Remote Security And Compliance Jobs
Remote Security And Compliance jobs are open across the U.S. at remote-first firms, distributed tech teams, and regulated-industry companies building out their compliance functions without geographic constraints. Sectors including financial services, healthcare technology, and SaaS are actively hiring, and employers posting right now include Entrust Corporation, GuidePoint Security, and eBay. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 24+ Remote Security And Compliance jobs











Chameleon Integrated Services has expertise in operations management, quality systems, data operations and cybersecurity. We secure some of the most sensitive data for the Department of Defense and for other U. S. federal government agencies. We are known for the great care we take with clients and employees, and we believe in promoting from within.
Senior Azure Government Security & Compliance Architect
Position Overview
- Position Type: Part-Time Consultant / Technical Vetting & Compliance Authority
- Target Allocation: 8–10 hours/week average (Note: Workload rises substantially during security engineering phases, technical readiness reviews, and the structural execution of Deliverables 10, 11, and 12).
- Technical Reality: This is an elite compliance role. The security architecture, authorization documentation, and continuous monitoring controls are too complex to distribute casually among traditional software developers. You will hold complete technical ownership over the platform's defensive validation strategy.
- Location: Remote. May require occasional travel to Tallahassee based on sprint completion.
This platform will unify statewide oversight, tracking abnormal spending patterns, contract vulnerabilities, and fraud/waste/abuse risks across up to 35 state agencies. Because this is a high-visibility, firm-fixed-price (FFP) state government contract, you will maintain absolute technical accountability for establishing an infrastructure that aligns perfectly with state and federal statutory requirements, preparing the system for full production authorization and independent validation.
Principal Responsibilities
- Compliance Gap Analysis: Develop a comprehensive security compliance control crosswalk to identify, map, and remediate technical gaps against strict federal and state high-control baselines.
- Identity & Access Architecture: Define and enforce a granular, role-based access control (RBAC) framework and end-to-end user lifecycle management model aligned strictly to least-privilege principles and multi-factor authentication (MFA) enforcement.
- Audit Logging & Monitoring: Architect comprehensive audit logging, monitoring, and retention specifications for user actions, administrative events, system configurations, and raw data access layers to ensure absolute traceability.
- Configuration Assessment: Conduct exhaustive, formal reviews of cloud, network, storage, and application configuration baselines to actively identify, catalog, and fix misconfigurations.
- Vulnerability & Pentest Coordination: Manage internal and external vulnerability scanning protocols, orchestrate formal penetration testing events, and document the rigorous technical evidence confirming the resolution of high or critical findings.
- Supply Chain Vetting: Perform comprehensive third-party risk assessments, map vendor/sub-vendor code dependencies, and produce a verified Software Bill of Materials (SBOM) alongside a critical service provider register.
- Privilege Access Governance: Develop and execute structured privilege-access reviews to monitor elevated account allocations, analyze account activities, and mitigate credential risk exposure.
- Incident Response Integration: Design and integrate actionable incident response workflows, contact escalation paths, security event reporting routines, and vulnerability patch management lifecycles that conform to state policies.
- Authorization Package Compilation: Compile and validate all technical security artifacts, data-flow diagrams, system security plans (SSP-style), and readiness review dossiers required to clear independent state testing and ensure a seamless handover to the State.
- Experience Baseline: 10+ years of comprehensive information security engineering experience.
- Cloud Depth: 5+ years of dedicated, hands-on cloud security architecture, data environment hardening, or security automation work.
- Government Control Mastery: Documented history implementing and mapping controls against NIST SP 800-53 and NIST SP 800-171 within federal or state government systems.
- High-Control Baselines: Direct experience preparing systems for or operating within FedRAMP High or comparable high-control, highly regulated environments.
- Infrastructure Toolkit: Proven hands-on mastery of Azure and Entra ID security parameters, managed identities, automated secrets/key management, and Azure Key Vault configuration.
- Threat Management: Strong background executing vulnerability management lifecycles, structured incident response mapping, and formal configuration assessments.
- Supply Chain Architecture: Practical understanding of third-party risk assessment methodologies and familiarization with Software Bill of Materials (SBOM) compilation frameworks.
- Testing & Assessment: Verifiable history acting as a security control assessor or leading technical control validation assessments.
- Vetting & Location: Must be a U.S.-based citizen or resident. Must be able to successfully clear an FDLE Level II background screening (including fingerprinting) within 5 business days of contract award.
- Prior experience navigating Florida state government compliance frameworks, specifically referencing Florida Administrative Code Rule 60GG-2 and Section 282.318, Florida Statutes.
- Practical security engineering context handling CJIS or HIPAA regulated government data streams.
- Hands-on security containment and control configuration for Azure Databricks workspaces, Azure Data Lake Storage Gen2 (ADLS Gen2), and Power BI workspaces inside Azure Government environments.
- Proven experience compiling, submitting, or auditing formal FedRAMP authority to operate (ATO) authorization packages.
- Active premium industry credentials such as CISSP, CISM, or CCSP.
