Remote IT Security Engineer Jobs
Remote IT Security Engineer jobs are open across the U.S. in sectors from financial services and healthcare to cloud software and defense contracting, with distributed teams at both remote-first firms and established enterprises hiring at every level from junior analysts to senior architects. Employers hiring remotely right now include Defense Unicorns, WesBanco Bank, and Make-A-Wish Foundation of America. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 30+ Remote IT Security Engineer jobs








Job Title: Senior Manager, Information Security & IT
Reports To: Chief Technology Officer
Department: Technology – Information Security & IT
Work Location: Irvine, CA or US-Remote
About Genea
As leaders in property technology, Genea provides cloud-based physical security, submeter billing and on-demand HVAC solutions to over 1 million users across 39 countries. But Genea is more than just a workplace. We're a mission-driven team that collaborates, innovates, and engineers the proptech solutions of tomorrow to solve the challenges of today. We pride ourselves on fostering an environment of teamwork, transparency and authenticity, where you can be yourself. But don't take our word for it. Genea has been recognized as a Top Workplace in 2021-2025, with a rating of 4.3 out of 5 stars on Glassdoor. Our team members love our competitive benefits, including 401k matching, PTO, 100% paid parental leave, remote work options, and development/training opportunities.
Job Overview
Genea is looking for a hands-on Senior Manager, Information Security & IT to lead and continuously improve our cybersecurity and corporate IT programs.
Reporting to the CTO, this role will lead Genea's cybersecurity and IT programs across compliance, cloud and application security, incident response, identity and access management, and corporate IT.
Genea is already SOC 2 Type 2 compliant. This role will be responsible for continuously maintaining and maturing that program while helping drive additional cybersecurity and compliance initiatives, including ISO 27001 and other relevant frameworks as the business evolves.
We are looking for a cybersecurity leader who embraces AI, understands the evolving risks introduced by AI and agentic technologies, and can help Genea adopt AI securely while leveraging AI and automation to strengthen cybersecurity operations.
This is a hands-on leadership role for someone who can set direction, build scalable programs, lead the IT team and build out the cybersecurity function as needed, work closely with Engineering and other business teams, and remain involved in execution where needed.
Duties and Responsibilities
Cybersecurity Compliance & Programs
- Own and continuously mature Genea's cybersecurity compliance program, including SOC 2 Type 2, policies, controls, audit readiness, evidence management, risk assessments, cybersecurity awareness, and readiness for ISO 27001 and other relevant frameworks.
- Establish practical governance and guardrails for secure enterprise adoption of AI, including approved AI technologies, data protection, third-party AI risk, responsible usage, and emerging AI cybersecurity requirements.
- Establish measurable cybersecurity KPIs, KRIs, risk reporting, and provide regular program updates to the executive team.
Cloud & Application Security
- Drive Genea's cloud and application security program in close partnership with Engineering, DevOps, Platform, and Product teams, including secure-by-design practices for traditional applications as well as AI and GenAI capabilities.
- Strengthen cybersecurity across AWS and Azure, including IAM roles and permissions, least privilege, network controls, secrets management, encryption, logging, secure configurations, infrastructure hardening, and secure access to AI models, agents, APIs, and data.
- Mature secure SDLC and DevSecOps practices, including threat modeling, architecture reviews, SAST/DAST, dependency and container scanning, software supply-chain security, and controls for emerging AI risks such as prompt injection and excessive agent permissions.
- Own vulnerability management and coordinate internal and external penetration testing, prioritizing findings and driving remediation with Engineering.
Incident Response & Cybersecurity Operations
- Own cybersecurity monitoring, detection, investigation, and incident response across cloud, applications, endpoints, corporate systems, and AI-enabled services.
- Lead incident response from triage and containment through recovery, post-incident review, and corrective actions, while maintaining playbooks and tabletop exercises.
- Leverage AI and automation to improve threat detection, investigation, alert triage, and response, while monitoring emerging AI-enabled threats and attack techniques.
Identity, Access Management & Corporate IT
- Own corporate IT operations, including employee endpoints, MDM, SaaS applications, device lifecycle management, onboarding/offboarding, hardware and software provisioning, and employee IT support.
