Remote Information Security Officer Jobs
Remote information security officer jobs are in active demand across the U.S., with remote-first firms and distributed teams hiring for these roles in sectors like financial services, healthcare technology, and enterprise software. Employers hiring remotely right now include Gainwell Technologies, Vanta, and Transact Campus. See the openings below and apply to the ones that match your experience.
Find JobsOverview
Showing 5 of 8+ Remote Information Security Officer jobs











The role:
You will be the operating second to the CISO and own the bank-entity scope of Mercury's 2LOD Information Security program. You'll be the person who keeps the program examiner-ready by default: coherent policy architecture, evidenced controls, a credible gap-remediation track record, and a tested incident response program with documented exercise history.
This is not a research or strategy role. It is a build-and-defend role. You will sit across the table from OCC examiners, FFIEC IT audit teams, our Chief Risk Officer, and the board's risk committee, and you will be expected to answer for every line in our policies and every status in our control inventory.
Mercury is a fintech company, not an FDIC-insured bank. Banking services provided through Choice Financial Group and Column N.A., Members FDIC
What you'll own:
- Bank-entity 2LOD InfoSec program. Governance, policy, risk, and oversight scoped to the chartered bank.
- Examiner posture. OCC, FFIEC, FDIC and FRB examiner inquiries; ownership of the examiner-ready narrative; coordination of the evidence.
- FFIEC control remediation. Lead remediation of identified FFIEC IT control deficiencies to charter readiness ahead of the OCC pre-opening examination.
- Policy architecture. Carry the bank-scoped policy stack (Policy / Standard / Procedure), including ratification cycles, MRCC memos, and board approvals.
- BC/DR. Partner with the Chief Risk Officer on bank continuity, resilience, and recovery, including tabletop exercises and full-scale drills.
- Audit and assurance. Manage relationships with internal audit (3LOD) and external assessors (SOC 2, FFIEC CAT, regulator-led IT examinations).
- Third-party risk. Ensure TPRM evidence holds up to bank-grade scrutiny for critical service providers and material outsourcing arrangements.
- Team development. Coach and grow the GRC sub-team; run a recurring training cadence; build the bench depth a national bank requires.
What we need:
- 8+ years in Information Security, with 3+ years inside a regulated bank, trust bank, or de novo bank charter effort. Mercury is a startup chartering a national bank — this experience is non-negotiable.
- Deep FFIEC and OCC fluency. You have deep working knowledge of the FFIEC CAT, the FFIEC IT Examination Handbook, BSA/AML IT supervisory expectations, and the OCC Heightened Standards.
- Direct examiner-facing experience. You have defended a control to an OCC, FDIC, or Federal Reserve examiner. You know what good evidence looks like before it gets challenged.
- Policy and standards craft. You can draft a board-ratifiable policy and the supporting standards stack that operationalizes intent, not just satisfies a checklist.
- Operating discipline. You run cadences, write status that survives executive review, and maintain currency of controls, evidence, and risk registers.
- 2LOD instinct. You understand the three-lines-of-defense model and have served in the oversight role.
What we'd love:
- Prior Deputy CISO or equivalent senior 2LOD role at a national bank, trust bank, or large credit union.
- Charter or de novo bank experience — if you've stood one up before, that is a meaningful advantage here.
- Strong technical baseline, you don't need to be an engineer, but you should be able to challenge an architecture review and read an incident timeline credibly.
- CISSP, CISM, or CRISC
What success looks like:
- At 30 days - You have developed working knowledge of Mercury’s FFIEC IT control inventory and roadmap, every in-flight policy draft, and met one-on-one with the GRC team. You can speak to the top ten risks in the bank-entity program by name.
- At 90 days - You are running the weekly bank charter status cadence, leading examiner-readiness reviews, and personally accountable for at least three priority program tracks. The CISO is briefing the board and the MRCC with material you authored.
- At one year - The charter timeline is on track. The bank-entity Information Security program sustains supervisory-grade standards as a standing posture. You are the executive other functions consult to determine whether a security risk is material.
Why this role:
We are building a security program designed to protect Mercury and enable the business. Chartering a national bank does not change that philosophy. It does mean we need a Deputy who can hold the bar to OCC standards without losing the operating tempo that has defined Mercury since inception.
If you've been waiting for a chance to build the bank-side security program you wish you'd inherited, this is it.
Compensation:
The total rewards package at Mercury includes base salary, equity (stock options), and benefits.
Our salary and equity ranges are highly competitive within the SaaS and fintech industry and are updated regularly using the most reliable compensation survey data for our industry. New hire offers are made based on a candidate’s experience, expertise, geographic location, and internal pay equity relative to peers.
Our target new hire base salary ranges for this role are the following:
- US employees in New York City, Los Angeles, Seattle, or the San Francisco Bay Area: $269,700 - 353,950
- US employees outside of the New York City, Los Angeles, Seattle or the San Francisco Bay Area: $242,700 - 318,550
Mercury values diversity & belonging and is proud to be an Equal Employment Opportunity employer. All individuals seeking employment at Mercury are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, sexual orientation, or any other legally protected characteristic. We are committed to providing reasonable accommodations throughout the recruitment process for applicants with disabilities or special needs. If you need assistance, or an accommodation, please let your recruiter know once you are contacted about a role.
See All 8 Remote Information Security Officer Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsRemote Information Security Officer Job Market
Who's Hiring
- Gainwell Technologies3

