Code and Theory Visa Sponsorship USA
Code and Theory is a digital-first creative agency known for blending design, strategy, and technology for major brands. It sponsors a modest but consistent range of visa types, including H-1B and E-3, making it a viable target for international creative and tech professionals navigating the U.S. job market.
See All Code and Theory JobsOverview
Showing 5 of 14+ Code and Theory Visa Sponsorship USA jobs


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?
See all 14+ Code and Theory Visa Sponsorship USA jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Code and Theory Visa Sponsorship USA roles.
Get Access To All Jobs
INTRODUCTION
We are seeking a Security Officer to lead security, privacy, and compliance for our SaaS products and the client projects we deliver as an agency. You will own this capability end to end, from new business through implementation, certification, and ongoing monitoring. This role is central to how we win and deliver projects, protect client and company data, and earn trust through clear, high quality security and privacy practices.
You will be responsible for audit readiness, ensuring applicable privacy requirements are met, and establishing the standards, processes, and tooling needed to run an effective security and privacy program.
WHAT YOU’LL DO
- Leadership:
lead our security program across SaaS products and client projects, setting strategy, priorities, and measurable outcomes
- Certifications:
lead SOC 2 Type II, ISO 27001, and ISO 42001 readiness and ongoing compliance, including control design, evidence processes, and auditor coordination. Own ISMS and AI governance documentation and oversight
- Privacy:
lead privacy governance and operational practices, ensuring compliance with applicable requirements including HIPAA, GDPR, and CCPA/CPRA, and addressing data handling, contractual privacy terms, and privacy by design expectations
- SDLC:
partner with delivery teams to embed security and privacy into how we build, with clear expectations, practical review gates, and patterns for common risks (identity, access, data handling, multi-tenancy, logging, and auditability)
- Project Delivery:
establish a repeatable client engagement security plan for client work (environment segregation, access provisioning and deprovisioning, client data handling, incident coordination, and delivery requirements)
- Third Party Risk:
lead vendor security reviews, including due diligence for critical providers, remediation tracking, and ongoing monitoring
- Customer Assurance:
support customer assurance efforts including security questionnaires, RFPs, client security reviews, and maintaining trust artifacts and standard responses
- Incident Response:
maintain an incident response program (playbooks, escalation, exercises) and drive post incident improvements
- Culture:
build a security and privacy culture through clear guidance, lightweight training, and day to day partnership with teams
WHAT YOU’LL NEED
- Experience:
8+ years of progressive experience in information security, including leadership in SaaS and/or professional services environments
- Security Fundamentals:
strong understanding of modern application and cloud security fundamentals (identity and access, encryption and key management, logging and monitoring, vulnerability management)
- Certifications:
demonstrated ownership of SOC 2 Type II and ISO 27001 programs from readiness through steady state operations
- Privacy:
strong working knowledge of privacy requirements and practices, including HIPAA, GDPR, and CCPA/CPRA, and experience operationalizing privacy controls in product and client delivery contexts
- Execution:
experience building security and privacy processes that work in real delivery environments
- Communication:
clear communication skills, able to represent security and privacy with internal teams, auditors, and client stakeholders with differing levels of technical fluency
- Distributed Teams:
comfortable operating across a geographically dispersed organization and coordinating work across time zones
NICE TO HAVES
- Agency:
experience in an agency or consulting environment supporting multiple client projects in parallel
- AI:
experience supporting AI-enabled products and data flows, including model and data risk considerations and familiarity with ISO 42001
- Cloud:
expertise in at least one major cloud platform (GCP, AWS, or Azure) and common SaaS security patterns
- Operations:
experience with security monitoring, incident response, and vulnerability management programs in production environments
- Tooling:
hands on experience with security tooling across CI/CD, cloud infrastructure, vulnerability scanning, and logging and monitoring workflows
- Certifications:
relevant security and/or privacy certifications such as CISSP, CISM, CCSP, CIPP, CIPT
About us
Born in 2001, Code and Theory is a digital-first creative agency that sits at the center of creativity and technology. We pride ourselves on not only solving consumer and business problems, but also helping to establish new capabilities for our clients. With a global client roster of Fortune 100s and start-ups alike, we crave the hardest problems to solve. With a remote-first approach to our people, we have teams distributed across North America, South America, Europe, and Asia. The Code and Theory global network of agencies is growing and includes Kettle, Instrument, Left Field Labs, Mediacurrent, Rhythm, and TrueLogic.
