- The remote cybersecurity roles that exist right now
- Why SOC analyst and penetration tester jobs are the trap
- James: helpdesk to remote GRC analyst in nine months
- The step-by-step route in if you're starting from zero
- What nobody selling you a certification will say
- Certifications worth paying for, and ones that are just expensive PDFs
- Red flags in "remote cybersecurity" job ads
- Frequently asked questions
- Official documentation
Straight answer: The remote-friendly cybersecurity jobs that exist from day one are GRC and compliance analyst, cloud security engineer, threat intelligence analyst, vulnerability management analyst, security technical writer, and bug bounty work, paying roughly £40k to £130k depending on level and country. SOC analyst and penetration testing jobs get advertised as remote far more often than they are truly remote, and the difference between those two lists is where most job seekers waste six months.
The remote cybersecurity roles that exist right now
I have spent the last few years watching hiring pages for clients who want their own team trained on this, and interviewing people who've made the jump, so this list is built from actual job postings and pay bands, not a bootcamp brochure.
- GRC (Governance, Risk and Compliance) analyst, £40k to £65k in the UK, $70k to $110k in the US. This is the most reliably remote role in the whole field, because the job is documents, spreadsheets, audits, and calls, not a server room. Companies like Vanta, Drata, and OneTrust build software for this exact function and hire remote analysts constantly.
- Cloud security engineer, £55k to £95k UK, $110k to $160k US. Needs AWS or Azure experience already, so it's rarely an entry point, but it's one of the least location-dependent roles in tech because the infrastructure itself lives in the cloud.
- Threat intelligence analyst, £45k to £75k UK, $75k to $120k US. Reading feeds, writing reports, tracking actor groups. Fully doable from a spare room, and firms like Recorded Future and Mandiant hire remote analysts across time zones because threats don't sleep either.
- Vulnerability management analyst, £42k to £70k UK, $80k to $115k US. Running scans, triaging findings, chasing IT teams to patch things. Tools like Tenable and Rapid7 sit at the centre of this and the work is entirely screen-based.
- Security technical writer, £35k to £55k UK, $65k to $95k US. If you can write clearly and understand security concepts, this is a quieter route in. It overlaps heavily with the kind of work covered in freelance writer positions, except the pay is better because the subject matter is specialist.
- Bug bounty hunter, wildly variable. Median payout per bug on HackerOne or Bugcrowd is low, often £50 to £300, but the top 1% of researchers clear six figures a year. This is the closest thing on this list to freelance income rather than a salary, so treat it like the gig work covered in online jobs from home, not a stable career start.
- Security awareness and training specialist, £38k to £58k UK. Building phishing simulations, writing internal training, running the "don't click that" campaigns. Almost always remote because the audience is spread across offices anyway.
Why SOC analyst and penetration tester jobs are the trap
These two get the most job ad clicks and the least honest treatment. A Tier 1 SOC analyst role in the US pays $55k to $70k, in the UK £28k to £35k, and the job ad almost always says "remote." What it usually means is remote after a training period of three to twelve months onsite, and shift work that includes nights and weekends because a security operations centre has to be watched around the clock. I've had two separate contacts tell me they accepted a "remote" SOC role and spent their first eight months driving to an office for a rotating 11pm to 7am shift before the fully remote part kicked in. If overnight shift patterns don't scare you off, it's worth reading overnight jobs that pay well before you sign anything, because the pay premium for nights in security is smaller than in most other fields.
Penetration testing is similar in a different way. The skill itself, breaking into systems on purpose, is very much doable from home, and plenty of testers at firms like Bishop Fox and Trail of Bits work fully remote. But client engagements sometimes require onsite social engineering or physical security testing, and junior testers get pulled into that far more than senior ones. If you want pure remote pentest work, you're aiming for a mid-level role at a firm with a fully distributed culture, not an entry-level one.
James: helpdesk to remote GRC analyst in nine months
A reader who emailed me after one of my talks, I'll call him James because he asked me not to use his real name, spent six years on an IT helpdesk in Leeds earning £24k. He was bored, capable, and stuck. He took an ISO 27001 Lead Implementer course online for £495, spent his evenings for four months building a portfolio site that documented a mock SOC 2 readiness assessment for a fictional company, and applied to 53 remote GRC and compliance roles.
He got four interviews and one offer, from a challenger bank, at £46k, fully remote, one video call a week with the rest handled async through Slack and a shared risk register. His previous six years of helpdesk experience mattered more in that interview than the certificate did, because it proved he could talk to non-technical staff about risk without making them feel stupid, which is most of what a GRC analyst does day to day. That soft skill is undervalued by almost every course selling you into this field.
