Security & Cybersecurity jobs

51 open security & cybersecurity roles aggregated daily from multiple job boards.

51 matches

  • Architect, Information Security - DevSecOps/Application Security - Remote

    Molina Healthcare

    Application-SecurityDevSecOpsInformation-Security-ArchitectureUnited StatesremoteHimalayas

    JOB DESCRIPTION Provides application security architecture and governance support within the Application Security Center of Excellence (AppSec CoE). Responsible for identifying, assessing, and managing application and software supply chain risks, and defining secure-by-design patterns that enable development teams to deliver secure applications at scale. Partners with development teams, solution architects, DevOps teams, and security stakeholders to embed security controls across the Software

  • Penetration Tester

    DeepSeas

    Penetration-TesterOffensive-SecurityEthical-HackingUnited StatesremoteHimalayas

    With 30 years of experience in cyber defense, DeepSeas is trusted by nearly 1,000 clients around the world, including Fortune 100 enterprises and mid-market organizations, higher education institutions, municipality and local governments, and federal agencies. Known for its programmatic approach to continuously transforming cyber defense programs, DeepSeas is recognized by Gartner as a top 40 provider of MDR and ranked as a top 5 MDR leader in the 2024 Frost Radar™: Global Managed Detection

  • Platform Security Engineer, NZ

    Partly

    Platform-Security-EngineerSecurity-Platform-EngineerPlatform-Security-EngineeringNew ZealandremoteHimalayas

    Note: Partly is headquartered in Austin, TX with offices in London, UK, Christchurch, NZ and Auckland, NZ. Wherever you're based, we'll connect you with your nearest office for onboarding, and fly you to join the full team for our quarterly "Season Openers" (we cover travel and accommodation). If you're relocating to join us, we can also assist with relocation costs. 🚀 Our story Partly is connecting the world's parts, and we're doing that by building the AI infrastructure layer for the

  • Security Analyst - Governance, Risk, and Compliance

    LaunchDarkly

    Security-AnalystGRC-AnalystCompliance-AnalystUnited Statesremote$116K–$188K USDHimalayas

    About the Job: LaunchDarkly 's Governance, Risk, and Compliance team is hiring a Security Analyst III to facilitate the definition, implementation, and operation of security and privacy programs at LaunchDarkly . LaunchDarkly is critical infrastructure. Our security team keeps it safe for the global systems that depend on us and the GRC team demonstrates that to earn the trust of our customers. As a member of the team, you'll drive initiatives to assess and reduce security risks to the co

  • Information Security Analyst

    COUNTRY Financial

    Bloomington, ILJooble

    Experience more with a career at COUNTRY Financial! We’re excited you’re interested in a career at COUNTRY as we strive toward our vision - to enrich lives in the communities we serve. Our footprint spans coast to coast. But more important than where we operate, is the...

  • SAP Governance & Risk Engineer

    Bright Vision Technologies

    SAP-SecuritySAP-GRCSAP-Governance-and-RiskUnited Statesremote$100K–$150K USDHimalayas

    Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States. This is a fantastic opportunity to join an established and well-respected organization offering tremendous career growth potential. Job Title: SAP Governance & Risk Engineer Location: 100% Remote (U.S.) Position Type: Full-time, Direct W2 Salary Range: $100,000–$150,000 Annually Experience Required: 6+ years Sponso

  • AppSec Engineer

    Bright Vision Technologies

    Application-SecuritySecurity-EngineeringCybersecurityUnited Statesremote$80K–$100K USDHimalayas

    AppSec Engineer – Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States. This is a fantastic opportunity to join an established and well-respected organization offering tremendous career growth potential. Job Title: AppSec Engineer Location: 100% Remote (U.S.) Position Type: Full-time, Direct W2 Salary Range: $80,000–$100,000 Annually Experience Required: 6+ years

  • Applied AI Engineer

    Action1

    Computer-And-Network-SecurityR&DEngineeringCyprusremoteHimalayas

    Who we are Action1 is an autonomous endpoint management platform trusted by many Fortune 500 companies. Cloud-native, infinitely scalable, highly secure, and configurable in minutes—it just works and is always free for the first 200 endpoints with no functional limits. By pioneering autonomous OS and third-party patching with peer-to-peer patch distribution and real-time vulnerability assessment (without requiring a VPN), Action1 eliminates routine IT labor, helps prevent ransomware and se

  • Senior Information Security Analyst

    Bonterra

    Washington DC$100K–$120K USDJooble

     ...About the Role The Bonterra Information Security Risk and Compliance department is looking to hire a Senior Information Security Risk Analyst to our team. If you enjoy problem solving, are enthusiastic working in a team format and want to thrive in the ever-changing risk &... 

