2

Remote Ciso Jobs in Massachusetts (NOW HIRING)

$125K - $150K/yr

... g. CIO, CISO, CFO and CEO) to maximize account engagement and long-term success. • Build a ... Work location is Remote, USA. * The ideal candidate resides in the following states: MA, VA, DC, PA ...

Work closely with the CISO on access-related audit requests and remediation items Required Qualifications * 2-5+ years of IT support experience supporting a remote or distributed workforce in the ...

A culture grounded in integrity, responsibility, and stewardship--supported by a company with a strong legacy and a future-focused mindset #LI-RK1 #LI-Remote MassMutual is an equal employment ...

A culture grounded in integrity, responsibility, and stewardship--supported by a company with a strong legacy and a future-focused mindset #LI-RK1 #LI-Remote MassMutual is an equal employment ...

Information Security Engineer

Andover, MA · On-site +1

$150K - $180K/yr

Review and advise on network changes, cloud connectivity, remote access design, and firewall rule sets in partnership with the MSP * Work with MSP to oversee Microsoft 365 and Entra ID (Azure AD ...

Cyber AI Security Manager

Boston, MA · On-site +1

$120K - $163K/yr

We offer unlimited PTO, a flexible remote work policy, and a supportive environment that prioritizes sustainable, long-term performance. About the Role The Cyber AI Security Manager sits at the ...

Remote Ciso information

See Massachusetts salary details

$76.4K

$162.4K

$253.9K

How much do remote ciso jobs pay per year?

As of Sep 7, 2026, the average yearly pay for remote ciso in Massachusetts is $162,449.00, according to ZipRecruiter salary data. Most workers in this role earn between $128,900.00 and $182,900.00 per year, depending on experience, location, and employer.

What is a remote CISO?

A Remote CISO (Chief Information Security Officer) is responsible for overseeing an organization's cybersecurity strategy and policies while working remotely. They manage security risks, ensure compliance, and develop protocols to protect sensitive data from cyber threats. Unlike an on-site CISO, a Remote CISO leverages virtual communication tools to collaborate with IT teams, executives, and stakeholders. This role is common in companies that prioritize remote work, need flexible security leadership, or outsource their CISO responsibilities.

What are the key skills and qualifications needed to thrive as a remote CISO?

To thrive as a Remote CISO, you need extensive experience in cybersecurity strategy, risk management, governance, and compliance, typically supported by a degree in information security or related fields and several years of leadership in IT security. Familiarity with frameworks like NIST, ISO 27001, and tools such as SIEM, DLP, and endpoint security solutions, along with certifications like CISSP or CISM, are highly valued. Outstanding communication, leadership, and decision-making skills are crucial for effectively guiding remote teams and influencing stakeholders across an organization. These skills enable a Remote CISO to protect critical assets, ensure regulatory compliance, and maintain organizational resilience in a distributed work environment.

What are some common challenges faced by a remote CISO, and how can they be addressed?

A Remote CISO often faces the challenge of coordinating information security initiatives and incident responses across distributed teams with varying time zones and communication styles. To overcome these obstacles, successful Remote CISOs implement clear security policies, leverage collaborative technologies, and establish regular communication routines with IT and business units. Building strong relationships virtually and ensuring ongoing visibility into the organization’s security posture are also key to mitigating risks. Additionally, staying updated with emerging threats and compliance requirements is crucial for maintaining an adaptive and effective security program. By proactively addressing these challenges, Remote CISOs can foster a culture of security and ensure robust protection regardless of team location.

What are the most commonly searched types of Ciso jobs in Massachusetts?

The most popular types of Ciso jobs in Massachusetts are:

What are popular job titles related to Remote Ciso jobs in Massachusetts?

For Remote Ciso jobs in Massachusetts, the most frequently searched job titles are:

What job categories do people searching Remote Ciso jobs in Massachusetts look for?

The top searched job categories for Remote Ciso jobs in Massachusetts are:

What cities in Massachusetts are hiring for Remote Ciso jobs?

Cities in Massachusetts with the most Remote Ciso job openings:

Infographic showing various Remote Ciso job openings in Massachusetts as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% Remote job distribution, with an average salary of $162,449 per year, or $78.1 per hour.

Senior Cybersecurity Engineer

Indico Data Solutions, Inc

Boston, MA • On-site, Remote

$165K - $185K/yr

Full-time

Re-posted 17 days ago


Job description

Senior Cybersecurity Engineer
Location: USA, East Coast Preferred
Experience Required: 6-10 years
About the Position
The Senior Cybersecurity Engineer is a hands-on technical security role responsible for improving Indico's security posture across AWS, Kubernetes, CI/CD, product security, internal systems, and incident response.
This role works in partnership with Indico's CISO and CTO. The CISO owns security strategy, formal risk acceptance, policy approval, and executive accountability. The Senior Security Engineer turns that direction into practical technical controls, security reviews, operating processes, and cross-functional execution.
This role acts as a security check and balance for Engineering and Platform. You will review technical work against defined security expectations, request changes where needed, and help teams build secure systems without creating unnecessary friction.
Security does not own every security task. Engineering and Platform own implementation and remediation for the systems they build and run, including CVEs, infrastructure changes, CI/CD permissions, committed-secret remediation, and production access implementation. IT/Ops, People Ops, and system owners own day-to-day access administration. The Senior Security Engineer owns technical security standards, reviews, escalation paths, control design, and program execution.
This is a remote role, with East Coast hours preferred.
About You
You are a pragmatic technical security generalist with strong cloud security instincts. You are comfortable working across AWS, Kubernetes, IAM, networking, secrets management, CI/CD, monitoring, product security, and incident response.
You are technical enough to earn credibility with Engineering and Platform, independent enough to act as a real check and balance, and practical enough to focus on controls that reduce meaningful risk.
You know how to make security work in a startup: focus on the risks that matter, keep the process lightweight, and build guardrails that help teams move quickly without creating unnecessary exposure.
Responsibilities
  • Improve Indico's technical security posture across AWS, Kubernetes, CI/CD, product security, internal systems, and incident response
  • Partner with the CISO and CTO to turn security priorities into practical technical controls, standards, reviews, and operating processes
  • Review Engineering work against security standards, with authority to request changes where needed
  • Partner with Engineering on AWS security controls, including IAM, networking, account structure, logging, encryption, key management, backups, production access, and customer-dedicated environments
  • Review and improve Kubernetes and container security controls, including workload identity, RBAC, network boundaries, image security, runtime monitoring, and deployment patterns
  • Define and improve secure CI/CD patterns, including GitHub permissions, branch protections, privileged workflows, secrets handling, release controls, and deployment access
  • Define and oversee processes for vulnerability management, committed-secret response, secure development, incident response, and access control while Engineering, Platform, IT/Ops, and system owners operate them in their domains
  • Provide product security support, including secure design review, threat modeling for sensitive features, scanner tuning, and high-risk change review
  • Improve detection and response coverage across tools such as CloudTrail, GuardDuty, CrowdStrike, SIEM/logging platforms, vulnerability scanners, and secrets detection
  • Own day-to-day security monitoring and response operations, including alert routing, triage expectations, escalation paths, and detection improvements
  • Coordinate technical containment during security incidents across Engineering, Platform, IT/Ops, and leadership
  • Maintain incident response runbooks and partner with the CISO on severity, executive escalation, counsel/compliance coordination, and customer communication strategy
  • Create practical security guidance, standards, procedures, and runbooks for security-sensitive work such as production access, secrets handling, vulnerability remediation, incident response, customer data handling, and secure engineering
  • Maintain reusable technical security documentation, standard responses, and evidence packages for customer due diligence and compliance support
  • Evaluate security tools and vendors with a focus on technical coverage, operational fit, and reducing manual work
  • Build or sponsor lightweight automation, checks, dashboards, and workflows that make security controls repeatable

Requirements
  • 6+ years of relevant security experience, ideally in a startup, SaaS, cloud-native, or enterprise software environment
  • Strong hands-on experience with AWS security, including IAM, networking, logging, monitoring, encryption, access controls, and production security
  • Experience securing Kubernetes, containers, CI/CD pipelines, infrastructure-as-code, and modern cloud deployment patterns
  • Strong understanding of identity and access management, least privilege, privileged access, workload identity, and service-to-service permissions
  • Working knowledge of application and product security, including authentication, authorization, secure coding, common web risks, and secure design review
  • Experience defining or operating vulnerability management, secrets management, secure development, access control, or incident response processes
  • Experience with secrets management, cloud key management, encryption design, data residency, threat modeling, or secure SDLC programs
  • Experience with security monitoring, alert triage, incident response coordination, and remediation tracking
  • Experience with Python, Go, Bash, or other scripting languages for security automation
  • Ability to review infrastructure, application, and operational changes for material security risk
  • Ability to partner with Engineering and Platform while maintaining appropriate independence and oversight
  • Strong written and verbal communication skills, including clear technical guidance, standards, runbooks, and customer-facing security documentation
  • Good judgment around risk prioritization, compensating controls, exceptions, and startup-appropriate tradeoffs
  • Ability to operate independently, create structure, and drive work to completion

Bonus
  • Experience as a first or early security hire at a startup
  • Experience securing single-tenant SaaS or customer-dedicated cloud environments
  • Experience with AWS EKS, Terraform, Helm, ArgoCD, GitHub Actions, or similar infrastructure tooling
  • Experience with CrowdStrike
  • Experience supporting SOC 2, ISO 27001, HIPAA, GDPR, customer audits, or enterprise security questionnaires
  • Pragmatic, risk-based, comfortable with ambiguity, and focused on security practices people actually use