Remote Security Engineer Jobs: AppSec, Cloud, Detection and GRC Titles
Searching for security engineer jobs, remote or not, runs into a naming problem quickly. "Security" covers several different careers, and one company's Security Engineer is another's Detection Engineer or Security Analyst. This guide groups the common titles by the work behind them, shows what to look for in a posting, and explains how to track the titles that fit you so your search stays focused.
Security is a family of jobs
Most security postings in tech companies fall into one of six areas. The work, the interviews and the people who move into each are different.
| Area | Common titles | What the work looks like |
|---|---|---|
| Application / product security | Application Security Engineer, AppSec Engineer, Product Security Engineer | Secure code review, threat modelling, security tooling in CI, working with developers |
| Cloud and infrastructure security | Cloud Security Engineer, Infrastructure Security Engineer, Security Platform Engineer | Hardening cloud accounts, identity and access, network controls, infrastructure as code |
| Detection and response | Detection Engineer, Security Engineer (Detection & Response), SOC Analyst, Incident Responder | Writing detections, triaging alerts, investigating incidents, on-call |
| Offensive security | Penetration Tester, Offensive Security Engineer, Red Team Engineer | Testing systems the way an attacker would, writing findings |
| GRC and compliance | GRC Analyst, Security Compliance Manager, Risk Analyst | Audits, policies, frameworks such as SOC 2 or ISO 27001, vendor risk |
| Corporate and IT security | Corporate Security Engineer, IT Security Engineer, IAM Engineer | Laptops, identity providers, employee access, internal tools |
Where people usually come from
- Developers often move into application security. Knowing how code actually gets written and shipped is the core of the job.
- DevOps, platform and SRE engineers are a natural fit for cloud security. Our guide to DevOps, SRE and platform engineer jobs covers the neighbouring titles.
- SOC analysts and system administrators often grow into detection engineering and incident response.
- Auditors, analysts and project managers with an interest in security often start in GRC.
Reading a security posting
The title narrows things down, but the description decides whether a role fits. Look for:
- Build, operate or assess? "Build tooling", "automate" and "own the platform" describe engineering work. "Monitor", "triage" and "respond" describe operations. "Assess", "audit" and "test" describe assurance or offensive work.
- On-call. Detection and response roles usually have a rotation. That matters for remote work across time zones.
- Languages. Python and Go are common in security engineering roles. If the posting asks for real coding, expect a coding interview.
- Frameworks. SOC 2, ISO 27001, GDPR and vendor assessments point towards GRC work, even when the title says Engineer.
- Citizenship or clearance. Some security roles, especially those serving government customers, require a specific nationality or security clearance. If you can't meet that, skip it and move on.
Our guide on how to read a job description covers the general version of this habit.
Remote and location
Security teams often handle sensitive data and access, and some companies prefer security staff in specific countries where they have an entity, or in overlapping time zones for incident response. Read the location line carefully, and check which countries a phrase like "EMEA" really covers; we explain how in what EMEA means in job postings. Where the posting lists countries, take the list at face value rather than assuming yours is included.
Certifications and evidence
Certifications carry different weight in different parts of security. GRC and consulting postings list them more often. Engineering roles tend to care more about evidence you can show: tools you built, detections you wrote, vulnerabilities you found and disclosed responsibly, write-ups, CTF results, or security improvements you drove in a codebase. Neither replaces the other; read what the posting asks for and put that first in your CV. For how to do that without overstating anything, see tailoring your CV to a posting.
If most of your experience is with local regulations or a single country's standards, describe it in terms international readers will recognise: the kind of controls you ran, the audits you prepared for, the size of the environment.
Titles to track
A focused search usually means two or three areas, not all six. For each area, track the main title and its variants:
- AppSec: Application Security Engineer, AppSec Engineer, Product Security Engineer.
- Cloud: Cloud Security Engineer, Infrastructure Security Engineer.
- Detection: Detection Engineer, Detection & Response Engineer, Security Analyst, SOC Analyst.
- Offensive: Penetration Tester, Offensive Security Engineer.
- GRC: GRC Analyst, Security Compliance, Risk and Compliance.
Also watch general Security Engineer postings; many companies use that single title for everything and explain the focus in the description.
How Hot Jobs matches security roles
Matching is by keywords in the job title. The Security role catches titles containing Security Engineer, Application Security, AppSec, Cybersecurity or Cyber Security, Penetration Tester, Security Analyst and Infosec. That covers Cloud Security Engineer, Product Security Engineer and "Security Engineer, Detection & Response".
Some titles don't contain those phrases and won't be matched: Detection Engineer, Security Architect, SOC Analyst, GRC Analyst and Red Team titles among them, so check those on the boards and career pages you use. Titles with Manager, Director or Head of are left out of the Security role; a Security Engineering Manager posting goes to the Engineering Manager role instead.
Hot Jobs checks the career pages of 390+ tech companies every 30 minutes, plus two remote boards, and sends new security postings that match your role and regions to Telegram. €3, paid once. Connect the bot