Skip to main content

5 companies hiring remote cybersecurity professionals

Explore five remote cybersecurity employers with current role examples, eligible locations, experience requirements and practical questions to ask before applying.

Updated by

JW
Jack WalshSep 7, 2026 · 9 min read

Hi, I'm Jack, the owner of Cybersecurity Jobs List, and co-founder of Himalayas (himalayas.app) and Cavuno (cavuno.com). Across all my platforms, I work with application security daily: dependency vulnerability scanning, secure authentication, API security, and data protection across hundreds of thousands of users. My technical background is in computer science (UNSW), where he studied security engineering and computer networks, and worked as a research assistant on VR experiments that were published in the Journal of Experimental Psychology. I also work with cybersecurity hiring data every day, tracking which companies are posting, what certifications actually appear in listings, how salaries differ by sub-discipline and clearance level, and where the talent gaps are widest. That combination of security practice, engineering at scale, and daily immersion in the hiring data is what shapes the content on this site. I'm currently based in Sydney, Australia.

Share this post

Illustration of remote workers, a laptop, opportunity cards and clocks connected across a world map
Conceptual illustration created for Cybersecurity Jobs List.

Huntress, 1Password, Abnormal AI, Canonical and Backblaze have remote openings for cybersecurity practitioners. The work ranges from investigating intrusions to securing software and building controls for AI systems. Your shortlist will depend on where you live, the work you've already done and the hours you can cover.

We checked the linked employer postings on 14 September 2026. These are examples to explore, with locations and requirements from individual vacancies. Openings can close, and a company's remote policy doesn't make every role available in every country. Follow the employer link before preparing an application.

Update, 14 September: We removed CyberSheath from the active shortlist because the linked Cloud Security Engineer vacancy is no longer available. You can still check its careers board for other openings.

Remote cybersecurity employers at a glance

The list includes security vendors and technology companies hiring for their own security work. It isn't a ranking of workplace quality. The location column describes the example role, not every vacancy at that employer.

Employer Example work Listed remote location Experience signal
Huntress SOC investigation and response Separate Australia and UK postings 2+ years in relevant operational roles
1Password Product security incident response United States or Canada 5+ years in IT or engineering with a security focus
Abnormal AI Application security engineering United States 5+ years in application security
Canonical Security-focused software engineering Worldwide Demonstrated software and security experience
Backblaze Internal AI security engineering Argentina, Colombia, Costa Rica or Mexico 7+ years in security engineering or backend systems

Huntress

Huntress has separate Australian and UK security operations analyst openings. The work includes investigating alerts, reading endpoint evidence and helping customers remove threats. These are useful roles to examine when your experience is in hands-on investigation rather than building software.

The Australian posting asks for at least two years in SOC, incident response, managed detection and response or digital forensics. It also includes an annual U.S. company trip. The UK posting asks for two years in SOC or digital forensics and mentions U.S. travel one or two times a year. Check the relevant country's posting and ask about the shift pattern before assuming the work fits your schedule.

For preparation, use our SOC analyst interview questions to practise explaining an investigation. Keep Huntress's openings page in your shortlist if a specific vacancy closes.

1Password

Product security response combines technical investigation with decisions about fixing and communicating a problem. At 1Password, the Senior Security Engineer, Vulnerability Management, PSIRT opening focuses on that coordination, including vulnerability disclosure and incident playbooks. PSIRT means product security incident response team.

This full-time role is remote within the U.S. or Canada. It asks for five or more years in IT or engineering with a security focus, incident response experience and the ability to read and write code. It includes an on-call rotation outside business hours. The posting also explains that remote employees work from their home country and that in-person travel is part of almost all roles.

Bring examples of decisions you made during an incident and how you explained the outcome to other teams. Browse 1Password's careers listings for other security specialisms.

Abnormal AI

The Application Security Engineer II role at Abnormal AI is listed as remote in the U.S. Despite the “II” in the title, the posting asks for at least five years of application security engineering experience.

Its responsibilities include reviewing architecture, threat modeling and building security checks into development pipelines. The role also covers AI-powered features and expects strong programming skills. Experience securing AI systems is one route to meeting the requirements; the posting also allows for a clear ability to learn those risks quickly.

Read this as an engineering role with close developer collaboration. A useful preparation exercise is to explain a security issue you helped fix, why the fix worked and how you kept it from returning. Our SOC analyst versus security engineer comparison helps distinguish the work. You can find other vacancies through Abnormal's open roles.

Canonical

Canonical's Security Software Engineer posting is labeled home-based worldwide. It describes security-oriented engineers working across product teams, with responsibilities that can include vulnerability fixes, code review and security features in open-source software.

The requirements emphasize programming, Linux, software engineering and a track record of improving security. A computer science or STEM degree is requested, with an alternative route allowed if you can explain it convincingly.

