2

Offensive Security Engineer Remote Jobs in Boston, MA

Senior DevSecOps Engineer

Boston, MA · Remote

$124K - $170K/yr

Senior DevSecOps Engineer (Remote-based role that requires US-citizenship) About us Hyperproof is ... Your expertise in DevOps methodologies and security practices, and federal compliance standards ...

Senior Software Engineer (Remote)

Boston, MA · Remote

$125K - $165K/yr

This shared standard is exactly what teams need to alleviate pressure on ops and enable developers to deploy on their own without sacrificing operational control and security. Architect is a venture ...

Manager Application Security

Boston, MA · On-site +1

$133K - $190K/yr

... 1 remote in one of the following organizational hubs: Johnston, RI - Westwood OR Boston, MA ... As part of the cybersecurity organization, this role partners closely with engineering, platform ...

Manager Application Security

Westwood, MA · On-site +1

$133K - $190K/yr

... 1 remote in one of the following organizational hubs: Johnston, RI - Westwood OR Boston, MA ... As part of the cybersecurity organization, this role partners closely with engineering, platform ...

Manager Application Security

Westwood, MA · On-site +1

$133K - $190K/yr

... 1 remote in one of the following organizational hubs: Johnston, RI - Westwood OR Boston, MA ... As part of the cybersecurity organization, this role partners closely with engineering, platform ...

Manager Application Security

Boston, MA · On-site +1

$133K - $190K/yr

... 1 remote in one of the following organizational hubs: Johnston, RI - Westwood OR Boston, MA ... As part of the cybersecurity organization, this role partners closely with engineering, platform ...

Showing results 41-60

Offensive Security Engineer Remote information

See Boston, MA salary details

$66.8K

$166K

$223.3K

How much do offensive security engineer remote jobs pay per year?

As of Aug 8, 2026, the average yearly pay for offensive security engineer remote in Boston, MA is $165,973.00, according to ZipRecruiter salary data. Most workers in this role earn between $155,400.00 and $172,200.00 per year, depending on experience, location, and employer.

What is the difference between Offensive Security Engineer Remote vs Penetration Tester?

AspectOffensive Security Engineer RemotePenetration Tester
CertificationsOSCP, OSWE, CEHOSCP, CEH, GPEN
Work EnvironmentRemote, collaborative security teamsOften client-site or remote assessments
Industry UsageSecurity teams, cybersecurity firmsConsulting firms, security assessments
Search & Comparison IntentUnderstanding roles, skills, and remote opportunitiesJob scope, certifications, and remote work options

Offensive Security Engineer Remote and Penetration Tester roles share overlapping skills and certifications like OSCP and CEH. However, Offensive Security Engineers typically work within security teams on ongoing security infrastructure, often remotely, focusing on offensive security strategies. Penetration Testers usually perform specific security assessments, sometimes on-site, and may have a broader consulting focus. Both roles are vital in cybersecurity but differ in scope and work environment.

What are the key skills and qualifications needed to thrive as an offensive security engineer?

To thrive as an Offensive Security Engineer (Remote), you need strong expertise in penetration testing, vulnerability assessment, and cybersecurity principles, often supported by a degree in computer science or a related field. Familiarity with tools like Metasploit, Burp Suite, and Kali Linux, as well as certifications such as OSCP or CEH, is typically required. Attention to detail, problem-solving skills, and effective written communication are critical soft skills for success in this role. These abilities are essential for identifying vulnerabilities, reporting findings clearly, and helping organizations strengthen their security posture against evolving threats.

What are some common challenges faced by remote offensive security engineers, and how can they be addressed?

Remote Offensive Security Engineers often face challenges such as coordinating effectively with geographically dispersed teams, maintaining secure access to sensitive systems, and staying updated on rapidly evolving threat landscapes. Overcoming these hurdles typically involves strong communication skills, leveraging secure collaboration tools, and establishing regular check-ins with colleagues. Additionally, continuous learning through online resources and industry forums is vital to remain effective and proactive in identifying and addressing security vulnerabilities.

What does an offensive security engineer do?

An Offensive Security Engineer is responsible for proactively identifying and mitigating security vulnerabilities in an organization’s systems, networks, and applications. Working remotely, they perform penetration testing, vulnerability assessments, and simulated cyberattacks to discover weaknesses before malicious actors can exploit them. They also provide detailed reports and recommendations to help organizations improve their overall security posture. Remote Offensive Security Engineers use a variety of tools and collaborate with other security professionals to ensure effective communication and secure operations across distributed environments.
What are popular job titles related to Offensive Security Engineer Remote jobs in Boston, MA? For Offensive Security Engineer Remote jobs in Boston, MA, the most frequently searched job titles are:
What job categories do people searching Offensive Security Engineer Remote jobs in Boston, MA look for? The top searched job categories for Offensive Security Engineer Remote jobs in Boston, MA are:
What cities near Boston, MA are hiring for Offensive Security Engineer Remote jobs? Cities near Boston, MA with the most Offensive Security Engineer Remote job openings:
Infographic showing various Offensive Security Engineer Remote job openings in Boston, MA as of August 2026, with employment types broken down into 100% Contract. Highlights an 100% Remote job distribution, with an average salary of $165,973 per year, or $79.8 per hour.

Staff GRC Engineer (Remote)

ezCater, Inc

Boston, MA • On-site, Remote

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 22 days ago


Job description

ezCater is the #1 food tech platform for workplaces in the US. The company makes it easy for any organization to manage its food needs and order from over 125,000 restaurants nationwide. For workplaces, ezCater provides flexible and scalable solutions for everything from employee meal programs to one-off meetings, all backed by 24/7 service and business-grade reliability. For restaurant partners, ezCater helps grow their business by bringing them new high-value customers and large orders.
ezCater is looking for a Staff GRC Engineer to join the Security Engineering & Compliance team as a technical leader who can help mature our governance, risk, compliance, and data security capabilities in a way that is durable, measurable, and embedded into how our systems operate day to day. This is not a narrow audit coordinator or policy only role. We're looking for a balanced builder-operator who can raise the quality and maturity of our security controls by expanding control monitoring, strengthening data security governance, automating and instrumenting the program where stronger evidence and better monitoring are needed, and improving the operational follow through that makes the program scalable, sustainable, and effective.
What You'll Do:
  • Lead control program maturity
    • Design and maintain an auditable control framework that fits ezCater's SaaS, cloud, data, and engineering environment rather than forcing generic controls onto modern systems.
    • Shape and define ezCater's AI Governance strategy with stakeholders across the Legal, Data, Engineering, and IT domains.
    • Define how key controls are implemented, tested, evidenced, and improved over time, with a strong bias toward reliability and highly-automated, low/no friction evidence paths.
    • Partner with internal and external audit stakeholders on control design, walkthroughs, exceptions, remediation, and readiness activities tied to SOX and related frameworks.
    • Help rationalize overlapping control requirements across SOC 2, PCI, SOX, and internal policy expectations into a coherent operating model.
  • Build continuous control monitoring and automation
    • Identify where quarterly or annual checks should become continuous or near-real-time monitoring, especially for high-value controls and failure-prone workflows.
    • Partner with Security Engineering, IT, Data, and platform teams to automate control testing, evidence collection, validation, and recurring compliance workflows.
    • Define the logs, metadata, dashboards, and signals needed to assess control health and make compliance more observable and less dependent on screenshots and one-off pulls.
    • Help shift the program from detective-only controls toward stronger preventive and engineering-embedded control patterns where appropriate.
  • Expand data security policy and program quality
    • Help define and mature data security policies, standards, and handling requirements so they are clear, enforceable, and tied to actual technical and operational practices.
    • Partner with Data, Engineering, and business stakeholders to ensure data governance shows up in meaningful places such as access patterns, role design, labels, masking, retention, and evidence paths.
    • Establish what a high-quality GRC program looks like by helping define operating cadences, ownership models, decision paths, metrics, and continuous improvement loops.
    • Drive clearer documentation, standards, and guidance that both technical teams and auditors can use effectively.
  • Drive operational quality improvements
    • Support day-to-day GRC and assurance work where hands-on execution is needed to keep the program moving, including control failures, remediation coordination, audit operations, and related follow-through.
    • Improve the team's ability to handle questionnaires, trust requests, vendor and partner reviews, and other recurring work through better structure, reusable materials, and smarter agentic workflows.
    • Act as a practical partner to teams implementing or remediating controls, not just an assessor of whether the control exists on paper.
  • Lead through influence and systems thinking
    • Own a domain with high autonomy, lead cross-team efforts from start to finish, and improve the quality of systems, controls, and processes across that domain.
    • Drive alignment across stakeholders with different incentives and constraints, making pragmatic decisions that balance risk, cost, and operational reality.
    • Mentor others, improve documentation and knowledge sharing, and help raise the overall maturity of the Security Engineering & Compliance team and its partners.