  • Information Security Analyst 4

    CACI International

    Aberdeen Proving Ground, MDJooble

    Job Title: Information Security Analyst 4 Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI Employee Type: Regular Percentage of Travel Required: Up to 10% Type of Travel: Local... 

  • Information Security Analyst 4

    CACI International

    New York StateJooble

    Job Title: Information Security Analyst 4 Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI Employee Type: Regular Percentage of Travel Required: Up to 10% Type of Travel: Local... 

  • Information Security Analyst

    Parsons Corporation

    United StatesJooble

     ...your talent and redefine what’s possible. Job Description: Parsons is looking for an amazingly talented Senior Information Security Analyst to join our team! In this role you will get to work with our National Guard customer. What You'll Be Doing: Perform as Lead... 

  • Information Security Analyst III

    CACI International

    Aberdeen, MDJooble

    Job Title: Information Security Analyst III Job Category: Service Contract Act Time Type: Full time Minimum Clearance Required to Start: TS/SCI Employee Type: Regular Percentage of Travel Required: Up to 10% Type of Travel: Local... 

  • Senior Security Engineer

    Kong

    Senior-Security-EngineerSenior-Information-Security-EngineerSenior-Cybersecurity-EngineerItalyremoteHimalayas

    Are you ready to unlock intelligence? If you don’t think you meet all of the criteria below but are still interested in the job, please apply. Nobody checks every box - we’re looking for candidates that are particularly strong in a few areas, and have some interest and capabilities in others. About the Role: As a Senior Security Engineer, you will serve as the technical security lead for securing the world’s most popular API gateway. You will apply deep expertise in high-performance networki

  • Automations Engineer Intern (TX and AK) - SkillBridge (Military Only)

    InfoDefense

    CybersecurityAutomation-EngineeringSecurity-OperationsUnited StatesremoteHimalayas

    Transition to a Career in Cybersecurity at a Dynamic Cybersecurity Company The cybersecurity industry is poised to grow by double digits again this year. Join the growing team at InfoDefense to provide exceptional services to our customers. Gain private-sector experience and expand your skill set with the latest in security methods and technology! This is a remote position, but candidates must live in or near Dallas, TX, or Anchorage, AK, or be willing to relocate if offered a permanent pos

  • Senior Information Security Analyst

    General Dynamics Information Technology

    Virginia$187K–$253K USDJooble

     ..., faster, and more securely in dynamic environments. JOB DESCRIPTION We are seeking an experienced Senior Information Security Analyst to support the security, compliance, and ongoing authorization of mission-critical information systems. The successful candidate will... 

  • Security Systems Field Engineer

    Digi Security Systems

    Dallas, TXJooble

     ...innovation and reliable service, and we're known as the industry's experts. Position Overview We are seeking an experienced Field Engineer to join our operations in the Dallas, TX area. This person will be responsible for performing the most skilled security... 

  • Cybersecurity Risk Analyst - Moldova

    name

    CybersecurityRisk-AnalysisCybersecurity-Risk-AnalystMoldovaremoteHimalayas

    Yopeso has been developing a diverse range of software products, from large-scale applications to smaller solutions, for 20 years. With a growing team of over 300 employees across five locations, we are dedicated to fostering a culture of growth, transparency, and professionalism. At Yopeso , we value authenticity, curiosity, and ambition. These values drive us to build strong connections within our community and with our partners, ensuring trust, integrity, and transparency in all our busin

  • Senior Information Security Risk Analyst

    Warner Bros. Discovery

    Washington DChybrid$83K–$190K USDJooble

     ...you can thrive. *Must work a hybrid schedule (3 days onsite) out of our DC office.* THE JOB: The Senior Information Security Risk Analyst will support the assessment of information security risks across all of Warner Bros. Discovery’s (WBD’s) third party suppliers/... 

