Skip to main content

Remote Cybersecurity Jobs: What's Actually Open (Late August 2026)

Live board snapshot: only about 11% of practitioner cyber roles are fully remote. Where remote seats sit by specialty, seniority skew, and posted USD bands.

Updated by

JW
Jack WalshAug 29, 2026 · 7 min read

Hi, I'm Jack, the owner of Cybersecurity Jobs List, and co-founder of Himalayas (himalayas.app) and Cavuno (cavuno.com). Across all my platforms, I work with application security daily: dependency vulnerability scanning, secure authentication, API security, and data protection across hundreds of thousands of users. My technical background is in computer science (UNSW), where he studied security engineering and computer networks, and worked as a research assistant on VR experiments that were published in the Journal of Experimental Psychology. I also work with cybersecurity hiring data every day, tracking which companies are posting, what certifications actually appear in listings, how salaries differ by sub-discipline and clearance level, and where the talent gaps are widest. That combination of security practice, engineering at scale, and daily immersion in the hiring data is what shapes the content on this site. I'm currently based in Sydney, Australia.

Share this post

Abstract editorial visual for remote cybersecurity job hunting: soft navy paths converging toward an open doorway motif, no text or logos
Editorial cover for the late August 2026 remote cybersecurity jobs snapshot from live board inventory.

Remote cybersecurity work is real. It is also narrower than social media makes it look. The useful question is not "is cyber remote?" It is how many live roles are labeled remote right now, which specialties get them, and what posted pay looks like when employers bother to publish a range.

For an employer shortlist with role-specific locations and requirements, see our companies hiring remote cybersecurity professionals guide. The figures below remain the dated August snapshot.

We reviewed 6,029 live listings on Cybersecurity Jobs List on 29 August 2026. After dropping obvious sales and go-to-market titles, 5,931 practitioner-facing roles remained. Of those:

  • 676 remote (about 11.4%)
  • 1,418 hybrid (about 23.9%)
  • 3,835 on-site (about 64.7%)

Plain English: fully remote seats are a minority. Hybrid is common. On-site still dominates the board. If your search filter is remote-only, you are shopping about one in nine practitioner ads, not the whole market.

About the data: Posted ranges are employer asks from live ads on this board, not accepted offers. Role groups come from job titles; each job is counted once. Work mode uses the listing remote field (remote, hybrid, on-site). Small salary samples are labeled. This is a board snapshot, not a government labor survey.

Horizontal bar chart of practitioner-facing cybersecurity jobs by work mode: on-site 3835, hybrid 1418, remote 676
Work mode mix across 5,931 practitioner-facing live listings (29 August 2026).

Remote vs hybrid vs on-site at a glance

MetricValue
Live listings scanned6,029
Practitioner-facing (ex-sales titles)5,931
Remote676 (11.4%)
Hybrid1,418 (23.9%)
On-site3,835 (64.7%)
Remote roles with usable USD yearly range203
Remote median posted band (USD/yr)$120,000 to $170,000
All-board median posted band (USD/yr)$115,000 to $172,500
Entry-level labels that are remote39 of 474 entry labels (8%)

So what: remote pay on this board is not a discount aisle. The remote median posted band sits near or slightly above the whole-board median. The constraint is access and seniority, not a race-to-the-bottom wage story in the posted numbers.

Who actually gets remote seats

Among the 676 remote practitioner ads, named specialty buckets look like this (messy "other" titles are large, same as every real board):

Title groupRemote openingsShare of that group's board volume
Security engineer / architect-style titles15012.7% of engineer bucket
GRC / risk / compliance9712.7% of GRC bucket
Security / cyber analyst7313.3% of analyst bucket
SOC / security operations4810.0% of SOC bucket
Pentest / red team1319.7% of pentest bucket (small base)
Cloud security / AppSec1216.9% of cloud/AppSec bucket (small base)
Other remote titles278mixed strings, leadership, niche labels
Horizontal bar chart of remote cybersecurity openings by title group: engineer 150, GRC 97, analyst 73, SOC 48, pentest 13, cloud AppSec 12
Named specialty remote volume. Engineer and GRC lead; SOC remote is real but thinner than the SOC brand suggests.