Striving never to be pigeonholed, we work across every major category: from tech to CPG, financial services to travel & hospitality, government and education to media and publishing. We value the collaboration with our client partners, including but not limited to Adidas, Amazon, Con Edison, Diageo, EY, J.P. Morgan Chase, Lenovo, Marriott, Mars, Microsoft, Thomson Reuters, and TikTok.
The Code and Theory network comprises nearly 2,000 people with 50% engineers and 50% creative talent. We’re always on the lookout for smart, driven, and forward-thinking people to join our team.
The target range of base compensation for this role is $140,000 - $175,000. Actual compensation is influenced by a wide array of factors including but not limited to skill set, level of experience, and location.

INTRODUCTION
We are seeking a Security Officer to lead security, privacy, and compliance for our SaaS products and the client projects we deliver as an agency. You will own this capability end to end, from new business through implementation, certification, and ongoing monitoring. This role is central to how we win and deliver projects, protect client and company data, and earn trust through clear, high quality security and privacy practices.
You will be responsible for audit readiness, ensuring applicable privacy requirements are met, and establishing the standards, processes, and tooling needed to run an effective security and privacy program.
WHAT YOU’LL DO
- Leadership:
lead our security program across SaaS products and client projects, setting strategy, priorities, and measurable outcomes
- Certifications:
lead SOC 2 Type II, ISO 27001, and ISO 42001 readiness and ongoing compliance, including control design, evidence processes, and auditor coordination. Own ISMS and AI governance documentation and oversight
- Privacy:
lead privacy governance and operational practices, ensuring compliance with applicable requirements including HIPAA, GDPR, and CCPA/CPRA, and addressing data handling, contractual privacy terms, and privacy by design expectations
- SDLC:
partner with delivery teams to embed security and privacy into how we build, with clear expectations, practical review gates, and patterns for common risks (identity, access, data handling, multi-tenancy, logging, and auditability)
- Project Delivery:
establish a repeatable client engagement security plan for client work (environment segregation, access provisioning and deprovisioning, client data handling, incident coordination, and delivery requirements)
- Third Party Risk:
lead vendor security reviews, including due diligence for critical providers, remediation tracking, and ongoing monitoring
- Customer Assurance:
support customer assurance efforts including security questionnaires, RFPs, client security reviews, and maintaining trust artifacts and standard responses
- Incident Response:
maintain an incident response program (playbooks, escalation, exercises) and drive post incident improvements
- Culture:
build a security and privacy culture through clear guidance, lightweight training, and day to day partnership with teams
WHAT YOU’LL NEED
- Experience:
8+ years of progressive experience in information security, including leadership in SaaS and/or professional services environments
- Security Fundamentals:
strong understanding of modern application and cloud security fundamentals (identity and access, encryption and key management, logging and monitoring, vulnerability management)
- Certifications:
demonstrated ownership of SOC 2 Type II and ISO 27001 programs from readiness through steady state operations
- Privacy:
strong working knowledge of privacy requirements and practices, including HIPAA, GDPR, and CCPA/CPRA, and experience operationalizing privacy controls in product and client delivery contexts
- Execution:
experience building security and privacy processes that work in real delivery environments
- Communication:
clear communication skills, able to represent security and privacy with internal teams, auditors, and client stakeholders with differing levels of technical fluency
- Distributed Teams:
comfortable operating across a geographically dispersed organization and coordinating work across time zones
NICE TO HAVES
- Agency:
experience in an agency or consulting environment supporting multiple client projects in parallel
- AI:
experience supporting AI-enabled products and data flows, including model and data risk considerations and familiarity with ISO 42001
- Cloud:
expertise in at least one major cloud platform (GCP, AWS, or Azure) and common SaaS security patterns
- Operations:
experience with security monitoring, incident response, and vulnerability management programs in production environments
- Tooling:
hands on experience with security tooling across CI/CD, cloud infrastructure, vulnerability scanning, and logging and monitoring workflows
- Certifications:
relevant security and/or privacy certifications such as CISSP, CISM, CCSP, CIPP, CIPT
About us
Born in 2001, Code and Theory is a digital-first creative agency that sits at the center of creativity and technology. We pride ourselves on not only solving consumer and business problems, but also helping to establish new capabilities for our clients. With a global client roster of Fortune 100s and start-ups alike, we crave the hardest problems to solve. With a remote-first approach to our people, we have teams distributed across North America, South America, Europe, and Asia. The Code and Theory global network of agencies is growing and includes Kettle, Instrument, Left Field Labs, Mediacurrent, Rhythm, and TrueLogic.
Striving never to be pigeonholed, we work across every major category: from tech to CPG, financial services to travel & hospitality, government and education to media and publishing. We value the collaboration with our client partners, including but not limited to Adidas, Amazon, Con Edison, Diageo, EY, J.P. Morgan Chase, Lenovo, Marriott, Mars, Microsoft, Thomson Reuters, and TikTok.
The Code and Theory network comprises nearly 2,000 people with 50% engineers and 50% creative talent. We’re always on the lookout for smart, driven, and forward-thinking people to join our team.
The target range of base compensation for this role is $140,000 - $175,000. Actual compensation is influenced by a wide array of factors including but not limited to skill set, level of experience, and location.
Job Roles at Code and Theory Companies
How to Get Visa Sponsorship in Code and Theory Visa Sponsorship USA
Target roles at the intersection of design and technology
Code and Theory's sponsorship history skews toward specialized roles in digital strategy, UX, and engineering. Focus your application on positions where creative and technical skills overlap, these are most likely to meet visa specialty occupation requirements.
Australian citizens should specifically explore the E-3 pathway
Code and Theory has sponsored E-3 visas, making it worth pursuing for Australian nationals. The E-3 requires less employer overhead than the H-1B, which can make agencies more willing to sponsor it for strong candidates in creative and strategy roles.
Understand that agency hiring cycles follow client demand
Marketing and advertising agencies like Code and Theory staff up around project wins and client growth. Time your outreach to coincide with major campaign seasons or publicly announced client partnerships, when headcount needs are highest and sponsorship conversations are more natural.
Lead with your portfolio before raising sponsorship
In the creative industry, work speaks first. Get a recruiter genuinely interested in your portfolio before the sponsorship question comes up, agencies are far more likely to initiate the conversation themselves when they're already sold on your capabilities.
Filter for verified sponsors before applying
Not every agency that posts jobs will sponsor visas. Migrate Mate surfaces verified sponsors so you can filter by real sponsorship history, helping you focus time on companies like Code and Theory that have an active track record rather than guessing from job descriptions.
F-1 OPT and CPT candidates have a clear entry point
Code and Theory supports F-1 OPT and CPT, giving international students a practical way to build experience within the agency. Strong performance during OPT is often the most direct path to a longer-term sponsorship conversation for H-1B or other visa types.
Code and Theory jobs are hiring across the US. Find yours.
Find Code and Theory JobsSee all 14+ Code and Theory jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Code and Theory roles.
Get Access To All JobsFrequently Asked Questions
Does Code and Theory sponsor H-1B visas?
Yes, Code and Theory sponsors H-1B visas. Its sponsorship activity is modest rather than high-volume, which is typical for a mid-sized creative agency in the marketing and advertising space. Sponsored roles tend to require specialized skills in areas like digital strategy, product design, or engineering, positions where the specialty occupation standard is clearly met.
Which visa types does Code and Theory sponsor?
Code and Theory sponsors H-1B, E-3, F-1 OPT, F-1 CPT, and TN visas. This range covers a meaningful cross-section of international applicants, from Australian nationals on the E-3 to students on OPT and Canadian or Mexican professionals on TN status. The breadth of visa types suggests a genuine willingness to work through sponsorship for the right candidates.
What departments or roles at Code and Theory are most likely to receive visa sponsorship?
Sponsorship at agencies like Code and Theory typically concentrates in roles that require demonstrable specialized expertise, think UX design, data analytics, software engineering, and digital strategy. Generalist or account management roles are less likely to clear the specialty occupation bar. If your background sits at the technical or creative-technical intersection, you're in the strongest position to be considered for sponsorship.
How do I find open visa-sponsored jobs at Code and Theory?
Migrate Mate is the most direct way to find open roles at Code and Theory that come with verified sponsorship history. Rather than combing through generic job postings and guessing whether sponsorship is available, Migrate Mate lets you filter by company and visa type so you can apply with confidence that sponsorship is actually on the table.
How do I approach the application process at Code and Theory as an international candidate?
Lead with your work and expertise rather than opening with visa questions. Recruiters at creative agencies respond to portfolios and demonstrated results first. Once there's mutual interest, raise your visa status clearly and early in the formal interview process. Code and Theory's track record across multiple visa types suggests familiarity with the process, so a straightforward conversation about your status is unlikely to derail a strong candidacy.
See which Code and Theory employers are hiring and sponsoring visas right now.
Search Code and Theory Jobs