The step-by-step route in if you're starting from zero
- Pick a lane based on your tolerance for shifts and math. If you hate irregular hours, cross SOC analyst off the list. If you're not comfortable with scripting, cross cloud security engineer off for now.
- Get one credential that proves baseline knowledge. CompTIA Security+ costs around $404 to sit and is the most widely recognised entry-level cert. For the GRC route, an ISO 27001 Lead Implementer or Lead Auditor course, typically £400 to £900, does more for your CV than a generic security cert.
- Build proof, not just paper. Document a mock risk assessment, write up a fake incident response plan, or complete rooms on TryHackMe and publish notes on a simple site. Hiring managers in this field say repeatedly that a visible portfolio beats a certificate with nothing behind it.
- Apply through the right channels. Cyberseek.org tracks real open roles by category, We Work Remotely lists distributed-first companies, and going straight to career pages at Vanta, Drata, GitLab, and Okta puts you in front of companies that hire remote by default rather than as an exception.
- Ask the one question that saves you six months: in the interview, ask directly, "is this role remote from day one, or after a training or probation period." Recruiters will answer honestly if you ask it plainly, because they don't want the churn either.
What nobody selling you a certification will say
The uncomfortable part of this whole industry is that the "cybersecurity skills gap" everyone quotes to sell bootcamps and certifications is real at the senior level and almost fictional at the entry level. Companies say they need three million more cybersecurity workers globally, and then post entry-level jobs asking for two to three years of experience, because what they lack is experienced mid-level staff, not warm bodies with a fresh certificate. A £3,000 bootcamp will not skip you past that requirement. What does work is exactly what James did: existing IT or customer-facing experience, one focused credential, a visible portfolio, and a lot of applications. There is no shortcut version of this that a course provider will tell you, because the shortcut doesn't exist.
The other thing rarely said out loud: remote cybersecurity pay is not automatically higher than office-based pay, and in some cases it's lower, because companies hiring remote-first are often competing on flexibility rather than salary. If your main goal is maximum pay, a hybrid role at a bank in London or New York will often beat a fully remote role at a smaller SaaS company doing the same job. Choose which trade-off matters to you before you start applying, not after you get an offer.
Want AI doing the heavy lifting in your marketing?
I build the systems that handle the boring 80 percent, so you get your week back. Done properly, with the human kept in.
Certifications worth paying for, and ones that are just expensive PDFs
- Worth it: CompTIA Security+ for a general entry point, ISC2's CISSP once you have four to five years of experience across two domains, OSCP if you want penetration testing and are willing to grind a hard practical exam, and ISO 27001 Lead Implementer or CISA for the GRC and compliance route.
- Skip or deprioritise: any certification whose entire selling point is "no experience needed, get hired in weeks." Vendor-specific badges from tools you haven't used on the job rarely move the needle on their own. And a general "cybersecurity fundamentals" certificate from a platform you've never heard a hiring manager mention is not worth the £200 to £600 it usually costs.
Red flags in "remote cybersecurity" job ads
- The ad promises "$100k+ with no experience." Real entry-level pay in this field, remote or not, sits closer to $55k to $70k in the US and £28k to £40k in the UK.
- The listing says "remote" but the shift pattern section mentions rotating on-call or 24/7 coverage without naming a training location. That usually means onsite first, remote later.
- The role is titled "cybersecurity analyst" with no specialism attached (not SOC, not GRC, not cloud) and the job description reads like a marketing page rather than a task list.
- The company has no clear security product or client base you can find on LinkedIn or its own site. Legitimate remote security employers, from Rapid7 to Coalition, have visible security teams and public case studies.
If you're weighing this against other home-based options while you build toward it, it's worth comparing pay bands against the wider list in remote jobs that pay well, and if you need something paying now while you study for a cert, the weekly-paying options in legitimate work from home jobs that pay weekly can bridge the gap without derailing the plan.
Related guides live in the Remote Jobs and Work From Home: 47 Guides to Real Jobs, Pay and Spotting Scams.
A closely related walkthrough: How Do You Find Work From Home Customer Care Roles That Pay.
Related: the cybersecurity page.
Frequently asked questions
Can you get a cybersecurity job with no experience and work from home immediately?
Rarely for SOC or penetration testing roles, but it's more possible in GRC and compliance if you come from an adjacent background like IT support, audit, or customer success, combined with one focused certification and a visible portfolio piece.
What is the highest paying remote cybersecurity role?
Cloud security engineer and senior penetration tester roles typically top the pay scale among remote-friendly positions, ranging from $110