Every network has a weak point somewhere β a misconfigured port, an outdated patch, a login someone forgot to disable. Finding it before someone else does is the entire job. We're hiring a Remote IT Security Analyst to protect a global client's digital infrastructure, working fully remote while carrying real responsibility for how secure that infrastructure actually is.
The Scope of the Role
This position covers the full lifecycle of security work: spotting risks, responding to incidents, testing for weaknesses, and ensuring policy keeps pace with an environment that never stays still for long. It's a role for someone who treats security as an ongoing discipline rather than a checklist to be cleared once and moved past.
Core Duties
Risk and Incident Management
You'll assess and mitigate risk across networks, systems, and applications, and when something does go wrong, you're the one monitoring the breach, containing it, and tracing the root cause so it doesn't happen twice.
Testing and Auditing
Regular vulnerability scans and penetration testing are your responsibility, along with system audits to ensure everything remains aligned with compliance standards and internal policy.
Policy and Threat Awareness
You'll draft and enforce security policy that actually reflects current regulatory requirements, while keeping an eye on emerging threat intelligence so the team isn't caught reacting instead of preparing.
People and Reporting
Security isn't purely technical. You'll work alongside developers and IT teams to implement protections, train staff on avoiding common security mistakes, and prepare reports that give leadership a clear picture of risk and compliance status.
Qualifications
A Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field is required, along with a minimum of 5 years of hands-on professional experience in IT securityβspecifically in threat management, incident response, and risk assessment βnot just adjacent IT work.
On the technical side, you should be able to configure and troubleshoot network defenses such as firewalls and endpoint protection software, and know your way around systems designed to detect intrusions before they cause damage. Hands-on time with SIEM platforms such as Splunk, QRadar, or ArcSight matters here, as does practical penetration testing using tools like Metasploit, Nessus, or Wireshark. You'll also need to be sufficiently fluent in regulatory frameworks β GDPR, HIPAA, ISO 27001 β to apply them in real-world situations, not just recognize the acronyms.
Certifications
CISSP, CISM, CEH, CompTIA Security+, and GIAC are all viewed favorably. None are an absolute requirement if your practical experience is strong, but any of them will move your application to the top of the pile.
Skills That Set Candidates Apart
- Cloud security experience with AWS, Azure, or Google Cloud
- Familiarity with DevSecOps practices and secure coding standards
- Exposure to AI-assisted threat detection tools
- A track record working remotely with globally distributed teams
Working Remotely on This Team
Location flexibility is real here, but so is the expectation of independence. Nobody's going to remind you when a scan is overdue or a report is due to leadership. You'll coordinate with IT teams and stakeholders across time zones, which occasionally means adjusting your hours around a global handoff. Naukri Mitra works with clients specifically seeking analysts who can operate independently while remaining genuinely connected to the broader security team.
Compensation and What's Included
This role pays
$140,000 annually. Along with that:
- Full flexibility to work from any suitable remote location
- Health, dental, and vision coverage
- Paid time off that's meant to be used, not just accrued
- Support for certification renewals and continued professional development
- Ongoing exposure to a wide range of security challenges across industries and technology stacks
What Strong Candidates Tend to Have in Common
The analysts who do well in roles like this think in terms of risk rather than rules alone. They pick up on something being slightly off before it becomes a formal incident. They write policy that engineers actually follow instead of quietly working around, and they can explain a technical vulnerability to a non-technical stakeholder without losing the room halfway through.
What's Genuinely Demanding About It
Threats don't evolve on a convenient schedule, so staying current is a baseline expectation, not an occasional task. Incidents can land outside normal hours, and remote work means managing your own focus without anyone physically checking in. This isn't unique to this role β it's simply what serious security work looks like day-to-day.
Apply
If protecting a global organization's digital footprint sounds like meaningful work rather than just a job description, we'd like to hear from you. Submit your application with a summary of relevant experience and certifications, and we'll follow up with next steps.