  • Senior Information Security Analyst

    ServiceNow

    United StatesJooble

    Company Description It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy. That moment inspired Fred to build a company that could do that for everyone—freeing people from busywork so they could...

  • Information Security Analyst Senior

    General Dynamics Information Technology

    Pearl City, HI$66K–$112K USDJooble

    Type of Requisition: Regular Clearance Level Must Currently Possess: Top Secret/SCI Clearance Level Must Be Able to Obtain: Top Secret/SCI Public Trust/Other Required: None Job Family: Cyber and IT Risk Management Job Qualifications: Skills: DISA STIG, Enterprise...

  • Information Security Analyst

    CACI International

    New York StateJooble

    Job Title: Information Security Analyst Job Category: Service Contract Act Time Type: Full time Minimum Clearance Required to Start: TS/SCI Employee Type: Regular Percentage of Travel Required: Up to 10% Type of Travel: Local *... 

  • Information Security Analyst

    NEPC, LLC

    United StatesJooble

     ...Location: Flexible (East Coast preferred). Must reside in a state where we are registered. Role Summary: The Information Security Analyst is a role reporting to the Director of Information Security and focused primarily on security operations, investigations, and... 

  • Sr Information Security Analyst (Remote)

    Military, Veterans and Diverse Job Seekers

    FloridaremoteJooble

    This position has the potential to work remotely within the Eastern or Central US timezones. WHAT YOULL DO: Basic administration and management of security operations solutions and programs, such as our database security program, PKI and SIEM management Provide...

  • Senior Information Security Analyst

    UNIVERSITY OF AZ FOUNDATION

    Tucson, AZJooble

     ...General Position Summary: As a Senior Information Security Analyst, you’ll have the opportunity to make a meaningful impact by fostering a security first mindset across the organization. If you’re passionate about cybersecurity, we’d love to hear from you! We are... 

  • Information Security Forensic Analyst

    Ryder

    Coral Gables, FLJooble

     ...review the Job Applicant Privacy Policy by clicking  here . Job Description : Summary The Information Security Forensic Analyst is responsible for a broad range of responsibilities with a primary emphasis on supporting the soc 24/7 incident response by providing... 

  • Senior Information Security Analyst, SME

    dmi

    Atlanta, GAJooble

     ...solutions that drive measurable results. Learn more at About the Opportunity DMI is seeking a Senior Information Security Analyst, SME to support cybersecurity operations for a large program. Serving as a trusted technical advisor, this role provides expert guidance... 

  • Information Security Analyst

    Savannah College of Art and Design

    Savannah, GAJooble

     ...As an information security analyst, you will monitor and advise on information security issues across systems and workflows to ensure the university's internal security controls are appropriate and functioning as intended. You will manage and maintain security appliances... 

  • Information Security Analyst

    Comtech Inc

    Atlanta, GAJooble

     ...Information Security Analyst Atlanta GA 12+ months Contract (Locals only) ** TAX Clearance Letter is mandatory ** Job Summary: We are looking for a skilled cybersecurity professional with relevant technical experience. As the Information Security Analyst 3,... 

  • Information Security Analyst

    Vista Innovative Solutions, LLC

    Rock Island, ILJooble

     ...and consulting company supporting several military installations and federal agencies across the nation.  The Information Security Analyst interacts with Cyber Security Team and those on contractor personnel to ensure all contract related RMF requirements are fulfilled... 

  • Sr. Information Security Analyst

    JPS Health Network

    Fort Worth, TXJooble

     ...meeting you! For more information, visit To view all job vacancies, visit or Job Title: Sr. Information Security Analyst Requisition Number: 43256 Employment Type: Full Time Division: IT TECHNICAL SERVICES & SECURITY... 

  • Information Security Analyst

    ISN

    Dallas, TXJooble

     ...suppliers and incorporate a level of due diligence in the contractor management process. The Position: The Information Security Analyst position will be responsible for providing technical and business assistance for a wide variety of information security related... 

  • Senior Information Security Analyst

    Arizona Department of Administration

    Phoenix, AZJooble

     ...excellence in innovation, exceptional customer service and public servant-led continuous improvement. SENIOR INFORMATION SECURITY ANALYST Job Location: Support Division 1600 W Monroe St. Phoenix, AZ 85007 Posting Details: Salary: $75,000  Grade: 24... 

  • Information Security Analyst- Applications

    Mohawk Industries

    GeorgiaJooble

     ...can find your more with Mohawk. What We Need: Position is open to Calhoun GA & Dallas TX The Application Security Analyst is a detail-oriented security professional who works to facilitate and support the application security function across the software... 

  • Information Security Analyst

    HD SUPPLY MANAGEMENT, INC.

    GeorgiaJooble

    Preferred Qualifications ~ Bachelor's degree in computer science or a related field. ~2+ years of experience in SOC analysis or incident response. ~ Security-centric certification, such as Security+ or Certified Ethical Hacker. Job Summary Monitors, analyzes...

  • Information Security Threat Analyst

    Gibson Dunn

    New York, NY$120K–$150K USDJooble

     ...firm’s work is distinguished by a unique combination of precision and vision. Based in New York, the Information Security Threat Analyst is responsible for detecting, investigating, and responding to information security events and incidents across the firm. The ideal... 

  • Information Security Analyst (SOC)

    Gulf Coast Automation Group

    Chicago, ILremote$100K–$105K USDJooble

     ...Job Title: Information Security Analyst (SOC) Primary Location: Remote Position Type: Direct Hire Overview TalentFish is casting a line for an Information Security Analyst. This is a Direct Hire role, fully remote. This position exists to strengthen a growing... 

  • Senior Information Security Analyst

    Carter's, Inc.

    Atlanta, GAJooble

     ...The Senior Security is a member of the IT Security team reporting to the Sr. Manager, IT Security. The Senior Information Security Analyst is primarily focused on leading complex investigations, driving departmental improvement efforts on monitoring, detecting, administration... 

  • Senior Information Security Analyst

    UMass Amherst

    New York, NYhybridJooble

     ...Title: Senior Information Security Analyst Executive Area: Information Technologies College/School/MBU: Information Technology Department: IT Information Security Work Location: Amherst Schedule: Full Time Work Arrangement:  Hybrid   Job Summary... 

  • Information Security Analyst

    ZGF Architects

    New York, NY$12K–$112K USDJooble

     ...ZGF is seeking a motivated and collaborative  Information Security Analyst  to join our Technology team.   We are open for this role to   be   based in   one of   ZGF ’ s   offices  (Portland, Seattle, Vancouver BC, Los Angeles, Denver, New York, or Washington DC... 

  • Information Security Analyst

    Vesync

    Tustin, CAJooble

     ...out our brands: levoit.com [ | cosori.com [ | etekcity.com [ pawsync.com [ The Opportunity: The Information Security Analyst is responsible for supporting the organization’s security posture by implementing, monitoring, and maintaining security controls... 

  • Senior / Information Security Analyst - Re - Post

    Western Farmers Electric Cooperative

    Moore, OKJooble

     ...following levels based on education, experience, knowledge, skills, and behaviors required. SUMMARY - Senior Information Security Analyst: Under the general supervision of the Supervisor, IT Infrastructure, the Senior Information Security Analyst performs troubleshooting... 

  • Security Host/Hostess - Full-Time, $29.00/Hour

    Aulani, A Disney Resort & Spa

    Makakilo City, HIThe Muse

    Come and join the magic with Aulani, A Disney Resort and Spa! Perks and benefits may include: 100% full coverage of healthcare for you and your eligible dependents Tuition paid upfront at network schools Free lunch Free parking Free theme park admission and much more! As a Security Host/Hostess, the main goal is to provide a safe and secure environment that enables our guests, cast members and vendors to experience the magic of Disney. Responsibilities : The Security Host/Hoste

  • Diplomatic Security Foreign Service Special Agent (SA) (FP-2501)

    Department of State - Agency Wide

    Criminal InvestigationMontevideo, Uruguay, Toshkent, Uzbekistan$61K–$98K USDUSAJobs

    In addition to the bachelor's degree requirement, candidates must possess at the time of application at least one year of work experience or academic achievements that reflect progressively increasing levels of responsibility. Experience must demonstrate basic knowledge of management, such as supervision, initiative, and leadership, and teamwork, English skills, including writing, speaking, and listening, conceptual skills, such as planning and organizing, critical thinking, active learning, and

  • TITLE 32 PERSONNEL SECURITY SPECIALIST GS-0080-09

    Army National Guard Units

    Security AdministrationCharleston, West Virginia$61K–$79K USDUSAJobs

    MINIMUM MILITARY GRADE: E-4 MAXIMUM MILITARY GRADE: E-7 Your rank MUST be included somewhere within your resume. You must fully substantiate in your own words that you meet the requirements listed below. When explaining minimum requirements and specialized experience you must give examples. Do not copy from the vacancy announcement or the position description. Explain it in your own words and give examples to be considered for this vacancy. All personnel applying for this position who do not mee

  • SECURITY GUARD

    Naval Special Warfare Command

    Security GuardDam Neck Naval Facility, Virginia Beach, Virginia$41K–$66K USDUSAJobs

    GS-06: Your resume must demonstrate at least one year of specialized experience at or equivalent to the GS-05 grade level or pay band in the Federal service or equivalent experience in the private or public sector. Specialized experience must demonstrate the following: performing security functions such as protecting property and guarding a broad range of highly sensitive items from hazards such as trespass, theft, and accidental or willful damage/destruction within installations or restricted a

  • SECURITY SPECIALIST T32

    Air National Guard Units

    Security AdministrationTucson, Arizona$75K–$98K USDUSAJobs

    Military Grades: Must possess SrA/E-4 to MSgt/E-7 Compatible Military Assignments: Most possess an AFSC GENERAL EXPERIENCE: Experience, education or training in collecting and analyzing data effectively, efficiently, and accurately. Able to apply procedures and directives by reading and interpreting technical material. Ability to communicate clearly and effectively orally and in writing, using presentation and report formats. Demonstrated ability to follow directions, to read, understand, and re

  • SECURITY GUARD

    Naval Air Systems Command

    Security GuardCherry Point, North Carolina, Kinston, North Carolina$45K–$58K USDUSAJobs

    Your resume must also demonstrate at least one year of specialized experience at or equivalent to the GS-05 grade level or pay band in the Federal service or equivalent experience in the private or public sector. Specialized experience must demonstrate the following: 1) Must be able to walk and stand for long periods of time. 2) Must be proficient with utilizing computer systems. 3) Must be able to multitask. Additional qualification information can be found from the following Office of Personne

  • Polygraph Examiner

    Central Intelligence Agency

    Security AdministrationWashington, District of Columbia$71K–$132K USDUSAJobs

    Minimum Qualifications Interested candidates should be passionate about the ideals of our American republic, committed to upholding the rule of law and the U.S. Constitution, and committed to improving the efficiency of the Federal government. Hiring decisions will not be based on race, sex, color, religion, or national origin. Excellent verbal and written communication skills Analytic skills Strong interpersonal skills and the ability to interact with a broad cross-section of society, sometimes

  • SECURITY SPECIALIST

    Air Force Civilian Career Training

    Security AdministrationBeale AFB, California, Edwards AFB, California$50K–$115K USDUSAJobs

    Air Force Qualification Standards To qualify for a GS-07: Completion of 1 full year of graduate level education, or bachelor's degree with Superior academic Achievement as provided in the "General Policies and Instructions" for Qualifications Standards Operating Manual, or 5 academic years of pre-professional study, or 1 year specialized experience equivalent to at least GS-5. KNOWLEDGE, SKILLS AND ABILITIES (KSAs): Your qualifications will be evaluated on the basis of your level of knowledge, s

About Security & Cybersecurity jobs

Security and cybersecurity jobs cover the people who protect a company's systems, data, and people from threats both technical and human. The titles span SOC / security operations center analyst roles (tier-1, tier-2, tier-3), security engineer (network, cloud, application), penetration tester / red team, security researcher, incident responder, identity and access engineer, governance/risk/compliance (GRC) specialist, security architect, and security leadership (security manager, director, CISO / chief information security officer). The work splits between proactive (designing controls, hardening systems, threat hunting, security architecture) and reactive (incident response, breach investigation, vulnerability management).