- Manage identity and access across corporate and approved AI systems, including SSO, MFA, privileged access, least privilege, IAM policies, access reviews, API credentials, and joiner/mover/leaver processes.
- Drive automation, standardization, patching, secure configuration, endpoint cybersecurity, access governance, and appropriate controls for enterprise AI tools and data usage.
Team Leadership & Development
- Lead and develop the IT team, establishing clear ownership, operational standards, and accountability across corporate technology and cybersecurity responsibilities.
- Build the cybersecurity team as the organization grows, identifying capability gaps and hiring or developing the right talent across areas such as cybersecurity engineering, operations, compliance, and risk.
Customer, Vendor & Cybersecurity Risk
- Own customer cybersecurity questionnaires, RFP responses, customer security reviews, third-party assessments, and vendor cybersecurity risk, including material AI-related vendor and platform risks.
- Represent Genea's cybersecurity program in customer and partner discussions and clearly communicate Genea's cybersecurity posture and controls.
- Identify and track material cybersecurity risks, drive remediation, and ensure appropriate executive visibility.
Qualifications
- 7+ years of experience across cybersecurity, information security, cloud security, application security, security engineering, or IT, including 2+ years in a leadership or management role.
- Strong technical experience with cloud-native SaaS environments, including AWS and/or Azure, IAM, application security, cloud security, vulnerability management, endpoint cybersecurity, and incident response.
- Experience with secure SDLC and DevSecOps practices, including threat modeling, penetration testing, SAST/DAST, dependency scanning, container scanning, and secrets management.
- Practical experience with SOC 2 Type 2, ISO 27001, NIST, or similar cybersecurity frameworks, including working with auditors, assessors, penetration-testing firms, and cybersecurity vendors.
- Working knowledge of AI/GenAI cybersecurity risks and secure AI adoption practices, including data protection, AI governance, LLM and agent security, and emerging threats such as prompt injection and excessive agent permissions.
- Strong understanding of modern identity and corporate IT environments, including SSO, MFA, endpoint management, MDM, SaaS administration, and privileged access, with the ability to communicate cybersecurity risk clearly to Engineering teams, customers, business leaders, and executives.
- Experience building or significantly maturing cybersecurity and IT programs within a growing SaaS technology company preferred.
- Experience implementing cybersecurity automation across CI/CD, cloud infrastructure, compliance, cybersecurity operations, and AI-enabled workflows preferred.
- Experience with technologies such as AWS, Azure, Okta, CrowdStrike or equivalent, SIEM, MDM, vulnerability-management platforms, and automated GRC tools preferred.
- Familiarity with AI cybersecurity frameworks and practices such as NIST AI RMF, OWASP GenAI/LLM guidance, AI red teaming, or securing agentic AI systems; CISSP, CISM, CCSP, or comparable cybersecurity certifications are preferred but not required.
What Success Looks Like
Success in this role means Genea maintains a strong, measurable, and continuously improving cybersecurity posture while supporting the speed and growth of the business.
Cybersecurity risks are clearly identified and prioritized, compliance programs remain audit-ready, cloud and application security practices are integrated into Engineering workflows, AI is adopted with appropriate cybersecurity guardrails, incidents are handled effectively, enterprise customers have confidence in Genea's cybersecurity program, and corporate IT provides employees with a reliable and secure technology environment.
The ideal candidate combines strong technical judgment, practical cybersecurity risk management, operational discipline, a builder's mindset, and a willingness to embrace AI thoughtfully. Cybersecurity should enable the business and Engineering teams to move quickly and securely rather than become a bottleneck.
Compensation
$160-180K annual base salary. This role is also bonus eligible.
This range reflects what Genea reasonably expects to pay for this role at the time of posting. Where an offer falls within the range depends on the candidate's experience, qualifications, and skills, and on internal equity.
Benefits
Full-time employees are eligible to participate in a comprehensive benefits program that includes medical, dental, and vision insurance; flexible spending accounts (FSA); life insurance; accidental death and dismemberment (AD&D) insurance; long-term disability (LTD) coverage; paid time off (PTO); and a 401(k) retirement savings plan. Eligibility is subject to plan terms and conditions.
