Remote Cyber security Jobs · Incident Response

Job listings

  • Lead incident response for major hacks, coordinating triage, communications, and post-incident reports.
  • Ensure major hacks are visible to customers within hours and keep TRM's hack data complete and accurate.
  • Design AI-powered systems to automate hacks analysis and detect vulnerable contracts before exploitation.

TRM provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM is a Series C company with $220M in total funding, backed by top investors, operating as a distributed-first company with hubs in major cities.

$120,000–$150,000/yr

  • Protect cloud infrastructure, applications, and customer data across a modern technology environment.
  • Identify and remediate vulnerabilities directly in application repositories and infrastructure code.
  • Build and tune SIEM detections, strengthen AWS security controls, and lead incident response.

Cloudbeds is a hospitality technology company providing cloud-based management solutions for lodging businesses. It operates as a remote-first organization with a globally distributed team across 40+ countries and a small, senior security team.

  • Manage daily incident response and forensic analysis of compromised systems.
  • Formulate and direct incident response efforts, prioritizing actions and creating detailed reports.
  • Build incident response plans, playbooks, and attack simulations for tabletop exercises.

Check Point protects over 100,000 organizations worldwide from cyber and AI-driven threats with a prevention-first approach. The company is recognized for workplace culture by TIME, Newsweek, and Forbes.

  • Identify and respond to security incidents on a global scale.
  • Act as incident commander to drive incidents through the entire response lifecycle.
  • Design and maintain security alerts, automated actions, playbooks and escalation workflows.

Mozilla Corporation is a non-profit-backed technology company that makes pioneering brands like Firefox and focuses on AI, social media, security, and more. With over 225 million monthly users, Mozilla is wholly owned by the Mozilla Foundation and strives to reclaim an internet built for people.

$120,000–$150,000/yr

  • Fix vulnerabilities across the stack by writing pull requests in application repositories and Terraform.
  • Build and tune SIEM detections, mapping coverage to MITRE ATT&CK and reducing false positives.
  • Lead incident response, harden AWS estate, and automate security workflows with code.

Cloudbeds is a hospitality management platform powering hotels across 150 countries, processing billions in bookings annually. The company is a remote-first team of 650+ across 40+ countries, recognized for innovation and an inclusive culture.

$208,500–$235,750/yr

  • Lead enterprise-scale security operations, including 24/7 SOC oversight, real-time detection, and automation.
  • Direct incident response, forensics, and risk-reduction programs across cloud and hybrid infrastructure.
  • Architect SIEM, SOAR, and AI/ML platforms; build and mentor high-performing cybersecurity teams.

U.S. FinTech operates the world's largest mortgage securitization platform, supporting the Uniform Mortgage-Backed Security of Fannie Mae and Freddie Mac. The company fosters a culture of innovation and flexibility, serving 70% of mortgage-backed securities in the market.

  • Lead and continuously improve the security posture, including operations, engineering, incident response, vulnerability management, and GRC.
  • Drive strategic security roadmaps and champion automation and AI adoption across security operations.
  • Develop and lead the security team while fostering a security-first culture and operational excellence.

WFAA is a private nonprofit that inspires gifts and connections between alumni and the University of Wisconsin-Madison. It values diversity and fosters an inclusive, respectful environment where staff and constituents thrive.

$105,000–$105,000/yr

  • Act as the primary escalation point and technical lead for complex incidents.
  • Enhance monitoring by tuning alerts, refining detection logic, and automating workflows.
  • Mentor junior engineers and document incident response procedures.

DYOPATH is a managed security services provider that helps organizations defend against evolving cyber threats through security operations and monitoring. The company fosters an award-winning culture guided by its L.O.V.E. philosophy, emphasizing teamwork, respect, and professional growth.

  • Monitor, triage, and investigate security alerts across SIEM, EDR, and cloud platforms.
  • Conduct deep log analysis and escalate threats to specialized incident response teams.
  • Improve detection quality, reduce false positives, and maintain SOC documentation.

They operate a global 24/7 Security Operations Centre focused on detecting, investigating, and responding to cyber threats. They provide a remote-first, globally distributed working environment with an inclusive and transparent culture.

  • Safeguard customer digital assets, sensitive data, and critical systems against cyber threats as part of the MXDR team.
  • Leverage expertise in vulnerability identification, robust security implementation, and incident response to enhance security posture.
  • Collaborate with cross-functional teams to assess risks, formulate security strategies, and ensure adherence to industry standards.

Check Point Software Technologies is a leading vendor of cybersecurity solutions, protecting against sophisticated threats and attacks. The company has been honored by Time Magazine as one of the World’s Best Companies for 2024 and recognized as one of the World’s Top Female-Friendly Places to Work.