The State of Florida strictly evaluates and verifies all named staff experience for this contract. Generic resumes that only list generalized cybersecurity buzzwords or generic compliance tool lists without specific government framework context will be automatically rejected.
To be considered for this role, your resume must explicitly detail the following metadata for your past contract positions:
- The Government Customer: Explicitly name the agency and the high-control environment context (e.g., Federal Agency, Military Branch, State Department).
- The Specific Compliance Baseline: Detail exactly how you applied security standards, naming the specific NIST families, FedRAMP control layers, or state statutory rules you personally mapped.
- Architecture Scale & Complexity: Specify the exact size of the cloud network architecture, the number of distinct user roles or environments secure-mapped, and the precise project duration.
- Personal Engineering Contribution: Detail exactly what you personally built, assessed, or documented (e.g., "Authored the System Security Plan for a FedRAMP High environment," "Configured least-privilege Entra ID access policies for database storage").
- Deployment & Vetting Status: Explicitly state the true production, operational, or steady-state authorization status achieved by platforms under your security oversight.
- Quantifiable Results: Include the precise metrics achieved under your guidance, such as percentage of vulnerabilities remediated, independent audit pass rates, or system availability uptime markers.
“We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status”
Texting Privacy Policy
- Message type: Informational; you will receive text messages regarding your application and potentially regarding interview scheduling.
- No mobile information will be shared with third parties/affiliates for marketing/promotional purposes.
- Message frequency will vary depending on the application process.Msg & data rates may apply.
- OPT out at any time by texting "Stop".
Z8oz247w36
See All 24 Remote Security And Compliance Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsRemote Security And Compliance Job Market
Who's Hiring



Top Industries Hiring
- Technology & Software
- Trucking
- Media & Entertainment
What Employers Look For
The qualifications that appear most often in remote security and compliance jobs.
- Bachelor's degree in information security, cybersecurity, finance, or a related field
- Hands-on experience with compliance frameworks such as SOC 2, HIPAA, PCI-DSS, or NIST
- Industry certifications including CISA, CISSP, CISM, or CRISC
- Proficiency with GRC platforms such as Archer, ServiceNow GRC, or similar tools
- Experience conducting internal audits, risk assessments, and control gap analyses
- Strong written communication skills for policy documentation and audit reporting
Tips for Your Remote Security And Compliance Job Search
Apply early to remote roles that fit
Migrate Mate lists remote security and compliance openings from across the U.S. in one place. Check it regularly and apply directly to roles that match your certifications and focus area before postings close, since remote openings often attract applications quickly.
Show your async communication skills upfront
Remote security and compliance work runs on written output. Use your cover letter and resume to demonstrate clear, precise writing, because employers judge whether you can document policies, communicate risk findings, and run audits without back-and-forth in the office.
Prepare compliance artifacts as portfolio evidence
Bring sample work to interviews: a redacted risk assessment, a policy draft, or a controls mapping exercise. Remote hiring managers want proof you can produce the actual deliverables of the role independently, not just describe your past responsibilities.
Target companies using the tools you know
Remote security and compliance teams rely heavily on specific GRC platforms, SIEM tools, and cloud security configurations. Identify the platforms a company mentions in its job posting and make your hands-on experience with those tools explicit in your application.
Remote Security And Compliance Jobs: Frequently Asked Questions
How do I get a remote security and compliance job?
Target companies that are already operating with distributed teams, because they've built the workflows that let security and compliance professionals do meaningful work without being on-site. Remote employers screen hard for written communication, since policy documentation, audit findings, and risk assessments all travel async. Certifications like CISA, CISSP, or CIPP signal credibility quickly, and a portfolio of real compliance artifacts or security assessments gives you a concrete edge over candidates who only list responsibilities.
Which companies hire remote security and compliances?
Remote security and compliance roles are posted by Entrust Corporation, GuidePoint Security, and eBay and others right now, based on current remote listings on Migrate Mate as of August 2026. These tend to be remote-first technology firms, cloud-native companies, and regulated-industry employers in healthcare and financial services that manage compliance obligations across distributed teams.
Can you get a remote security and compliance job with no experience?
Yes, but remote entry-level roles in this field are harder to land because employers expect you to operate independently from day one without in-office mentorship. Cloud security fundamentals, GRC platform familiarity, and entry-level certifications like CompTIA Security+ open doors at remote-first startups and managed security service providers. Documenting a self-directed lab project or a sample risk assessment shows remote employers you can produce real work without hand-holding.
Do you need a degree for remote security and compliance jobs?
Not always. Many remote employers weight certifications, demonstrated hands-on skills, and verifiable results more heavily than a formal degree, particularly for roles focused on GRC tools, policy writing, or security auditing. A degree can help at larger enterprises or for roles with a regulatory-advisory component, but candidates who show practical competence through certifications, project work, and clear written communication consistently compete for remote openings without one.
Which industries hire the most remote security and compliances?
Most remote security and compliance openings sit in Technology & Software, Trucking, and Media & Entertainment, per current remote listings on Migrate Mate as of August 2026. These sectors hire security and compliance professionals remotely because their compliance obligations, data protection requirements, and risk frameworks apply equally regardless of where the team is located.
See All 24 Remote Security And Compliance Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs