2

Remote Infrastructure Security Engineer Jobs in California

Vercel is the agentic infrastructure company. We free people and agents to ship what's next. For ... If you're located beyond that distance, the role is fully remote. For location-specific details ...

Senior AI Security Engineer

San Francisco, CA ยท On-site +1

$134K - $185K/yr

The Senior AI Security Engineer, under the direction of the Director, Security Engineering and Operations, sits at the frontier of AI infrastructure and enterprise security - a rare opportunity to ...

We are seeking a Staff Security Engineer who operates at the nexus of high-level strategy and multi ... Automation / IaC Proficiency in Python, Terraform, or Ansible for infrastructure-as-code.

Security Engineer

San Ramon, CA ยท On-site +1

$174/hr

It is closer to a security engineering role than to a conventional SOC analyst role, and we expect ... This role is fully remote for candidates who reside outside the 30 mile radius of one of our ...

Senior Security Engineer

Los Angeles, CA ยท On-site +1

$145K - $170K/yr

This is a remote role, serving as a senior security presence and point of escalation across the ... A background in infrastructure, cloud platform, DevOps, SRE, or systems engineering before moving ...

Guide customers through infrastructure, security, and compliance considerations. * Support ... Remote-friendly within the United States * Preference for candidates located near major East or ...

Senior Security Engineer

Los Angeles, CA ยท On-site +1

$145K - $170K/yr

This is a remote role, serving as a senior security presence and point of escalation across the ... A background in infrastructure, cloud platform, DevOps, SRE, or systems engineering before moving ...

Developer & Infrastructure Expert Role Type: Contractor Location: Remote Job Overview We are ... Identify technical errors, security or reliability concerns, and workflow gaps. * Document findings ...

Developer & Infrastructure Expert Role Type: Contractor Location: Remote Job Overview We are ... Identify technical errors, security or reliability concerns, and workflow gaps. * Document findings ...

Infrastructure Engineer

San Francisco, CA ยท On-site +1

$126K - $166K/yr

MUST-HAVES * 3+ years exp. of AWS (ownership of provisioning, security and deployment) * 3+ years ... Remote work not available TRAVEL Travel not required VISA Candidate visas are not supported ...

Developer & Infrastructure Expert Role Type: Contractor Location: Remote Job Overview We are ... Identify technical errors, security or reliability concerns, and workflow gaps. * Document findings ...

Showing results 41-60

Remote Infrastructure Security Engineer information

See California salary details

$73K

$140.3K

$167.8K

How much do remote infrastructure security engineer jobs pay per year?

As of Sep 5, 2026, the average yearly pay for remote infrastructure security engineer in California is $140,272.00, according to ZipRecruiter salary data. Most workers in this role earn between $141,100.00 and $141,100.00 per year, depending on experience, location, and employer.

What is a remote infrastructure security engineer?

A Remote Infrastructure Security Engineer is a cybersecurity professional who is responsible for protecting an organization's IT infrastructure, such as servers, networks, and cloud services, from security threats. They work remotely, using specialized tools to monitor systems, detect vulnerabilities, and respond to incidents. Their duties often include implementing firewalls, managing access controls, and ensuring compliance with security standards. These engineers play a crucial role in maintaining the safety and integrity of digital assets while supporting teams from any location.

How does a remote infrastructure security engineer typically collaborate with other IT teams to ensure system security?

As a Remote Infrastructure Security Engineer, collaboration with various IT teams is integral to maintaining a secure environment. You'll often work closely with network administrators, system engineers, and DevOps teams to assess vulnerabilities, implement security controls, and respond to incidents. Regular virtual meetings, shared documentation platforms, and ticketing systems are commonly used to coordinate efforts and ensure everyone is aligned on security protocols. This collaborative approach helps proactively address risks and ensures compliance with organizational security standards.

What are the key skills and qualifications needed to thrive as a remote infrastructure security engineer, and why are they important?

To thrive as a Remote Infrastructure Security Engineer, you need a solid background in cybersecurity, network architecture, and systems administration, often supported by a relevant degree and certifications like CISSP or CompTIA Security+. Familiarity with security tools such as firewalls, intrusion detection/prevention systems (IDS/IPS), SIEM solutions, and cloud security platforms is essential. Strong analytical thinking, effective communication, and the ability to work independently are standout soft skills in this role. These skills and qualifications are crucial to proactively protect organizational infrastructure, rapidly respond to threats, and ensure secure remote operations.

What is the difference between Remote Infrastructure Security Engineer vs Network Security Engineer?

AspectRemote Infrastructure Security EngineerNetwork Security Engineer
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, CCNP Security
Work EnvironmentCloud-based infrastructure, remote teamsOn-premises and cloud networks, often remote
Industry UsageTech, finance, healthcare, remote-first companiesTelecom, enterprise, government agencies
Common Search/ComparisonYesYes

The Remote Infrastructure Security Engineer focuses on securing cloud and remote infrastructure environments, while the Network Security Engineer specializes in protecting network hardware and on-premises or cloud networks. Both roles require similar certifications and often work remotely, but their primary focus areas differ, aligning with different aspects of cybersecurity infrastructure.

Can remote infrastructure security engineers work remotely?

Remote infrastructure security engineers can work remotely, as the role primarily involves managing security protocols, monitoring networks, and configuring security tools that can be accessed remotely. Many companies offer this position as a fully remote role, requiring strong knowledge of cybersecurity tools, cloud platforms, and remote collaboration skills.

What are popular job titles related to Remote Infrastructure Security Engineer jobs in California?

For Remote Infrastructure Security Engineer jobs in California, the most frequently searched job titles are:

What job categories do people searching Remote Infrastructure Security Engineer jobs in California look for?

The top searched job categories for Remote Infrastructure Security Engineer jobs in California are:

What cities in California are hiring for Remote Infrastructure Security Engineer jobs?

Cities in California with the most Remote Infrastructure Security Engineer job openings:

Infographic showing various Remote Infrastructure Security Engineer job openings in California as of August 2026, with employment types broken down into 84% Full Time, 14% Part Time, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $140,272 per year, or $67.4 per hour.

Product Security Engineer

Vercel

San Francisco, CA โ€ข On-site, Remote

Full-time

Re-posted 11 days ago


Key responsibilities

  • Build tooling to triage and validate bug bounty and external findings at scale by designing and operating systems that assess validity, severity, and reproducibility of vulnerabilities.

  • Develop agent-based reasoning systems to analyze business logic, authentication, and design-level findings beyond pattern matching.

  • Trace validated security findings back to their root cause to facilitate effective fixes and propose automated remediation solutions.


Job description

About Vercel:
Vercel is the agentic infrastructure company. We free people and agents to ship what's next.
For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.
Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.
We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. Whether you're building our products, supporting our customers, growing our community, or shaping our story, you'll help define what comes next.
About the Role:
Traditional product security teams work one report at a time: a person triages a bug bounty submission, validates it, reproduces it, and hands it off for a fix. That doesn't scale past a certain volume, and Vercel is well past it. Adding more triagers doesn't close that gap. Building the systems that triage at that scale does.
This role is about building that system. Your core focus is tooling that triages and validates bug bounty and other externally reported security findings at scale, reasoning about validity, severity, and reproducibility the way a human triager would, but continuously and at volume. And we want to go beyond triage. The real leverage is in connecting a validated finding to its root cause and driving the fix, ideally with the remediation itself proposed or opened automatically for well-understood vulnerability classes.
More broadly, this is a mandate to rethink traditional security tooling for how Vercel actually operates: agent-scale testing and automation in place of processes built for a much smaller company. This role also has real scope to build tooling that gives our customers their own security testing capabilities for what they build on Vercel, not just harden Vercel's own surface.
Because of this, we're optimizing for someone who wants to build systems, not someone whose background is manual penetration testing. A software engineer with a strong desire to move into security, or a security engineer with a strong engineering background, is exactly who we're looking for.
If you're based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday. If you're located beyond that distance, the role is fully remote. For location-specific details, please connect with our recruiting team.
What You Will Do:
  • Build tooling to triage and validate bug bounty and external findings at scale: Design and operate the systems that take in externally reported vulnerabilities and automatically assess validity, severity, and reproducibility, at a volume no manual triage process could match.
  • Push triage beyond pattern matching, into agentic analysis: Build and operate LLM/agent-based reasoning that can validate business logic, auth, and design-level findings, not just match against known signatures.
  • Go from validated finding to root cause: Trace validated findings back to the underlying pattern or class, so the team fixes the reason it happened, not just the one report that came in.
  • Build toward automated remediation, not just automated triage: Design systems that can propose, and increasingly open, the fix itself for well-understood vulnerability classes, with the right human review gates in place.
  • Rethink traditional security tooling for scale: Question which parts of the traditional product security toolkit (manual threat modeling, ad hoc code review, point-in-time pentests) still make sense at Vercel's scale, and build the agent-driven tooling that replaces or augments them.
  • Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement) as well as the internal tooling, so every report gets resolved and makes the automated triage smarter for the next one.
  • Build toward customer-facing security testing capabilities: Extend the tooling and automation you build for Vercel's own products into a capability customers can use to test the security of what they build and deploy on the platform.
About You:
  • You're a builder first: Strong software engineering background is more important here than classic penetration testing experience. You'd rather build the system that triages a thousand reports than work through them one at a time. We're equally excited by a software engineer who wants to move into security and a security engineer with a strong engineering background; a manual pentesting background alone is not what this role is optimized for.
  • Understand vulnerability triage and validation, even if that's not your primary background: You know (or can quickly learn) how to assess an externally reported finding, reproduce it, and judge severity, and you understand what makes that process hard to scale.
  • Curious about, or already building with, agentic and LLM-based security tooling: You have a point of view on where AI agents can reliably validate, root-cause, and fix vulnerabilities today, and where they can't yet.
  • Root cause and systems thinking: You default to "how do I make this scale to the next ten thousand reports" and "why did this class of bug happen," rather than closing the one ticket in front of you.
  • Comfortable defining a new practice: Agent-scale product security isn't a mature discipline yet. You're excited to help define what it looks like at Vercel rather than inherit a playbook.
  • Web tech stack proficiency: Strong familiarity with JavaScript/TypeScript and Node.js runtime security, and modern web frameworks (ideally Next.js or React and Node-based frameworks), so you can read and validate the code your tooling is analyzing.
Bonus If You:
  • Have built or contributed to security automation used broadly across an engineering org, not just for your own team.
  • Have experience running or triaging a bug bounty / vulnerability disclosure program.
  • Have experience testing or securing multi-tenant platforms where customer-built applications run on shared infrastructure.
  • Have built systems that auto-generate or auto-propose code fixes, not just findings.
  • Have thought about what security testing as a product capability could look like for a platform's customers.
  • Hold relevant security certifications or recognitions (for example, OSCP, OSWE, CISSP, or notable bug bounty hall of fame entries). These demonstrate your depth of knowledge, though they are not required.
Benefits:
  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.
The San Francisco, CA base pay range for this role is $208,000.00 - $312,000.00. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.