Postings here come from the same multi-source feed: broad aggregators, federal feeds, remote-only listings, and tech-heavy boards. The full list refreshes once a day. You'll see SOC analyst roles at MSSPs / managed security service providers, security engineer positions at SaaS companies, penetration tester roles at consultancies and at large enterprises, GRC roles at companies in regulated industries, federal security positions, and CISO-track leadership openings.

Signed in? The list is re-ranked against your values assessment, so the roles at the top are the ones that line up with what actually matters to you: comp, the kind of security work (defensive, offensive, GRC, leadership), industry, on-call expectations, the team. The scoring math is the same for everyone; the weighting is yours.

What does a security or cybersecurity job pay?

Security pay sits above general IT and roughly tracks engineering at the same level. SOC analyst (tier-1): $55-80k entry, $80-110k tier-2/tier-3. Security engineer (network, cloud, app security): $120-180k mid-career, $180-260k+ at senior levels at growth-stage SaaS, $300k+ at staff/principal levels at FAANG-tier (Meta, Apple, Amazon, Netflix, Google) and top tech. Penetration tester / red team: $110-180k at consultancies, $180-260k+ at well-funded in-house red teams. GRC specialist: $90-140k mid-career; senior GRC manager: $140-200k. CISO at a growth-stage SaaS: $300-500k+ total comp; CISO at large public enterprise: $500k-$1.5M+ at the top. Federal security roles follow the GS / General Schedule scale; cleared positions in defense and intelligence pay premiums of 15-30% over comparable uncleared work. Major certifications (CISSP / Certified Information Systems Security Professional, OSCP / Offensive Security Certified Professional, CEH / Certified Ethical Hacker, GIAC / Global Information Assurance Certification) translate to real pay bumps at most companies.

Are security jobs hiring remote?

Highly remote-friendly for most security functions. SOC analyst work, security engineering, penetration testing, security research, and GRC roles all run heavily remote at most companies. The work is mostly on a computer with cloud-based tooling and collaboration over chat and video. Exceptions: physical security roles (rare in tech), forensics work that involves seized devices, classified work in defense and intelligence (mostly on-site or hybrid with SCIF / sensitive compartmented information facility access), and senior leadership roles at large enterprises with strong office cultures. The remote toggle on this page filters to listings tagged remote-only or remote-first. Pen testing engagements sometimes involve on-site assessments for clients, even when the home role is remote.

Entry-level vs senior security roles

Entry-level security is one of the harder fields to break directly into without prior IT experience. The traditional path: IT support to sysadmin or networking, then a SOC analyst role, then security engineering. Direct-entry SOC analyst roles do exist (especially at MSSPs running 24/7 operations) and often hire candidates with Security+ certification and demonstrable lab work. Senior security roles split sharply: defensive (security engineer, security architect, detection engineer, threat hunter), offensive (pen tester, red team operator, security researcher), and governance (GRC manager, compliance officer, privacy lead). The CISO track requires breadth across all three plus strong business and communication skills. Calibrating senior level from a listing: years of experience, scope of systems covered, on-call expectations, whether the role owns architecture decisions, and reporting line (does the role report to CIO, CTO, or directly to CEO/board).

How to compare two security offers

Security offers diverge on dimensions other roles don't have. Pin down: the company's security maturity (is there a real program with leadership support, or is security a cost center being squeezed?), the specific function (defensive, offensive, GRC, all-of-the-above), on-call expectations (how often, response SLA, how brutal the incidents are likely to be), the threat landscape the company actually faces (a small SaaS sees different attacks than a defense contractor), and the team's relationship with engineering (security partners with eng vs. security blocks eng releases). WorkWomp's offer comparison handles this kind of multi-variable decision. Save both offers, take the 5-minute values assessment so the scoring weights what actually matters to you, drop in interview notes (the team's maturity, the on-call burden, leadership exposure), and the breakdown shows which offer wins where.

