H-1B Visa Application Security Engineer Jobs
Application Security Engineer roles qualify as H-1B visa specialty occupations under USCIS guidelines, requiring at least a bachelor's degree in computer science, cybersecurity, or a related field. Employers filing H-1B visa petitions for this role must certify a prevailing wage through a DOL Labor Condition Application before your petition can be approved.
Find H-1B Visa Application Security Engineer JobsOverview
Showing 5 of 159+ Application Security Engineer jobs










See all 159+ Application Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Application Security Engineer roles.
Get Access To All Jobs
Job Function: Research & Development
Location:
Stafford, TX, US, 77477
Work Location (for field-based positions):
Work Flexibility: Hybrid
Pay Range: $101,800 - $132,300
Job ID: 5566
Why KARL STORZ?
At KARL STORZ, we are driven by innovation and a commitment to improving patient outcomes through cutting-edge medical technology. As a global leader in endoscopy and medical imaging, we offer an environment where collaboration, technical excellence, and continuous learning are highly valued. Join a team where your cybersecurity expertise will directly contribute to the development of secure, compliant, and life-changing healthcare technologies.
Position Summary
The Application Security Engineer III serves as the technical lead for cybersecurity compliance and secure product development initiatives, with primary responsibility for achieving and maintaining Department of Defense (DoD) Authorization to Operate (ATO) certifications under the Risk Management Framework (RMF). This role partners closely with Software Engineering, Systems Engineering, Quality, Regulatory, and Product Management teams to ensure products meet cybersecurity requirements throughout the development lifecycle.
Key Responsibilities
DoD RMF & ATO Leadership
- Lead and maintain DoD Authorization to Operate (ATO) certifications.
- Serve as the primary cybersecurity contact for DoD-related projects.
- Manage RMF compliance activities, including STIG and SCAP scanning, POA&M management, and risk mitigation planning.
- Author and maintain cybersecurity documentation, risk analyses, and compliance reports.
- Support certification audits, renewals, and customer-facing cybersecurity reviews.
Product Security & Verification
- Verify cybersecurity requirements through testing, documentation, and validation activities.
- Partner with engineering teams to implement secure development practices.
- Support threat modeling, vulnerability management, and security testing throughout the SDLC.
- Participate in product security reviews and provide risk mitigation recommendations.
DevSecOps & Security Operations
- Design and maintain DevSecOps pipelines with automated security testing and vulnerability scanning.
- Support secure CI/CD practices and compliance monitoring.
- Establish and maintain cybersecurity lab environments and test infrastructure.
Cross-Functional Collaboration
- Collaborate with R&D, Quality, Regulatory, IT, Operations, and Product Management teams.
- Communicate cybersecurity risks, requirements, and recommendations to technical and non-technical stakeholders.
- Participate in customer meetings, technical reviews, and occasional on-site visits.
Qualifications
Required
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related technical field.
- 5+ years of cybersecurity experience (4+ years with a Master's degree).
- Experience supporting application, product, or embedded cybersecurity in regulated industries such as medical devices, defense, or aerospace.
- Hands-on experience with DoD RMF, STIGs, SCAP tools, and POA&M management.
- Knowledge of NIST frameworks, including NIST 800-53 and NIST 800-171.
- Experience with secure software development, vulnerability management, risk assessment, and DevSecOps practices.
- Experience with Windows and Linux hardening, network security, and system compliance validation.
- Strong communication, analytical, organizational, and problem-solving skills.
Preferred
- Experience obtaining or maintaining DoD ATO certifications.
- Knowledge of FDA cybersecurity guidance and medical device security standards.
- Certifications such as CISSP, Security+, CEH, or GSEC.
- Experience with cloud security, container security, and automated testing frameworks.
- Experience working in Linux, Windows Server, virtualized environments, and network security architectures.
- Master's degree in a related technical discipline.
Additional Information
Travel: Up to 10%
Physical Requirements: Ability to sit for extended periods and lift equipment up to 20 pounds occasionally.
Work Environment: Fast-paced, collaborative environment supporting highly regulated medical technology products.
Eligible Employee Benefits
- Medical / Dental / Vision including a state-of-the-art wellness program and pet insurance, too!
- 3 weeks vacation, 11 holidays plus paid sick time
- Up to 8 weeks of 100% paid company parental leave; includes maternal/paternal leave, adoption, and fostering of a child.
- 401(k) retirement savings plan providing a match of 60% of the employee’s first 6% contribution (up to IRS limits)
- Section 125 Flexible Spending Accounts
- Life, STD, LTD & LTC Insurance
- We prepay your tuition up to $5,250 per year! - Tuition pre-reimbursement
- Fitness reimbursement of up to $200 annually
- And much more!
KARL STORZ reserves the right to change or modify the employee’s job description whether orally or in writing, at any time during the employment relationship. Additionally, KARL STORZ, through its supervisors, may require an employee to perform duties outside their normal description within the sole discretion of the supervisor. Employees must comply with all applicable KARL STORZ policies and procedures.
KARL STORZ is committed to creating an inclusive space where employees are valued for their skills and unique experiences. To achieve this goal, we are committed to diverse voices, and all applicants will receive consideration without regard to race, color, sex, national origin, disability, veteran status, or any other protected characteristic. KARL STORZ is also committed to providing reasonable accommodations during our recruitment process. Should you need assistance or accommodation please email us at taoperations@karlstorz.com.
See all 159+ H-1B Visa Application Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new H-1B Visa Application Security Engineer Jobs.
Get Access To All JobsTips for Finding H-1B Visa Sponsorship as an Application Security Engineer
Map your degree to the SOC code
USCIS evaluates specialty occupation eligibility by matching your degree field to the job's SOC code. For Application Security Engineer roles, the relevant O*NET profile lists computer science, information security, and software engineering as qualifying degree fields.
Verify the prevailing wage before accepting
Run the OFLC Wage Search using the Application Security Engineer SOC code and the employer's worksite zip code. If the offered salary falls below the Level I or Level II wage, the DOL will reject the LCA and block your H-1B filing.
Target E-Verify enrolled employers early
STEM-adjacent roles like Application Security Engineer attract employers already enrolled in E-Verify, which is required for any sponsor filing cap-subject H-1B petitions. Filter your search on Migrate Mate to surface employers with active H-1B LCA filing history in security roles.
Document hands-on security certifications strategically
USCIS RFEs for security engineer roles often challenge whether the position truly requires a specific degree rather than broad IT experience. Certifications like OSCP, CEH, or CISSP strengthen the specialty occupation argument when your job duties include penetration testing or secure architecture design.
Confirm the employer files cap-subject or cap-exempt petitions
Universities, nonprofit research organizations, and government-affiliated entities can file cap-exempt H-1B petitions year-round with no lottery. If you're already on OPT, a cap-exempt employer in application security gives you an H-1B path outside the annual registration window.
Negotiate premium processing into your offer timeline
Application Security Engineer roles often involve security clearance timelines or project start dates that can't wait five to seven months for standard USCIS adjudication. Ask the employer to include premium processing in the offer letter before you sign, not after.
H-1B Visa Application Security Engineer: Frequently Asked Questions
Does an Application Security Engineer role qualify as an H-1B specialty occupation?
Yes. USCIS classifies Application Security Engineer positions as specialty occupations because the role normally requires a bachelor's degree or higher in computer science, cybersecurity, software engineering, or a closely related field. Employers strengthen the petition by documenting that the specific duties, including threat modeling, code review, or penetration testing, require that theoretical and practical expertise.
Which employers actively sponsor H-1B visas for Application Security Engineer roles?
Technology companies, financial institutions, cloud infrastructure providers, and defense contractors are the most active H-1B sponsors for Application Security Engineer positions, based on DOL LCA disclosure data. Migrate Mate surfaces employers with verified H-1B filing history in security engineering roles, so you can prioritize outreach to organizations that have already navigated the sponsorship process.
Can I transfer my H-1B to a new employer for an Application Security Engineer position?
Yes. Under H-1B portability rules, you can start working for a new employer as soon as the new I-129 petition is filed with USCIS, without waiting for approval, as long as you've been in valid H-1B status for at least 180 days. The new employer must file a fresh LCA certified to the Application Security Engineer wage level at the new worksite location.
How does the DOL prevailing wage apply to Application Security Engineer H-1B filings?
Before filing your H-1B petition, your employer must submit an LCA to the DOL certifying they'll pay at least the prevailing wage for Application Security Engineer roles in the worksite's metropolitan area. Wages are set at four levels based on experience and complexity. You can verify the applicable wage using the OFLC Wage Search before evaluating any offer.
What documentation should I prepare if USCIS issues an RFE for my Application Security Engineer H-1B?
RFEs for security engineer roles typically challenge either specialty occupation status or the degree-to-job-duty match. Prepare a detailed job duty breakdown showing that the role requires security-specific theoretical knowledge, not just general IT skills. Supporting evidence includes org charts showing the role alongside other degreed engineers, job postings for similar roles, and industry standards from professional bodies like NIST or ISC2.