Tracking 100,000+ career sites

Senior Cybersecurity Jobs

Built from a 20M+ job database and updated hourly, this list surfaces senior cybersecurity roles across security engineering, architecture, operations, consulting, and cyber risk.

Titles can include senior security engineer, cybersecurity architect, cloud or application security engineer, detection engineer, incident responder, security operations lead, security consultant, governance or cyber-risk manager, and security engineering director. The underlying work spans preventive controls, threat detection, incident response, architecture reviews, vulnerability management, identity, compliance, and security strategy. Team placement can shape the job: some postings describe close work with engineering, while others center on operations, risk, assurance, or client advice. Advisory positions may add deliverables and recommendations for several stakeholder groups. Seniority is reflected in authority over risk decisions, ownership during incidents, scope of systems protected, influence on architecture, and responsibility for mentoring or managing teams. Separate technical specialist and principal roles from governance or people-leadership positions, even when their titles use similar security language.

Classify the function as engineering, operations, incident response, architecture, advisory work, assurance, or governance. That choice determines whether cloud and security tools, threat expertise, certifications, policy knowledge, or stakeholder influence should carry the most weight. Identify the assets and users being protected, the decisions the role can make, and who accepts residual risk. Next verify clearance requirements, on-call duties, travel, management scope, and reporting line in the original posting. If technical scenarios, architecture reviews, incident walkthroughs, or risk discussions are named, prepare evidence for those steps rather than assuming a universal security interview. Company, location, industry, compensation, and sponsorship filters can narrow the set. Consider pay with call burden, onsite constraints, team maturity, and authority to change systems; confirm authorization and residency language at the source.

The list is free to browse and filter. A free account is optional for saved cybersecurity roles, application tracking, and Copilot. A short note on security domain and operating responsibility makes later comparisons clearer.

6,144
roles in this list
1,631
added this week
Featuring roles at
Canva
Netflix
Notion
Visa
Capital One
& 100K+ more

Explore More

Related Job Lists

Curated lists closely related to this one — similar roles, industries, and locations.

Senior Information Technology Jobs icon

Senior Information Technology Jobs

This list tracks 100K+ company job sources and updates hourly with senior information technology roles across IT management, systems, technical support, service delivery, security, and enterprise technology. Openings may be titled senior systems engineer, IT manager or director, service-delivery manager, enterprise applications leader, technical-support lead, infrastructure manager, technology-risk professional, or IT transformation leader. Work can include operating networks and endpoints, managing identity and enterprise systems, leading support, overseeing vendors and budgets, improving service processes, governing security and risk, or delivering modernization programs. Financial services, healthcare, manufacturing, consulting, government, and software employers differ in scale, regulatory pressure, legacy systems, and service expectations. Judge seniority through the business criticality and breadth of systems owned, decision authority, budget and vendor responsibility, escalation duties, and the size and structure of the team. A senior engineer may remain an expert individual contributor, while a director may be evaluated on operating performance, workforce planning, governance, and executive communication. Map the operating model before comparing tool lists. Establish which systems and users the team supports, whether services are run internally or with vendors, and whether the remit is operations, support, governance, applications, or transformation. Note which service levels, budgets, and security or business risks sit with the position. Then review required platforms, certifications, clearance, on-call expectations, service-management practices, regulatory knowledge, budget responsibility, and team resources at the source. Any described assessment can guide preparation for troubleshooting, architecture, service, incident, vendor, or change-management scenarios. Employer, location, industry, compensation, and sponsorship filters can reduce the inventory. Compare disclosed pay and bonuses with call burden, workplace and travel requirements, and the condition of the environment being inherited. Browsing and filtering are free. A free account can save IT roles, record application progress, and provide Copilot for selected forms. Keep the systems boundary and service expectations in the application record, with the source posting as the final check.

Senior DevOps and Infrastructure Jobs icon

Senior DevOps and Infrastructure Jobs

This list is updated hourly from 100K+ company job sources and surfaces senior DevOps and infrastructure roles across CI/CD, SRE, platform engineering, systems, networks, databases, and observability. Openings may be labeled senior DevOps engineer, site reliability engineer, platform engineer, infrastructure engineer, systems or network engineer, database administrator, production engineer, or infrastructure lead. Responsibilities can include deployment automation, internal developer platforms, Kubernetes operations, network and database reliability, monitoring, capacity planning, incident response, and modernization of core systems. The balance between software development, platform enablement, and direct operations varies by team and should be clear in the source description. Some postings measure the role through developer adoption and delivery speed; others focus on availability, recovery, capacity, or safe change. Seniority is reflected in production ownership, architectural judgment, incident command, automation depth, and the ability to reduce recurring operational work. Staff and principal roles may set technical direction without direct reports; managers and operations leaders can add staffing, service-level, and escalation responsibilities. Production responsibility is the most useful starting point. Determine whether the engineer owns services, a shared platform, networks, databases, or an operating process, and how much of the work is software development versus administration. Then verify the cloud and operating environment, coding and infrastructure-as-code tools, container stack, observability systems, security or clearance needs, on-call rotation, and role during high-severity incidents. Look for evidence of who sets service objectives, approves risky changes, and follows remediation work after an incident. A disclosed interview plan may call for coding, systems design, troubleshooting, or incident examples; tailor preparation to the ownership described. Compare pay with call frequency, remote-access limits, and platform maturity. Company, location, compensation, and sponsorship filters refine the list, while the original posting controls authorization and workplace requirements. The list remains free to browse and filter. An optional free account keeps saved infrastructure roles and application progress together and offers Copilot for selected forms. Revisit any saved posting before applying.

Senior Cloud Engineer Jobs icon

Senior Cloud Engineer Jobs

Updated hourly from a 20M+ job database, this list surfaces senior cloud engineer roles across AWS, Azure, Google Cloud, platform engineering, migration, security, and reliability. Openings can include senior or principal cloud engineer, cloud architect, cloud platform engineer, infrastructure engineer, site reliability engineer, cloud security engineer, and engineering manager. Day-to-day work may involve designing landing zones and network boundaries, migrating applications, codifying infrastructure, operating Kubernetes, improving observability and resilience, controlling cloud cost, or setting security and governance standards. Some roles focus on a shared internal platform; others are tied to a particular product, migration, security program, or operating environment. Migration-led work may have defined transition milestones, while platform ownership continues through capacity, incident, and lifecycle decisions. Seniority depends on the systems and failure modes owned, autonomy in architecture decisions, incident leadership, and influence across development, security, and operations teams. Staff or principal openings may lead through expertise, while management roles can add staffing, service-health, and roadmap responsibilities. A useful first split is architecture and migration work versus ongoing platform and reliability ownership. From there, compare the required cloud provider with the broader networking, security, automation, and distributed-systems knowledge the role expects. The source posting should clarify infrastructure-as-code tools, container or serverless environment, certification or clearance requirements, travel, workplace terms, and whether production support includes an on-call rotation. Determine whether the team consumes an existing cloud foundation or owns the controls and services other teams depend on. If an interview format is described, prepare system-design, troubleshooting, automation, security, or incident examples appropriate to that platform boundary. Employer, location, compensation, and sponsorship filters can narrow results, but authorization and remote-work conditions should be confirmed in the original listing. No account is needed to browse or filter. A free account can hold saved cloud roles and application stages, with Copilot available for forms you choose to complete. Keep provider and on-call details attached to the relevant role.

Got questions?

Explore our FAQ section to learn more.

Recognizable employers to research include Microsoft, Google, Amazon, Palo Alto Networks, CrowdStrike, Cisco, JPMorgan Chase, Capital One, Deloitte, and major healthcare organizations. Security vendors hire people to build and defend security products, while banks, retailers, hospitals, and cloud providers maintain large internal teams for their own systems. Consultancies and managed security providers offer client-facing work across several environments. Government agencies and defense contractors are another major market, though many positions require citizenship or a clearance. Check each employer's careers site for security engineering, operations, application security, cloud security, incident response, threat research, and governance roles.

The field has several distinct paths. Security engineers build controls and automation. Security operations teams monitor threats and respond to incidents. Application and product security specialists work with developers to prevent flaws before release. Cloud security, identity, threat research, governance, risk, and security architecture have their own hiring tracks. Senior candidates can also move into program leadership or management. Titles are inconsistent, so compare the work product and the team served. Decide whether you prefer building systems, investigating adversaries, advising business teams, or setting organization-wide standards, then look for roles where your previous evidence matches that daily work.

Certifications help when an employer, customer contract, or regulated framework names them, and when they support a move into a new specialty. Broad credentials can confirm experience for governance or leadership roles, while technical certifications may help in cloud security, offensive testing, incident response, or specific vendor environments. They carry particular weight in consulting and government contracting. At senior level, however, employers still expect evidence of investigations, engineering work, risk decisions, or programs you owned. Check experience prerequisites and renewal obligations before paying. A certification chosen because it appears repeatedly in your target postings is more useful than the credential receiving the most attention online.

Show the risk or operational problem, the action you owned, and what changed. Strong examples include reducing detection time, closing a class of vulnerabilities, improving access controls, building a response process, automating repetitive analysis, or helping a product pass a demanding review. Use numbers only when they are meaningful and safe to disclose. Describe incidents without exposing confidential details, customer names, or defensive gaps. Senior work often succeeds by preventing events, so explain the evidence used to judge improvement, such as coverage, test results, audit findings, or recovery time. Separate your contribution from the work of the broader security team.

Interviews usually combine technical depth with risk judgment. You may investigate a hypothetical alert, review an architecture, identify abuse paths, prioritize vulnerabilities, or explain how you would contain an incident. Engineering roles can include coding or automation, while governance positions may use policy, audit, or stakeholder scenarios. Senior candidates should expect questions about a decision made with incomplete information and a time they disagreed with another technical team. State assumptions and explain what evidence would change your answer. Prepare examples that show both immediate response and the slower work of removing the condition that allowed a problem to occur.

Ask which events page the team, how frequently that happened in the last quarter, and whether the role is first response or escalation. Find out who can isolate systems, contact customers, or stop a release during an emergency. A healthy program has documented roles, realistic staffing, useful alerts, and time after an incident to correct underlying weaknesses. Ask how investigations are reviewed and whether blame interferes with reporting mistakes. Global coverage can reduce overnight work, but only if handoffs are clear. Also confirm compensation or recovery time, because a demanding rotation changes the real value of an otherwise attractive offer.

Yes. Staff, principal, architect, distinguished engineer, and senior research roles can carry substantial influence without direct reports. Individual contributors may set security standards, lead incident investigations, review major designs, build shared controls, or advise executives on technical risk. They often mentor colleagues and coordinate work across teams, which is leadership even though it is not people management. Ask for the technical career ladder and examples of decisions made by people above the senior level. Some companies use impressive titles without granting authority or pay comparable to management, so compare actual scope, promotion criteria, and access to decision makers rather than relying on the title.

Most commercial security jobs do not require citizenship, and some employers sponsor experienced candidates. The restricted part of the market is still significant. Positions that require access to classified national security information generally require US citizenship and an employer-sponsored clearance. Government contracts may impose additional requirements, while some commercial roles limit access because of customer rules or regulated data. A public-trust background check is not the same as a security clearance, so read the wording carefully. Current work authorization and future visa sponsorship are separate issues. Confirm both with recruiting and treat this as general information rather than legal advice.