Travel deserves an early conversation. The description requires international travel at least twice a year, while the application asks about two to four events lasting one to two weeks. Clarify the schedule and any accommodations you need. The application also explicitly requires your own words and prohibits AI-generated application content.

This is a useful employer to research when you can demonstrate software contributions and security judgment. See Canonical's current openings for narrower roles, and confirm that your country is supported for the specific position.

Backblaze

Backblaze offers an example outside the specialist cybersecurity vendor category. The cloud storage company's Sr. AI Security Engineer opening lists remote locations in Argentina, Colombia, Costa Rica and Mexico.

The role focuses on safeguards for internal AI use, including access controls, runtime enforcement and monitoring. It asks for seven or more years in security engineering or backend systems, strong programming skills and experience deploying security controls. The geographic list is specific, so don't treat it as an opening throughout Latin America.

An experienced backend engineer should read the responsibilities closely before ruling themselves out on title alone. You would still need evidence of security work, not simply general interest in AI. Use Backblaze's openings page to check availability and other locations.

Build a shortlist you can act on

Start with eligibility, then compare the work. A long list of recognizable employers is less useful than a few roles you can explain a strong fit for.

For each vacancy, copy these fields into your own notes:

  • Role and source: employer, title, requisition or link, and the date you checked it.
  • Location decision: your country appears, your country is excluded, or eligibility needs clarification. Record citizenship or work-authorization requirements separately.
  • Working pattern: normal hours, on-call, travel and office attendance. Write “not stated” where the posting doesn't answer.
  • Evidence of fit: two responsibilities you can support with examples from your own work, and the most significant gap.
  • Next action: apply, clarify a specific requirement, or check the employer again later.

Keep unknowns visible. A location dropdown on an application form isn't, by itself, a promise that the employer can hire in every country it contains. Likewise, a request about sponsorship doesn't establish whether sponsorship will be offered.

A worked example

Suppose you're based in the UK, have three years of SOC experience, can travel occasionally and need predictable weekday hours. This is an illustrative decision, not an assessment of a real applicant.

Huntress's UK role is worth a closer look because its stated location and experience threshold fit that starting point. Your next step is to clarify the rota. You haven't established schedule fit simply because the job is remote.

The U.S./Canada 1Password opening wouldn't be a location match for you as described. Canonical's worldwide label clears an initial geographic screen, but you'd still need to evaluate its software requirements and travel commitment. Being able to apply from a country and being prepared for the job are separate decisions.

That leaves you with a focused question for one employer and specific reasons to keep searching. You don't need a numerical employer score to make that decision.

Questions to ask before accepting a remote security role

Use the interview to resolve the details that affect your working week. Choose questions the posting hasn't already answered:

  1. What does a normal rota look like? Ask about nights, weekends, handovers, on-call frequency and what happens after an overnight incident.
  2. How will I get help while onboarding? Find out who reviews early work, how escalation works and whether you shadow a teammate before taking responsibility alone.
  3. Where can I work, and can that change? Confirm the permitted home location, any office expectations and the process for requesting temporary work elsewhere.
  4. How much travel should I plan for? Ask about frequency, duration, notice and how costs are handled.
  5. Which compensation range applies to me? Confirm the currency, location basis and what is included in base pay versus variable compensation.

A concrete answer is more useful than “we're flexible.” For example, ask the manager to describe the last person's first month or a recent on-call week. You can then compare the arrangement with your own constraints.

Common questions about remote cybersecurity hiring

Which companies hire worldwide?

Of the examples here, Canonical explicitly labels the linked role worldwide. The other openings name countries or regions. Even with a worldwide label, confirm the employer can hire you in your home country and that you can meet the travel requirements.

Are these entry-level remote jobs?

This shortlist is mainly for experienced candidates. A title without “senior” can still require several years of work. If you're starting out, use the entry-level cybersecurity filter and read each description for the experience it expects. Keep internships, apprenticeships and suitable adjacent IT roles in your search rather than assuming these five examples define your options.

Do I need a particular certification?

Use the requirements of your target vacancy. In the linked 1Password posting, relevant certifications are valued but not required; its practical experience requirements remain. Build your preparation around the work you'd be asked to do, then assess whether a credential addresses a specific gap. Our SOC career guide explains how to weigh credentials alongside experience for that path.

Should I only search cybersecurity companies?

Include internal security teams at other employers. Backblaze is one example in this list. Search for the work itself, such as application security, incident response or cloud security, as well as for familiar company names. That gives you a way to discover relevant teams outside a vendor directory.

Find your next remote role

Open the remote cybersecurity jobs collection, which starts with the Workplace filter set to Remote. Check each role's stated location and original employer requirements before applying.

Keep the employer career pages for teams that interest you and revisit your shortlist weekly. Record what changed: a suitable vacancy appeared, a requirement became clearer or a role closed. That small habit turns repeated browsing into a search you can build on.

Related posts