employer of record can solve.
- Data residency and regulated customers. If your team touches regulated customer data, the company may be contractually obliged to keep access inside a jurisdiction.
- Background checks and device control. Almost every security role involves a background check, and many require a company-managed laptop shipped to you. Both are harder across borders.
If you are outside the US, read the geography line before anything else — our guide to what "remote, US only" really means covers how to tell a genuine legal restriction from a time-zone preference wearing a country's name.
"Security engineer" is five different jobs
The title covers tracks with different skills, different interviews and different remote prospects.
| Track | What you do | Remote outlook |
| Application / product security | Threat modelling, code review, secure SDLC, fixing classes of bug rather than instances | Strong — the work is code and design review |
| Cloud / infrastructure security | IAM, network policy, key management, hardening, infrastructure-as-code guardrails | Strong — the systems are already remote |
| Detection and response | Detections, alert triage, incident handling, forensics, threat hunting | Strong, but on-call and time-zone rota matter more than anywhere else |
| Governance, risk and compliance | Frameworks, audits, evidence, vendor risk, policy | Strong; also the most certification-heavy track |
| Offensive security | Penetration testing, red team, exploit development | Mixed — often consultancy work, sometimes with client-location constraints |
A posting titled "Security Engineer" can be any of these. The responsibilities list decides, and so does the tooling list: Terraform and IAM mean cloud security, SAST and threat models mean AppSec, SIEM and detection-as-code mean blue team. If you are moving from platform work, the overlap with remote DevOps and SRE roles is larger than the job titles suggest.
Which certifications employers actually ask for
This is the part of the field with the widest gap between marketing and postings.
When we checked in September 2026, a published analysis by the training-comparison site Programs.com of 2,694 unique cybersecurity job postings collected in April 2026 found that only 6.9% explicitly required a certification, while 25.2% mentioned one in some context. Within that minority, the pattern was clear:
| Certification | Share of postings mentioning it | How often a mention is a hard requirement |
| CISSP | 17.6% | About one mention in four |
| CISM | 7.7% | Lower |
| CISA | 6.0% | Lower |
| CompTIA Security+ | 3.2% | Highest of the major certs — roughly 41% of mentions |
| OSCP | 3.0% | About one mention in five |
Read that as a strategy, not a ranking. CISSP is the credential most likely to be named — shorthand for "senior enough" — while Security+ is the one most likely to be genuinely required, because it is the baseline credential for US government and defence-adjacent work. OSCP appears in fewer postings, and usually as a preference on offensive roles.
One 2026 change is worth knowing if you were planning a route to CISSP. ISC2 cut its CISSP experience-waiver list roughly in half for applications submitted from 1 April 2026, removing about thirty credentials including CEH, CISA, CRISC and OSCP. Security+, CySA+, CASP+/SecurityX, CISM, the Cisco security track, the ISC2 family, AWS Certified Security – Specialty and Microsoft's Cybersecurity Architect Expert were among those that survived. CISSP itself still asks for five years of paid work across two of its eight domains, with one year waivable by a qualifying credential or degree — so the waiver list is the difference between four and five years of experience, not a shortcut past them.
The practical conclusion: a certification is a tiebreaker and a keyword, not a qualification. If you need one credential to get past filters in a US-facing market, Security+ is the cheapest signal with the highest hard-requirement rate. If you are aiming at senior or GRC roles, CISSP is the one most often named. Neither substitutes for the thing every interview actually tests: whether you can reason about a system you have never seen.
Moving in from system administration
This is the most common entry path into security engineering, and it works because the mental model transfers. A sysadmin already knows how systems connect, how access is granted and revoked, where the fragile joints are, and what a normal day looks like on a network — which is exactly the baseline an attacker has to deviate from. The transition is about re-aiming that knowledge, not rebuilding it.
A realistic sequence:
- Take the security work already inside your current job. Patching cadence, access reviews, MFA rollout, log retention, the response when something looked odd. Write it down as security work, because it is.
- Pick a track. Cloud security is the most natural landing spot for an infrastructure background; GRC is the most natural for someone who has run audits and documentation.
- Learn to write code, not just scripts. Detection-as-code, infrastructure-as-code and automation are the daily medium of modern security teams, and it is the gap most often cited as the blocker for sysadmins.
- Get the credential your target track names. For cloud security that is usually a platform certification — AWS Security – Specialty, Azure AZ-500 or Google's Professional Cloud Security Engineer — matched to the platform your target employers run.
- Take a bridge title if it is offered. Security administrator, security analyst, or a platform role on a team with security ownership pays you while you build the CV that the engineer title asks for.
- Build one artefact you can walk someone through. A home lab with a detection you wrote, a threat model for a service you know, a hardening change you made and can explain. Interviews in this field reward specifics; our guide to preparing for a remote job interview covers how to set that story up.
Hiring conditions, honestly
ISC2's Cybersecurity Workforce Study published at the end of 2025 reported the global workforce gap growing 19% to 4.8 million, alongside continued budget pressure — a combination that produces a field with real demand and slow, picky hiring processes. Expect long loops, background checks that take weeks, and hiring managers who are looking for specific skills rather than headcount. The shortage is real; it is not a shortage of applicants.
How to search
- Search the track, not just the title. "Application security engineer", "cloud security engineer", "detection engineer", "security operations engineer" and "GRC analyst" all sit under the same umbrella and return different lists.
- Filter on geography first. With 31.5% of these roles naming the US, the location line eliminates more postings faster than any other filter if you are elsewhere.
- Read the on-call terms before the benefits. In detection and response, the rota is the job's real shape.
- Use the published ranges. At 20.0%, this is one of the better-documented role families for pay; our explainer on what a salary range in a job posting really tells you covers how to read a band before you name a number.
- Browse the role. Our remote security engineer page lists live openings from employers' own careers pages, and the security engineer salary page collects the ranges that postings actually state.
See which security roles fit your background and can hire where you live, scored against your own resume. Try it free.
FAQ
How many remote security engineer jobs are there?
Our index held 661 live remote security engineering roles on 20 September 2026, from companies' own careers pages. Of those, 20.0% published a salary range and 31.5% named the United States among the regions they can hire in.
Do you need a CISSP to get a security engineer job?
No. In an analysis of 2,694 cybersecurity postings collected in April 2026 by the training-comparison site Programs.com, only 6.9% explicitly required any certification. CISSP was the most frequently named — appearing in 17.6% of postings — but it is usually listed as a preference and works mainly as shorthand for seniority.
Which security certification is most often a hard requirement?
CompTIA Security+. It appears in fewer postings than CISSP, but when it is mentioned it is a stated requirement roughly 41% of the time, the highest rate among the major certifications — largely because it is the baseline credential for US government and defence-adjacent employers.
Can a system administrator become a security engineer?
Yes, and it is the most common entry path. The transferable part is knowing how systems connect and how access is granted and revoked. The parts to add are coding beyond scripting, a chosen track such as cloud security or GRC, a platform security certification matched to your employers' stack, and one artefact you can walk an interviewer through.
Why are so many remote security jobs restricted to the United States?
Three reasons: clearance and citizenship requirements in government and defence work, data-residency obligations to regulated customers, and the background checks and managed devices that almost every security role involves. That is why 31.5% of the remote security roles we counted name the US among their hiring regions, against 18.7% of all remote postings being US-only.