What that means if you want remote work:

  • Engineer and GRC are the thickest named remote lanes (150 and 97). Architecture, cloud-adjacent engineering, and control-framework writing travel better than desk-bound ops folklore admits.
  • Analyst remote exists (73) but competes hard. Broad analyst titles beat glamorous niche labels.
  • SOC remote is available, not abundant (48). Many defensive shops still want shift coverage, tooling proximity, or cleared facilities. Plan for hybrid or on-site SOC if you need volume.
  • Pentest and AppSec show higher remote share on tiny bases. Treat the percentages as directional. Absolute openings are still low double digits.
  • "Other" is large because real ads are messy: program managers, consultants, tool-specific titles, and leadership. Read the description. Do not celebrate a remote keyword alone.

Remote skews senior

Seniority label on remote rolesCountShare of remote
Senior37255%
Mid-level20230%
Director / executive639%
Entry-level / associate-style entry labels396%
Horizontal bar chart of remote cybersecurity roles by seniority: senior 372, mid 202, leadership 63, entry 39
Remote inventory is majority senior. Entry-level remote is a thin slice.

Board-wide entry labels number 474. Only 39 of those are remote (about 8% of entry). Hybrid picks up another 97 entry labels. On-site still holds most beginner seats (337).

So what: remote-first job hunting is mostly a mid-to-senior game on this inventory. If you are breaking in, hybrid and on-site paths remain the volume play. That matches the earlier August entry-level brief: junior remote is the exception, not the plan.

What remote postings pay (when they say)

203 remote practitioner roles published a usable USD yearly range in this cut. That is a decent sample for directional medians, still not an offer database.

  • Remote median posted band: about $120k to $170k.
  • Hybrid median posted band: about $122k to $180k (n=283).
  • On-site median posted band: about $112k to $170k (n=837).
  • Whole-board median posted band: about $115k to $172.5k (n=1,323 USD yearly rows).

Specialty slices inside remote (small n means directional only):

Remote title groupUSD yearly nMedian posted band
Engineer60$113k to $162k
GRC / risk28$113k to $168k
Analyst17$80k to $130k
SOC / ops11$119k to $151k
Cloud / AppSec4directional only ($141k to $187k median pair)

National context still helps. BLS puts information security analysts near a $124,910 median (May 2024). That mixes levels and work modes. Use board posted bands to reject fantasy numbers and to sanity-check offers after locality, clearance, shift differential, and bonus.

Remote does not automatically mean "same pay, better couch." Some employers discount remote; some pay a premium for scarce skills. On this snapshot, the remote median band is competitive with the board overall. Competition for those seats is also high because everyone can click Apply from anywhere.

If you are hunting remote cyber roles

  1. Start with the live remote filter: Remote cybersecurity jobs. Add hybrid when you can travel a few days: hybrid cybersecurity jobs.
  2. Bias toward lanes with remote volume: engineer-style titles, GRC/risk, and broad analyst roles beat waiting on a perfect junior remote SOC unicorn.
  3. Keep SOC in the mix if that is your path: SOC analyst jobs and U.S. SOC analyst jobs. Expect more hybrid/on-site than pure remote.
  4. Entry seekers: use entry-level filters and read the August entry brief. Do not build a plan that requires remote-only junior cyber.
  5. Calibrate pay with live inventory: July salary snapshot, August role-demand snapshot, and entry-level August brief.
  6. Prove location flexibility honestly. If you can do hybrid near a metro with defense, finance, or cloud employers, your funnel gets much wider than remote-only.

How we built this snapshot

  • Source: live published listings on Cybersecurity Jobs List, 29 August 2026.
  • Sales and go-to-market style titles removed from the practitioner picture.
  • Work mode from the listing remote field (remote, hybrid, on-site).
  • Specialty groups from job titles; each job counted once in the first matching group.
  • Salary math: USD yearly posted minimums and maximums only; extreme outliers outside roughly $25,000 to $450,000 excluded.
  • Board inventory snapshot, not accepted-offer data and not a national employment census.

Hiring remote or hybrid cybersecurity talent?

If you hire practitioners and want a niche board instead of a general marketplace, post a free moderated 30-day listing or use the $49 Featured Launch Special for priority placement. Introductory pricing. No performance guarantees.

Post a job · Employer pricing

Browse live cybersecurity roles

Start with a filter that matches how you can actually work. Come back weekly. New roles land every day.

Keep reading

Related posts