- Vanta2

- Transact Campus1

- Mercury Intermedia1

- Information Technology Senior Management Forum1
Top Industries Hiring
- Technology & Software7
- Healthcare & Medical Services3
- Cybersecurity2
What Employers Look For
The qualifications that appear most often in remote information security officer jobs.
- CISSP, CISM, or equivalent security certification strongly preferred or required
- Proven experience building or leading an information security program
- Deep knowledge of risk management frameworks such as NIST CSF or ISO 27001
- Familiarity with regulatory compliance requirements including SOX, HIPAA, or PCI-DSS
- Experience conducting or overseeing security audits and vulnerability assessments
- Bachelor's degree in information security, computer science, or a related field
Tips for Your Remote Information Security Officer Job Search
Show async security communication skills clearly
Remote information security officer roles depend on written communication for policy documentation, incident reports, and cross-team risk briefings. Include examples of security documentation, written risk assessments, or compliance summaries you have produced independently to demonstrate you can lead without in-person coordination.
Apply early to remote roles that fit
Migrate Mate lists remote information security officer openings from across the U.S. in one place, so you can find roles that match your background and apply directly without sorting through location-filtered listings on general job boards.
Highlight remote-relevant security tools and frameworks
Employers hiring remotely prioritize candidates with direct experience in cloud security platforms, zero-trust architecture, and remote access control tools like VPN management and identity governance systems. Name the specific platforms you have worked with so hiring managers can match your skills to their distributed environment.
Prepare for distributed-team interview formats
Remote information security officer interviews often include written scenario exercises, asynchronous video responses, or multi-stage panel calls across time zones. Practice articulating your incident response process and governance approach in writing, not just verbally, since many remote teams use written assessments to evaluate judgment and communication before extending offers.
Demonstrate self-directed security program ownership
Remote employers need information security officers who can drive compliance programs, vendor risk reviews, and policy updates without waiting for in-person direction. Describe specific programs you have owned end to end, including how you prioritized work, escalated risks, and kept distributed stakeholders informed without relying on physical presence.
Remote Information Security Officer Jobs: Frequently Asked Questions
How do I get a remote information security officer job?
Target companies that already run distributed security teams, because they have established workflows for remote governance, incident response, and compliance reviews. Remote employers screen for self-direction, clear asynchronous written communication, and hands-on experience with cloud security frameworks and remote access controls. Certifications like CISSP or CISM, paired with documented examples of managing risk programs independently, give candidates a clear edge.
Which companies hire remote information security officers?
Companies hiring remote information security officers right now include Gainwell Technologies, Vanta, and Transact Campus, based on current remote listings on Migrate Mate as of June 2026. Remote-first technology firms, distributed financial services companies, and healthcare IT organizations are among the most consistent hirers of information security officers in fully remote arrangements.
Can you get a remote information security officer job with no experience?
Yes, but remote entry-level information security officer roles are harder to land because employers expect you to manage security responsibilities independently without in-office supervision. Smaller remote-first startups and managed security service providers are more open to candidates early in their careers. Demonstrating hands-on lab work, relevant certifications, and strong written communication skills can open the door when direct experience is limited.
Do you need a degree for remote information security officer jobs?
Not always. Remote employers weigh certifications like CISSP, CISM, or CompTIA Security+, demonstrated experience securing cloud environments, and a record of managing compliance programs alongside or instead of a formal degree. Candidates who can show they have led security initiatives, written clear policy documentation, and worked effectively across remote teams often compete strongly regardless of their educational background.
Which industries hire the most remote information security officers?
Most remote information security officer openings sit in Technology & Software, Healthcare & Medical Services, and Cybersecurity, per current remote listings on Migrate Mate as of June 2026. These sectors hire information security officers remotely because their distributed teams require consistent oversight of access controls, compliance obligations, and incident response across geographically scattered workforces.
See All 8 Remote Information Security Officer Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs