2

Offensive Security Engineer Remote Jobs in Boston, MA

Senior Security Engineer

Boston, MA · On-site +1

$124K - $170K/yr

Senior Security Engineer Remote, United States About this position: We're looking for a Senior Security Engineer to strengthen Later's company-wide security posture through hands-on engineering ...

This role is remote with the expectation that candidates are based near one of the following Voya ... This role will partner closely with Cloud,DevSecOps, Application Security, and Platform Engineering ...

Sr. Product Security Engineer II

Burlington, MA · Remote

$124K - $170K/yr

Establish technical standards for account management, privilege management, remote access/service modes, and secure debug/manufacturing workflows. Firmware and Software Security Engineering * Work ...

Sr. Product Security Engineer II

Burlington, MA · Remote

$124K - $170K/yr

Establish technical standards for account management, privilege management, remote access/service modes, and secure debug/manufacturing workflows. Firmware and Software Security Engineering * Work ...

next page

Showing results 1-20

Offensive Security Engineer Remote information

See Boston, MA salary details

$66.8K

$166K

$223.3K

How much do offensive security engineer remote jobs pay per year?

As of Aug 10, 2026, the average yearly pay for offensive security engineer remote in Boston, MA is $165,973.00, according to ZipRecruiter salary data. Most workers in this role earn between $155,400.00 and $172,200.00 per year, depending on experience, location, and employer.

What is the difference between Offensive Security Engineer Remote vs Penetration Tester?

AspectOffensive Security Engineer RemotePenetration Tester
CertificationsOSCP, OSWE, CEHOSCP, CEH, GPEN
Work EnvironmentRemote, collaborative security teamsOften client-site or remote assessments
Industry UsageSecurity teams, cybersecurity firmsConsulting firms, security assessments
Search & Comparison IntentUnderstanding roles, skills, and remote opportunitiesJob scope, certifications, and remote work options

Offensive Security Engineer Remote and Penetration Tester roles share overlapping skills and certifications like OSCP and CEH. However, Offensive Security Engineers typically work within security teams on ongoing security infrastructure, often remotely, focusing on offensive security strategies. Penetration Testers usually perform specific security assessments, sometimes on-site, and may have a broader consulting focus. Both roles are vital in cybersecurity but differ in scope and work environment.

What are the key skills and qualifications needed to thrive as an offensive security engineer?

To thrive as an Offensive Security Engineer (Remote), you need strong expertise in penetration testing, vulnerability assessment, and cybersecurity principles, often supported by a degree in computer science or a related field. Familiarity with tools like Metasploit, Burp Suite, and Kali Linux, as well as certifications such as OSCP or CEH, is typically required. Attention to detail, problem-solving skills, and effective written communication are critical soft skills for success in this role. These abilities are essential for identifying vulnerabilities, reporting findings clearly, and helping organizations strengthen their security posture against evolving threats.

What are some common challenges faced by remote offensive security engineers, and how can they be addressed?

Remote Offensive Security Engineers often face challenges such as coordinating effectively with geographically dispersed teams, maintaining secure access to sensitive systems, and staying updated on rapidly evolving threat landscapes. Overcoming these hurdles typically involves strong communication skills, leveraging secure collaboration tools, and establishing regular check-ins with colleagues. Additionally, continuous learning through online resources and industry forums is vital to remain effective and proactive in identifying and addressing security vulnerabilities.

What does an offensive security engineer do?

An Offensive Security Engineer is responsible for proactively identifying and mitigating security vulnerabilities in an organization’s systems, networks, and applications. Working remotely, they perform penetration testing, vulnerability assessments, and simulated cyberattacks to discover weaknesses before malicious actors can exploit them. They also provide detailed reports and recommendations to help organizations improve their overall security posture. Remote Offensive Security Engineers use a variety of tools and collaborate with other security professionals to ensure effective communication and secure operations across distributed environments.
What are popular job titles related to Offensive Security Engineer Remote jobs in Boston, MA? For Offensive Security Engineer Remote jobs in Boston, MA, the most frequently searched job titles are:
What job categories do people searching Offensive Security Engineer Remote jobs in Boston, MA look for? The top searched job categories for Offensive Security Engineer Remote jobs in Boston, MA are:
What cities near Boston, MA are hiring for Offensive Security Engineer Remote jobs? Cities near Boston, MA with the most Offensive Security Engineer Remote job openings:
Infographic showing various Offensive Security Engineer Remote job openings in Boston, MA as of August 2026, with employment types broken down into 100% Contract. Highlights an 100% Remote job distribution, with an average salary of $165,973 per year, or $79.8 per hour.

Senior Security Engineer

Later

Boston, MA • On-site, Remote

$124K - $170K/yr

Full-time

Re-posted 2 days ago


Job description

Later is the world's most intelligent influencer marketing company, built to give brands the confidence to create unforgettable campaigns. By combining real creator relationships, trusted intelligence, and expert guidance, Later removes fear and guesswork from one of marketing's most visible investments.
Built on a native, AI-powered platform and more than a decade of proprietary data-including billions of social interactions, impressions, and $2.4B+ in verified influencer-driven purchases-Later helps teams understand what will work before they launch.
By combining trusted insight with expert guidance, Later removes guesswork from influencer marketing, enabling brands to choose the right creators, execute fully managed campaigns, and drive meaningful growth across awareness, engagement, and revenue. Trusted by leading enterprise brands including Nike, Wayfair, Unilever, and Southwest Airlines, Later bridges creativity and performance so campaigns don't just look good-they deliver results. Learn more at later.com.
Senior Security Engineer
Remote, United States
About this position:
We're looking for a Senior Security Engineer to strengthen Later's company-wide security posture through hands-on engineering, thoughtful collaboration, and pragmatic standards. This role blends deep security expertise with strong software engineering skills, with a focus on application security, cloud and infrastructure security, secure development practices, vulnerability management, compliance enablement, and security improvements across our corporate systems and business operations. You'll partner closely with teams across Engineering, Infrastructure, Product, IT, Legal, People, Finance, and other business functions to embed security into Later's systems, tools, workflows, and operating practices. A core focus of this role is helping Later mature its security capabilities in support of SOC 2 and other compliance expectations through practical controls, automation, evidence-ready processes, and clear guidance that works across the company. This role is ideal for a senior security practitioner who thinks like a defender, builds like a software engineer, and leads through influence across both technical and non-technical teams.
What you'll be doing:
Company-Wide Security Strategy & Compliance
  • Assess and continuously improve Later's overall security posture across applications, infrastructure, cloud environments, corporate systems, vendor tooling, and business workflows.
  • Define and implement scalable security standards, best practices, and guardrails that support SOC 2 readiness through practical, automated, and auditable solutions.
  • Partner with Engineering, Infrastructure, IT, Product, Legal, People, Finance, and business leaders to align security priorities with company goals, risk reduction, and delivery timelines.
  • Translate SOC 2 and related compliance requirements into sustainable technical and operational controls, procedures, and evidence collection practices.
  • Identify security gaps across the company, prioritize remediation efforts, and help teams make pragmatic, risk-based decisions.
  • Support company-wide security awareness, secure operating practices, and adoption of security controls across business teams.

Technical Execution
  • Build and maintain internal security tools, automation, and services that support secure development, compliance workflows, vulnerability management, corporate security operations, and operational visibility.
  • Design and implement security controls within CI/CD pipelines, including secure build and deploy patterns, security scanning, dependency management, container scanning, and secret management.
  • Support application security efforts, including secure design reviews, threat modeling, code review guidance, API security, microservices security patterns, and remediation planning.
  • Improve cloud infrastructure and corporate systems security through hardening, monitoring, configuration review, Infrastructure-as-Code security scanning, access reviews, and secure operational patterns.
  • Collaborate with technical and business teams to identify vulnerabilities and control gaps, explain impact clearly, and drive effective remediation.
  • Strengthen security observability and response readiness through logging, alerting, detection engineering, incident response improvements, and company-wide security process maturity.

Collaboration & Enablement
  • Partner with teams across the company to identify, understand, and fix security issues in a collaborative, non-blocking way.
  • Provide pragmatic security guidance on designs, implementations, vendor tools, operational practices, and business workflows.
  • Communicate security risks, tradeoffs, and recommendations clearly across technical and non-technical audiences.
  • Embed security into development workflows, corporate systems, and company operating practices without slowing teams unnecessarily.
  • Support SOC 2 and related compliance efforts through automation, well-defined controls, reliable evidence practices, and cross-functional coordination.
What success looks like:
  • Within the first 90 days, you've completed a security posture assessment, identified the highest-priority gaps, and have a remediation roadmap that's been reviewed and socialized with key stakeholders across Engineering, IT, and Leadership.
  • By 6 months, core SOC 2 controls are documented, automated where possible, and evidence collection is running reliably without manual heroics from any single team.
  • Security is embedded into Later's CI/CD pipelines, with scanning, secret management, and container security integrated and maintained as a standard part of the development lifecycle.
  • Teams across Engineering, IT, and the business have a clear point of contact for security questions, a shared understanding of the risk landscape, and security guidance that helps them move faster, not slower.
  • Later's security observability has materially improved: logging, alerting, and detection coverage are in place, and the company has a documented, practiced incident response process.
What you bring:
We are committed to building an inclusive, supportive place for you to do the best and most rewarding work of your career. If you identify with any of the following, we encourage you to apply!
  • 5-7+ years of experience as a Security Engineer or Software Engineer with a strong security focus.
  • Proven ability to build and operate production-quality software, automation, and internal tooling.
  • Strong understanding of application security, infrastructure security, cloud security, secure CI/CD practices, and corporate security controls.
  • Hands-on experience with vulnerability management, secure software development, threat modeling, remediation workflows, and operational security improvements.
  • Experience with security frameworks and standards such as OWASP, NIST, CIS Controls, SOC 2, and ISO 27001, and the ability to apply them in production and business environments.
  • Experience supporting SOC 2 compliance efforts through practical, automated, and auditable controls.
  • Familiarity with cloud security platforms such as AWS Security Hub, Azure Security Center, or GCP Security Command Center.
  • Experience with SIEM/SOAR tools, logging and monitoring platforms, detection workflows, and practical incident response processes.
  • Experience with Infrastructure-as-Code security scanning for tools such as Terraform or CloudFormation.
  • Ability to translate complex security concepts into clear, actionable guidance for technical and non-technical audiences.
  • Experience collaborating closely with engineering, IT, compliance, and business teams to improve security outcomes.
  • Familiarity with C#, modern backend systems, cloud-native architecture, and SaaS business tooling.
How you work:
  • Driven by Impact: You deliver results that matter, prioritizing high-value work, meeting deadlines, and adapting quickly while keeping outcomes clear.
  • Strategic & Customer-Centric: You anticipate risks and opportunities, connect decisions to long-term growth, and build trust through proactive insights.
  • Curious & Growth-Oriented: You seek knowledge, ask sharp questions, and apply learnings fast, challenging the status quo with a mindset of improvement.
  • Collaborative & Resilient: You thrive in change by staying resourceful, solution-focused, and positive, removing roadblocks, sharing insights, and keeping morale high.
  • Accountable & Honest: You own your work, hold yourself and others to a high bar, and use transparent feedback to drive growth.
  • Emotionally Intelligent: You build trust through empathy and collaboration, foster inclusion, and inspire others with grit, optimism, and integrity.
Our approach to compensation:
We take a market-based & data-driven approach to compensation. We leverage data from trusted third-party compensation sources to help us understand the market value of a role based on function, level, geographic location, and scope. We evaluate compensation bi-annually, including performance and market-related factors.
Our salaries are benchmarked against market Total Cash Compensation for the geographic location of our job posting. Compensation for some roles is structured as On Target Earnings (OTE = base + commission/variable) while for others it is structured as Salary only.
To comply with local legislation and ensure transparency, we share salary ranges on all job postings. Skills, experience and other factors help determine the final salary we offer which may vary from the original range posted.
Additionally, all permanent team members are eligible to participate in various benefits plans as part of their overall compensation package.
Salary Range:
$145,000 - $175,000
#LI-Remote
Where we work:
We have offices in Boston, MA; Vancouver, BC; and Vancouver, WA. For select positions, we are open to hiring fully remote candidates. We post our positions in the location(s) where we are open to having the successful candidate be located.
Diversity, inclusion, and accessibility:
At Later, we are committed to fostering a culture rooted in an inclusion-first mindset at every level of the company, embracing the importance of hiring and building teams for culture add rather than culture fit. We openly build and maintain unbiased hiring, pay, and promotion practices to create a foundation for an equitable workplace, paving the way for systemic change.
We are committed to creating a diverse environment and are proud to be an equal opportunity employer. All applications will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, national origin, disability, or age. Please let us know if you require any accommodations or support during the recruitment process.