H-1B Visa Infrastructure Security Engineer Jobs
Infrastructure Security Engineer roles qualify for H-1B visa sponsorship as specialty occupations requiring at least a bachelor's degree in computer science, information security, or a related field. Employers filing LCAs with DOL must certify they're paying the prevailing wage for your specific location and job level, which directly affects your offer negotiation.
Find H-1B Visa Infrastructure Security Engineer JobsOverview
Showing 5 of 95+ Infrastructure Security Engineer jobs










See all 95+ Infrastructure Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Infrastructure Security Engineer roles.
Get Access To All Jobs
Google Infrastructure and Security Lead Architect
Join our AI & Engineering team in transforming technology platforms, driving innovation, and helping make a significant impact on our clients' success. You'll work alongside talented professionals reimagining and re-engineering operations and processes that are critical to businesses. Your contributions can help clients improve financial performance, accelerate new digital ventures, and fuel growth through innovation.
AI & Engineering leverages cutting-edge engineering capabilities to build, deploy, and operate integrated/verticalized sector solutions in software, data, AI, network, and hybrid cloud infrastructure. These solutions are powered by engineering for business advantage, transforming mission-critical operations. We enable clients to stay ahead with the latest advancements by transforming engineering teams and modernizing technology & data platforms. Our delivery models are tailored to meet each client's unique requirements.
Engineering as a Service provides complete design, implementation, and technology operations, leveraging our core engineering expertise. We transform engineering teams, modernize technology, and deliver complex programs with a product engineering approach. Our flexible delivery models-traditional teams, pools, or pods-are tailored to each client's needs, offering engineering-led advisory, implementation, and operational capabilities to accelerate innovation.
Recruiting for this role ends on 10-31-2026
Work you'll do:
As a Google Cloud (GCP) Infrastructure & Security Lead Architect, you will serve as a strategic technical leader and trusted advisor for our enterprise clients, guiding them through complex cloud transformation journeys. In this role, you will bridge the gap between high-level business objectives and deep technical execution, focusing on building scalable, highly available, and deeply secure cloud environments.
You will be responsible for the end-to-end design and implementation of foundational cloud architectures, from establishing secure multi-tenant landing zones and robust networking topologies to guiding application migration strategies. A critical component of this role is embedding security by design-leveraging Google Cloud's advanced security portfolio to protect workloads, secure data, and maintain continuous compliance against evolving cyber threats. You will collaborate closely with development, operations, and security teams to foster a culture of automation and DevSecOps excellence.
Responsibilities include:
- Architect and deploy highly scalable, multi-tenant GCP landing zones utilizing structured resource hierarchies (Organizations, Folders, Projects) tailored to client governance and billing requirements.
- Design centralized identity and access strategies leveraging Google Cloud Identity, Single Sign-On (SSO), and role-based access control (RBAC). Implement Context-Aware Access and the Principle of Least Privilege (PoLP) to secure human and machine identities.
- Standardize and automate the deployment of cloud infrastructure using Terraform. Develop modular, reusable infrastructure code to ensure consistent, repeatable, and auditable environment provisioning.
- Design and implement robust network topologies, including Shared VPCs, Hub-and-Spoke models, and isolated subnets to control traffic flow and minimize the blast radius of potential incidents.
- Architect highly available and secure connections between on-premises data centers and Google Cloud using Dedicated/Partner Interconnect or High Availability (HA) Cloud VPN.
- Secure inbound and outbound traffic flows by implementing Cloud Armor for WAF and DDoS protection, hierarchical firewall policies, and VPC Service Controls to prevent data exfiltration.
- Evaluate existing on-premises or multi-cloud legacy workloads to define optimal migration blueprints, utilizing industry-standard patterns.
- Architect and deploy highly scalable, multi-tenant GCP platform utilizing structured resource hierarchies (Organizations, Folders, Projects) tailored to client governance and billing requirements.
- Guide development teams in modernizing applications by adopting GCP managed services, serverless computing (Cloud Run, Cloud Functions), and container orchestration platforms (Google Kubernetes Engine - GKE).
- Collaborate with data architects to ensure real-time streaming and batch ingestion pipelines (e.g., Pub/Sub, Dataflow, BigQuery) are architected with strict security boundaries and encryption standards.
- Integrate and tune Google Cloud Security Command Center (SCC Premium) to provide unified visibility into misconfigurations, vulnerabilities, and active threats.
- Architect strategies for data security at rest and in transit using Cloud KMS (including Customer-Managed Encryption Keys), GCP Secret Manager, and Cloud Data Loss Prevention (DLP).
- Develop and implement organization policies and Google Cloud Policy Library rules to establish automated security guardrails that prevent non-compliant resource deployments.
Required Qualifications
- Bachelor's degree in computer science, Information Technology, Cybersecurity, or a closely related technical field (or equivalent practical experience).
- 7-10+ years of hands-on experience in cloud architecture, infrastructure engineering, or cloud security, with a significant portion of that time dedicated to Google Cloud Platform environments.
- Strong practical experience writing and maintaining Infrastructure as Code (IaC) using Terraform, alongside familiarity with CI/CD tools (e.g., GitHub Actions, GitLab CI, Cloud Build).
- Proven track record of participating in/or leading enterprise-scale cloud migrations and modernizing legacy infrastructure.
- Ability to travel up to 50% based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred Qualifications:
- 12+ years of comprehensive experience in cloud migration and security architecture, particularly in consulting, professional services, or client-facing advisory roles.
- Active status as a Google Cloud Professional Cloud Architect or Google Cloud Professional Cloud Security Engineer.
- Recognized cybersecurity certifications such as CISSP, CCSP, or CISM.
- Deep expertise in securing containerized workloads, Kubernetes (GKE) clusters, and microservice meshes (e.g., Anthos/Google Cloud Service Mesh).
- Strong ability to align technical designs with compliance frameworks such as NIST SP 800-53, CIS Benchmarks, SOC 2, HIPAA, or GDPR.
Wages + Salary
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $141,200 to $278,300.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
See all 95+ H-1B Visa Infrastructure Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new H-1B Visa Infrastructure Security Engineer Jobs.
Get Access To All JobsTips for Finding H-1B Visa Sponsorship as an Infrastructure Security Engineer
Verify your credentials match specialty occupation standards
USCIS requires your degree to directly relate to infrastructure security work. A degree in computer science, cybersecurity, or electrical engineering strengthens your petition. Unrelated degrees paired with security certifications like CISSP or CISM can still qualify but require stronger documentation.
Target employers with active LCA filing history
Use Migrate Mate to filter Infrastructure Security Engineer roles by employers who have filed LCAs for this occupation code. DOL disclosure data shows which companies sponsor consistently, so you're not guessing about sponsorship willingness before applying.
Check prevailing wage levels before accepting an offer
Run your target job title, location, and experience level through the OFLC Wage Search before negotiating. Your offered salary must meet the DOL wage level tied to your role. A Level I wage for a senior security engineer role can trigger an RFE.
Prioritize cap-exempt employers for faster timelines
Universities, nonprofit research institutions, and government-affiliated entities are cap-exempt and can file H-1B petitions year-round without the lottery. Infrastructure security roles exist at many of these organizations, and you'd start work within weeks of approval rather than waiting until October 1.
Confirm your employer uses E-Verify before the offer stage
STEM OPT extensions require your employer to be enrolled in E-Verify. If you're transitioning from OPT to H-1B, confirming E-Verify enrollment early prevents gaps in your authorization timeline if the lottery selection is delayed.
Document security clearance history for petition support
If you hold or have held a U.S. security clearance, include documentation in your H-1B petition package. Clearance eligibility signals employer investment and supports the specialty occupation argument, particularly for roles involving classified infrastructure or government contractor environments.
H-1B Visa Infrastructure Security Engineer: Frequently Asked Questions
Does an Infrastructure Security Engineer role qualify as a specialty occupation for H-1B purposes?
Yes. Infrastructure Security Engineer roles typically qualify because they require theoretical and practical application of highly specialized knowledge, and a bachelor's degree or higher in a directly related field like computer science, cybersecurity, or information systems is a standard entry requirement. USCIS evaluates the specific job duties and degree requirement stated in the LCA and petition, so your employer's job description needs to reflect genuine technical specialization, not generalist IT work.
Which employers are most likely to sponsor H-1B visas for infrastructure security roles?
Large technology companies, defense contractors, financial institutions, healthcare systems, and cloud infrastructure providers consistently file H-1B LCAs for security engineering roles. Cap-exempt employers like research universities and nonprofit hospitals are also strong options since they can sponsor outside the lottery window. Browse Infrastructure Security Engineer roles filtered by sponsorship history on Migrate Mate to see which companies have active LCA filings for this occupation.
How does the H-1B lottery affect Infrastructure Security Engineers specifically?
The annual H-1B cap of 65,000 regular slots and 20,000 U.S. master's exemption slots applies to most private-sector employers. If you hold a U.S. master's degree in a relevant field, you get two chances in the lottery, which statistically improves selection odds. Targeting cap-exempt employers, like universities or nonprofit research organizations with infrastructure security teams, eliminates lottery risk entirely.
Can a security clearance affect my H-1B petition for an infrastructure security role?
A clearance doesn't directly influence USCIS adjudication of the H-1B petition, but it affects the underlying job offer. Roles requiring an active clearance may limit the employer's ability to transfer sponsorship to a foreign national who isn't yet eligible, since clearance adjudication takes time. Confirm with your employer whether the role requires a clearance to start or only to advance, and get that distinction in writing before signing.
What happens to my H-1B status if I'm laid off from an infrastructure security role?
You have a 60-day grace period after your employment ends to find a new H-1B sponsor, transfer your petition, or change to another nonimmigrant status. During this window you can't work, but the clock starts from your last day of employment. If you're actively job searching, filing an H-1B transfer with a new employer during the grace period maintains your lawful status. USCIS requires the new petition to be filed before the 60 days expire.