Find your next role
Strengthen your profile
Average salary for remote Information Security Analyst jobs: $77K–$174K across all experience levels.

Tabula Rasa HealthCare - Digital Health & Health Tech - Large

DXC Technology - IT Services & IT Consulting - Large

LexisNexis Reed Tech - Information Services & Data Providers - Large

Elsevier - Information Services & Data Providers - XLarge

Interclypse - IT Services & IT Consulting - SME

LexisNexis France - Information Services & Data Providers - SME

Athelas - Digital Health & Health Tech - Scaleup

Proact Deutschland - IT Infrastructure & Managed Services

RELX - Information Services & Data Providers - XLarge

LexisNexis Risk Solutions - Data Analytics & Business Intelligence - XLarge

LexisNexis Risk Solutions Healthcare - Data Analytics & Business Intelligence

Interclypse - IT Services & IT Consulting - SME

Cision - Public Relations & Communications - Large

Cirium - Data Analytics & Business Intelligence - SME
Information security analysis at the senior level spans a broader scope than cybersecurity operations, encompassing the governance, risk, compliance, and policy dimensions of organizational security alongside technical controls. For senior information security professionals with 10 or more years of experience, this breadth is an advantage in the remote market: the GRC and policy layer of information security is particularly well-suited to distributed work because it is documentation-intensive, framework-driven, and conducted through stakeholder engagement rather than hands-on technical operations. The challenge is positioning that scope clearly in a market that applies cybersecurity and information security titles interchangeably while screening for very different profiles.
The information security analyst title covers a wide range of actual scope, from technical SOC analysis to risk assessment, policy development, compliance audit support, and vendor security review. At the GRC and compliance end, the qualified senior pool is smaller than the title frequency suggests, because the work requires both security depth and organizational communication capability. Senior professionals who have owned information security programs, developed and maintained security policies aligned to regulatory frameworks, managed third-party risk programs, and supported security certifications (ISO 27001, SOC 2, FedRAMP) are operating in a market with more open roles than qualified applicants. The CISO-track GRC profile in particular is consistently undersupplied at companies that are undergoing compliance certification for the first time.
Remote information security hiring is strong at the Senior Analyst and Information Security Manager level, particularly in the GRC and compliance domains. Companies that are pursuing security certifications, expanding into regulated markets, or building their third-party risk programs hire information security professionals remotely because the work is document and framework-based. Senior Information Security Analyst and Information Security Manager roles at SaaS companies undergoing SOC 2 certification, healthcare companies managing HIPAA compliance programs, and financial services companies building vendor risk management functions are among the most consistent remote hiring categories. Director of Information Security roles are increasingly remote at distributed technology companies.
Framework specificity is the first filter. Information security professionals who describe their compliance work in generic terms without naming the specific frameworks they have implemented or managed (ISO 27001, NIST CSF, SOC 2 Type II, HIPAA Security Rule, FedRAMP, PCI DSS) are consistently deprioritized by automated systems that treat framework names as required screening terms. A second filter is the program ownership signal: professionals who have supported compliance audits from an operational support role are screened differently from those who have built and owned the information security management system, and the distinction is not visible without explicit description of program ownership scope. Third, third-party risk management experience has become a specific screening criterion at the senior level as companies have formalized vendor security review programs, and professionals without documented TPRM experience are screened out of roles where it is a primary responsibility.
Explore more remote jobs:
Browse thousands of remote opportunities across all industries
11121 remote jobs
e.g.: GTM Engineer (Fully Remote), Marketing Operations Specialist
+6 new4413 remote jobs
e.g.: Human Resources Associate - Rollins School of Public Health, HUCA211: Recruiter
+1 new1421 remote jobs
e.g.: Senior Director Labor Relations, Demand Planner
New 2026 benchmark data from Greenhouse and Ashby shows why job boards drive most applications but a shrinking share of executive hires, and what to do with that gap instead of applying more.
Start ReadingA new Center for an Urban Future report shows entry-level tech postings in New York down 49 percent since 2022. Paired with PwC's 2026 Global AI Jobs Barometer, the data shows AI is not shrinking demand for experienced judgment, it is concentrating the damage at the entry point where that judgment has not been built yet.
Start ReadingA function-specific breakdown of the remote Finance Director market, what seniority level actually gets hired remotely, and how experienced finance leaders should position their scope to stand out.
Start Reading