See how WorkWomp compares offers

Common questions

  • What's the difference between SOC analyst, security engineer, and pen tester?

    Different roles along the security stack. SOC / security operations center analyst monitors alerts from security tools (SIEM / security information and event management, EDR / endpoint detection and response, network IDS / intrusion detection system), triages incidents, escalates to senior analysts when something looks real. The work is reactive and shift-based, often 24/7 coverage in MSSPs. Security engineer designs and builds security controls: firewall rules, authentication systems, vulnerability scanning pipelines, incident response runbooks. The work is mostly proactive engineering. Penetration tester / red team operator simulates attackers against the company's own systems, identifies exploitable weaknesses, and reports them in detail. The work mixes technical depth with creative thinking; engagements are typically project-based (1-3 week sprints per engagement). Pay tracks complexity: SOC analyst typically pays less than security engineer or pen tester at the same level (security engineer and pen tester pay similarly).

  • Do security jobs require a degree?

    Less than most fields require. Security hires aggressively from non-traditional backgrounds: self-taught practitioners with strong CTF / capture-the-flag competition records, military and government veterans with security clearances, IT support and network engineers transitioning into the field, and bootcamp grads with Security+ certifications. Degree requirements show up most in leadership tracks (CISO at a large enterprise often requires a master's), in federal security positions (degrees and clearances), and in security research (academic-oriented roles). For entry and mid-career individual contributor work, capability beats credential almost universally.

  • How do I break into cybersecurity without prior security experience?

    Two reliable paths. Path 1: IT support to security. Move into a tier-1 helpdesk or sysadmin role, build IT fluency, then pivot into a SOC analyst position. Most SOC teams hire from internal IT pipelines. Path 2: technical bootcamp plus lab work. Build skills via Security+, hands-on labs (TryHackMe, HackTheBox, Cybrary), CTF competitions, and a small portfolio of self-directed projects (a home lab running pfSense, Suricata, ELK stack), then pitch yourself into entry-level SOC roles at MSSPs that hire aggressively. Federal security agencies (CISA / Cybersecurity and Infrastructure Security Agency, NSA / National Security Agency, DOD / Department of Defense) also run direct-entry programs for non-traditional candidates with strong aptitude. Avoid the common trap of stacking certifications without hands-on work; cert-only candidates without lab evidence struggle in interviews.

  • Is security a recession-resistant field?

    More resistant than most, less than people assume. Compliance-driven security work (GRC, audit response, regulatory reporting) is genuinely recession-resistant because the regulations don't pause when budgets tighten. Defensive security engineering at well-funded enterprises (banking, defense, healthcare, large tech) holds up well. Offensive security and security research at smaller companies cut more aggressively during downturns because the work feels like 'nice-to-have' to non-security executives. Federal security jobs are very stable. The roles most exposed in cuts: junior security analysts at non-regulated companies, security consultants at less-established firms, and security 'evangelist' or 'developer relations' roles. The roles most stable: GRC at regulated industries, security engineering at financial services, federal cleared positions.

  • Is AI changing security work?

    Yes, in both directions. AI is augmenting defensive work: automated triage of SOC alerts, AI-assisted code review for vulnerabilities, AI-driven threat hunting across large logs. The roles being squeezed: tier-1 SOC analyst doing volume alert triage, junior compliance analysts doing repetitive evidence collection. AI is also enabling attackers: AI-generated phishing at scale, automated reconnaissance, faster vulnerability discovery. The roles holding or growing: senior security engineers who architect AI-aware controls, detection engineers who build novel signatures faster with AI tools, threat hunters who interpret AI-generated alerts critically, and security researchers studying AI-native attack patterns. The honest framing: if your security work is mostly running standard playbooks, AI is competing for your seat. If your work involves judgment about novel threats and architectural trade-offs, you're fine.