What You Have:
  • 8+ experience in security GRC, compliance, risk, or security program work in a SaaS or cloud-native environment, including meaningful ownership of control design, testing, and program improvement.
  • Strong experience with security compliance frameworks such as ISO-27001, NIST CSF, SOC 2, ITGC, and PCI-DSS, including how to translate framework requirements into controls that work in real systems and teams.
  • Demonstrated ability to automate or instrument parts of a compliance or assurance program through scripting, APIs, dashboards, platform configuration, or other technical approaches.
  • Implementation of engineering system guardrails for ensuring compliance utilizing Policy-as-Code (Terraform) or secure configurations of platform systems within cloud hosted environments (AWS, GitHub, etc.)
  • Experience building or improving data security governance, classification, handling rules, or related control practices across business systems, data platforms, or collaboration environments.
  • Familiarity with governing and securing AI/Agentic systems and business processing.
  • Strong written communication and cross-functional influence skills, with the ability to explain controls, trade-offs, and program expectations to both technical and non-technical audiences.
  • Able to collaborate closely with engineers and technical teams to design controls as code, configuration, workflow, or monitoring instead of relying only on policy documents and manual checklists.
  • Strong systems thinker who can break ambiguous governance problems into workable operating models, measurable outcomes, and implementation steps.
  • Comfortable balancing strategic design work with operational execution when the program needs direct hands-on support.
  • Someone who improves process quality, identifies gaps between teams, and drives implementation of better ways of working.
  • Comfortable leveraging AI tooling and automated workflows to increase scale and velocity.

Nice To Have:
  • Experience with scaling a unified control framework across multiple governance and compliance frameworks
  • Experience with continuous control monitoring, policy-as-code, or GRC platforms and evidence tooling.
  • Familiarity with AI governance or emerging technology risk, especially where governance needs to be translated into practical technical guardrails.

The national total targetcash compensation range for this position, including base salary and bonus target, is $165,000-$210,000 annually.*
*Please note: Final offer amounts are determined by multiple factors, including prior experience, expertise and region & may vary from the amount above. This range does not represent additional compensation benefits (such as equity, 401K or medical, dental or vision insurance).
ezCater does not sponsor applicants for work visas or legal permanent residence.
What You'll Get from Us:
You'll get a terrifically compelling experience in an innovative, high performing environment. You'll get to work with engaged and passionate colleagues on challenging and impactful projects. You will have opportunities to grow in your career, and work in a place that values work/life harmony.
Oh, and you'll get all this: Market competitive salary, stock options that you'll help make worth a lot, 12 paid holidays, flexible PTO, 401K with ezCater match, health/dental/FSA, long-term disability insurance, mental health and family planning resources, remote-hybrid work from our awesome Boston office OR your home OR a mixture of both home and office, a tremendous amount of responsibility and autonomy, wicked awesome co-workers, employee meal program (and many more goodies) when you're in our office, and knowing that you helped transform the food for work space.
ezCater is an equal opportunity employer. We embrace humans of every background, appearance, race, religion, color, national origin, gender, gender identity, sexual orientation, age, marital status, veteran status, and disability status. At the same time, we do not employ jerks, even brilliant ones. Following a conditional offer of employment, ezCater may require a background check.
For information on how ezCater collects and uses job applicants' personal information, please visit our Job Applicant Privacy Policy.
#BI-Remote