E-Verify
Genea participates in E-Verify to confirm the employment eligibility of all new hires working in the United States. For more information about E-Verify, please visit the E-Verify website.
Equal Employment Opportunity
Genea is an equal opportunity employer. We make employment decisions based on qualifications, merit, and business need.
Genea does not discriminate on the basis of race, color, religion or religious creed, national origin, ancestry, citizenship status, sex (including pregnancy, childbirth, breastfeeding, and related medical conditions), sexual orientation, gender, gender identity or expression, age, physical or mental disability, medical condition, genetic information, marital status, military or veteran status, height, weight, or any other characteristic protected by applicable federal, state, or local law.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, compensation, benefits, training, transfer, leave of absence, and termination.
See All 30 Remote IT Security Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsRemote IT Security Engineer Job Market
Who's Hiring



Top Industries Hiring
- Technology & Software
- Consulting & Professional Services
What Employers Look For
The qualifications that appear most often in remote IT security engineer jobs.
- Bachelor's degree in computer science, information security, or a related field
- Active certifications such as CISSP, CEH, CompTIA Security+, or CISM
- Hands-on experience with SIEM platforms, firewalls, and intrusion detection systems
- Proficiency in vulnerability assessment tools and penetration testing methodologies
- Working knowledge of compliance frameworks including NIST, ISO 27001, and SOC 2
- Experience with cloud security controls in AWS, Azure, or Google Cloud environments
Tips for Your Remote IT Security Engineer Job Search
Apply early to remote roles that fit
Migrate Mate lists remote it security engineer openings from across the U.S. in one place, so you can find roles that match your skills and apply directly without sorting through unrelated listings.
Document your async communication skills visibly
Remote security teams rely on written runbooks, Slack threads, and Confluence documentation. Include examples of incident reports, policy drafts, or post-mortems you've written so hiring managers can see you can communicate security findings clearly without a meeting.
Build a home lab and show your work
Remote employers can't watch you work, so a documented home lab using tools like Splunk, Wazuh, or a cloud security sandbox proves hands-on competence. A GitHub repo or a write-up detailing what you built and what you learned makes your skills concrete and verifiable.
Prepare for async-first remote interviews
Many distributed security teams use asynchronous technical screens before live interviews. Practice explaining your approach to threat detection or vulnerability management in written form, and be ready for a take-home scenario involving log analysis or cloud misconfiguration review.
Remote IT Security Engineer Jobs: Frequently Asked Questions
How do I get a remote it security engineer job?
Remote it security engineer roles go to candidates who can demonstrate self-direction and clear written communication alongside technical depth. Distributed security teams screen for hands-on experience with SIEM platforms, endpoint detection tools, and cloud security frameworks because there's no one to shadow on day one. A home lab, an active GitHub, or a published incident response write-up signals you can work independently, which remote employers weigh heavily.
Which companies hire remote it security engineers?
Companies hiring remote it security engineers right now include Defense Unicorns, WesBanco Bank, and Make-A-Wish Foundation of America, based on current remote listings on Migrate Mate as of September 2026. Remote-first software firms, managed security service providers, and distributed financial services companies account for a large share of these openings.
Can you get a remote it security engineer job with no experience?
Yes, but remote entry-level security roles are harder to land than in-office ones because you must work independently from day one without on-site mentorship. Smaller remote-first companies and MSSPs occasionally hire juniors who hold CompTIA Security+, CEH, or equivalent certifications. A documented home lab, a CTF portfolio, or a completed cloud security training path can substitute for professional experience and open those doors.
Do you need a degree for remote it security engineer jobs?
Not always. Many remote employers prioritize certifications such as CISSP, CompTIA Security+, or AWS Security Specialty alongside demonstrable hands-on skills over a formal degree. Distributed teams care most about what you can do asynchronously and independently, so a strong portfolio of real security work, documented in writing, often carries as much weight as a computer science credential.
Which industries hire the most remote it security engineers?
The sectors hiring the most remote it security engineers are Technology & Software and Consulting & Professional Services, based on current remote listings on Migrate Mate as of September 2026. These industries run large distributed workforces and complex cloud environments that require dedicated security coverage regardless of where the engineer is located.
See All 30 Remote IT Security Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs