2

Remote Vulnerability Analyst Jobs in Waco, TX (NOW HIRING)

Senior Security Engineer

Waco, TX · Remote

$101K - $139K/yr

Director of Engineering Summary AxisCare is hiring a full-time, fully remote Senior Security ... When you flag a vulnerability, you can explain the fix, not just the finding. A pragmatist. You ...

Senior Security Engineer

Waco, TX · Remote

$117K - $160K/yr

Director of Engineering Summary AxisCare is hiring a full-time, fully remote Senior Security ... When you flag a vulnerability, you can explain the fix, not just the finding. A pragmatist. You ...

Remote Vulnerability Analyst information

See Waco, TX salary details

$27.5K

$65K

$115.4K

How much do remote vulnerability analyst jobs pay per year?

As of Sep 5, 2026, the average yearly pay for remote vulnerability analyst in Waco, TX is $65,038.00, according to ZipRecruiter salary data. Most workers in this role earn between $46,600.00 and $77,200.00 per year, depending on experience, location, and employer.

What is a remote vulnerability analyst?

A Remote Vulnerability Analyst is a cybersecurity professional who identifies, assesses, and helps mitigate security vulnerabilities in an organization's digital systems, typically while working from a remote location. They analyze networks, applications, and other IT assets to find weaknesses that could be exploited by cyber attackers. Their responsibilities often include conducting vulnerability scans, reviewing security reports, and collaborating with IT teams to recommend solutions. This role is crucial for proactively protecting sensitive data and ensuring the overall security posture of an organization.

What are the key skills and qualifications needed to thrive as a remote vulnerability analyst?

To thrive as a Remote Vulnerability Analyst, you need a strong understanding of cybersecurity principles, vulnerability assessment methodologies, and relevant security frameworks, typically backed by a degree in cybersecurity or related field. Familiarity with tools such as Nessus, Qualys, Burp Suite, and certifications like CEH or CompTIA Security+ are commonly required. Analytical thinking, attention to detail, and effective remote communication are essential soft skills for success in this position. These skills and qualities are crucial for accurately identifying and mitigating security risks, ensuring the protection of organizational assets in a remote work environment.

What are some common challenges faced by remote vulnerability analysts and how can they be addressed?

Remote Vulnerability Analysts often encounter challenges such as maintaining effective communication with on-site teams, staying updated with rapidly evolving security threats, and managing multiple vulnerability assessments simultaneously. To overcome these, it's important to utilize collaborative tools, participate in regular virtual meetings, and stay engaged with industry news and professional development. Building strong relationships with other cybersecurity professionals and leveraging automation tools can also help streamline workflows and ensure timely vulnerability remediation.

What is the difference between Remote Vulnerability Analyst vs Remote Security Analyst?

AspectRemote Vulnerability AnalystRemote Security Analyst
CertificationsCompTIA Security+, CEH, OSCPCompTIA Security+, CISSP, CEH
Work EnvironmentRemote, cybersecurity teams, vulnerability managementRemote, security operations centers, incident response
Industry UsageIT, cybersecurity firms, large enterprisesIT, government, financial institutions

Remote Vulnerability Analysts focus on identifying and assessing security weaknesses in systems, while Remote Security Analysts handle broader security monitoring, incident response, and policy enforcement. Both roles require similar certifications and often work remotely within cybersecurity teams, but their core responsibilities differ in scope and focus.

What are the most commonly searched types of Vulnerability Analyst jobs in Waco, TX?

The most popular types of Vulnerability Analyst jobs in Waco, TX are:

What are popular job titles related to Remote Vulnerability Analyst jobs in Waco, TX?

For Remote Vulnerability Analyst jobs in Waco, TX, the most frequently searched job titles are:

What job categories do people searching Remote Vulnerability Analyst jobs in Waco, TX look for?

The top searched job categories for Remote Vulnerability Analyst jobs in Waco, TX are:

What cities near Waco, TX are hiring for Remote Vulnerability Analyst jobs?

Cities near Waco, TX with the most Remote Vulnerability Analyst job openings:

Infographic showing various Remote Vulnerability Analyst job openings in Waco, TX as of June 2026, with employment types broken down into 72% Full Time, 27% Part Time, and 1% Contract. Highlights an 37% Physical, 4% Hybrid, and 59% Remote job distribution, with an average salary of $65,038 per year, or $31.3 per hour.

Senior Security Engineer

AxisCare

Waco, TX • Remote

$101K - $139K/yr

Full-time

Medical, Dental, Vision

Posted 23 days ago


Job description

Senior Security Engineer

Reports To: Director of Engineering


Summary

AxisCare is hiring a full-time, fully remote Senior Security Engineer to own security and compliance across our SaaS platform, the market-leading product powering the home care industry.

This is not a job where you'll write policies that nobody reads. You'll work directly with product engineering teams, embedded in how we build software, shaping our security posture. You'll own engineering's side of our SOC 2 Type II compliance program, lead us toward HITRUST certification, and keep our AWS infrastructure, Docker pipelines, and PHP/React codebase hardened as we move fast.


We're also building AI-powered products on top of Amazon Bedrock and our own machine learning models, and we use AI heavily in how we develop software. That creates new kinds of risk that most security playbooks don't cover yet. We need someone who's thinking about this already and building the guardrails that agents need to write secure software.

Home care agencies trust us to run their business every day. Their data includes protected health information. We need someone who takes that personally.


What You'll Do

Own AxisCare Engineering's security program as an individual contributor. Continually improve our security standards as threats evolve, strengthen the systems that enforce them, and work directly with engineers to close gaps.

Own engineering's share of SOC 2 Type II compliance: control design, evidence collection, audit prep, and gap remediation. Chart the path toward HITRUST certification, mapping what we already have and building what we don't.

Threat-model our application and infrastructure. We run a PHP/React modular monolith on AWS, managed with Terraform, deployed in Docker containers, backed by MySQL in RDS. Raise the bar on this stack's security (IAM policies, VPC design, secrets management, container security, database access controls) and keep raising it as the architecture evolves.

Own and improve our security scanning program. Tune findings, cut false positives, and make sure scan results turn into developer action.

Assess and mitigate the security risks inherent in our AI products: prompt injection, data leakage, model output filtering, abuse scenarios. Set guardrails for AI-assisted development workflows so the team ships faster without opening new attack surface.

Strengthen our detection and response capabilities: logging, alerting, incident response playbooks. Coordinate penetration tests, track findings, and drive remediation.

Keep our security policies clear, current, and short. Train developers on secure practices without burying them in process.


What We're Looking For

A builder, not just an auditor. You've built or run a security program inside a product company, not just assessed one from the outside. You can point to systems, controls, and habits you put in place that made a real difference.

A technical peer to engineers. You read code, read Terraform, and talk to developers in their language. When you flag a vulnerability, you can explain the fix, not just the finding.

A pragmatist. You understand that we need to ship. You weigh tradeoffs, probability, and impact, not by saying no to everything.

A strong writer. Remote work demands it, and clear writing is clear thinking. You'll write policies, incident reports, audit narratives, and messages to engineers explaining why something matters. Clarity counts.

An AI-aware security thinker. You're already wrestling with what AI means for security: new attack surfaces, new tooling, new ways that development workflows create risk.


Experience required:

  • 5+ years in application security, infrastructure security, or security engineering at a SaaS company
  • Hands-on experience with AWS security (IAM, VPC, Security Groups, KMS, CloudTrail, GuardDuty)
  • Experience owning or heavily contributing to the engineering side of SOC 2 Type II compliance
  • Familiarity with container security (Docker, Kubernetes) and infrastructure-as-code (Terraform)
  • Solid grasp of web application security fundamentals (OWASP Top 10, secure SDLC)
  • Experience securing AI/ML systems or LLM-powered products
  • Concrete examples of how you've used AI to improve your own security work: automating compliance tasks, speeding up threat analysis, building detection rules faster, or something we haven't thought of
  • Able to work remotely from the Eastern, Central, or Mountain time zones
  • Qualified to work in the United States or Canada


What We'd Be Excited to Find

  • Experience building or maintaining HIPAA-compliant or HITRUST-certified environments
  • CISSP, OSCP, or AWS Security Specialty certification
  • Background in penetration testing or red team work


Working Conditions

  • Manual dexterity required to use desktop computer and peripherals.


Compensation and Equipment

  • Salary (TBD based on job experience and skill level)
  • Medical insurance is covered in full for the employee (Medical, Dental, and Vision)
  • Company will provide laptop and other needed computer equipment


How to Apply

Apply with a brief resume and either a written or video cover letter.


We review the cover letter before anything else in your application, so this really matters. This is your single biggest opportunity to improve your chances, and video submissions go right to the front of the line.


Prompt: How has AI changed the security landscape you work in: what's gotten easier, what's gotten harder, and how have you adapted? Tell us about a security program, control, or hard problem you're proud of owning. Tell us why this position is the one you've been hoping to find.


Written: No more than 600 words. We're looking for clarity of thought and strong communication. Use AI if you want, but don't send slop.


Video: 1-2 minutes, linked in the "Website, Blog, or Portfolio" section of your application. Doesn't need to be highly produced. We care about how you think and communicate.


We strongly encourage candidates from all backgrounds and every walk of life to apply. Every person on our team brings their own unique perspective, and it's what makes our products better and our work more rewarding. We're eager to support you so that you can ship work you're proud of.


Candidates only. No recruiters, please.


About AxisCare

According to Pew Research, roughly 10,000 baby boomers turn 65 every day, and the American Society on Aging calculated that an American has a 70% chance of needing help with activities of daily living such as dressing, bathing, hygiene, etc. This has led to an unprecedented increase in Home Care agencies in the U.S. and abroad who strive to help those who have difficulty helping themselves, specifically offering non-medical (also referred to as non-skilled) services to seniors in their homes.


AxisCare was started in 2011 by industry leaders to help meet the demand for a more user-friendly and mobile-compatible solution. Our product is a web-based management platform that helps agencies manage CRM and marketing, Caregiver/Client scheduling, billing, payroll and much more. Headquartered in Waco, TX, AxisCare has clients in all 50 states as well as 6 other countries. We are a fast-growing company seeking high-performing individuals looking for a fast-paced, autonomous working environment.