H-1B Visa IT Security Engineer Jobs
IT Security Engineer roles qualify for H-1B visa sponsorship as specialty occupations requiring at least a bachelor's degree in computer science, cybersecurity, or a related field. Most sponsoring employers in this field file during the April cap season, though cap-exempt research institutions and universities hire year-round.
Find H-1B Visa IT Security Engineer JobsOverview
Showing 5 of 96+ IT Security Engineer jobs










See all 96+ IT Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new IT Security Engineer roles.
Get Access To All Jobs
TG IT Application Security Manager
Date: Sep 16, 2026
Location: Lakewood, US
Company: Terumo BCT, Inc.
Requisition ID: 35487
At Terumo Blood and Cell Technologies, our 8,000+ global associates proud to come to work each day, knowing that what we do impacts the lives of patients around the world. For Terumo, for Everyone, Everywhere.
We make medical devices and related products that are used to collect, separate, manufacture and process various components of blood and cells. With our innovative technologies and service offerings, we touch a patient’s life every second of every day and are committed to continuing to increase the number of patients we serve. Advancing healthcare with heart.
With some of the best and brightest minds in the industry, an unmatched global footprint, comprehensive benefits and a distinct culture, Terumo Blood and Cell Technologies is a great place to work, grow and be part of a team that is focused on making a difference. Join us and help shape wherever we go next. You create your future and ours.
Application Security Manager
JOB SUMMARY
Enterprise Application Portfolio - The Application Security Manager is responsible for leading the organization's Application Security program, ensuring that security is integrated throughout the Application Cycle (SDLC). This role partners closely with the software teams, cloud, architecture, infrastructure, and potentially product teams to identify, assess, and mitigate application security risks while enabling secure software delivery.
The successful candidate will lead a team of application security analysts, establish secure development standards, oversee security testing programs, and drive adoption of security best practices aligned with industry standards such as NIST SP 800-218 (Secure Software Development Framework), NIST Cybersecurity Framework (CSF) 2.0, OWASP, and CIS Controls.
Employment Type: Full-time
Department: Global Cybersecurity
Role Reports to: Security Operations Leader
Location: Americas
Work Arrangement: Hybrid
Scope: Regional
ESSENTIAL DUTIES
Application Security Leadership
- Collaborate with other global and regional leaders within to develop the enterprise Application Security strategy.
- Lead, mentor, and develop Application Security Analysts.
- Define AppSec metrics, KPIs, and maturity goals in collaboration with regional and global security leaders.
Secure Software Lifecycle
- Integrate security into all phases of the enterprise application portfolio.
- Ensure security requirements are incorporated during design and architecture reviews.
- Promote security-by-design principles across application teams.
Security Testing
Manage and oversee:
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- Interactive Application Security Testing (IAST)
- API Security Testing
- Container Security
- Infrastructure as Code (IaC) Security
- Mobile Application Security Testing
- Secrets Detection
- Review findings, prioritize remediation, and validate fixes.
- Assist in Supply Chain Security
Threat Modeling
- Facilitate threat modeling sessions with development teams.
- Identify abuse cases and attack paths.
- Recommend architectural improvements.
- Ensure high-risk applications undergo formal security architecture reviews.
Vulnerability Management
- Establish application vulnerability management processes
- Prioritize remediation using risk-based methodologies
- Track remediation SLAs
- Report vulnerability metrics to executive leadership
- Coordinate penetration testing remediation activities
- Threat Intelligence
Cloud Application Security
Support secure development within cloud platforms including:
- AWS
- Microsoft Azure
- Google Cloud Platform
Secure Code Reviews
- Conduct manual secure code reviews
- Review high-risk applications
- Provide secure coding guidance
- Coach development teams on remediation
API Security
- Establish and set-up safe rules
- Find weak spots through testing
- Monitor logs to spot shadow APIs and strange traffic patterns
Security Awareness
Collaboration on training programs covering:
- OWASP Top 10
- Secure Coding
- API Security
- Cloud Security
- Common software vulnerabilities
- Secure design principles
Application Risk Management
- Perform application security risk assessments.
- Support enterprise application risk management initiatives.
Incident Response
Support cyber incident response by:
- Investigating application security incidents.
- Supporting forensic analysis.
- Identifying root causes.
- Leading post-incident reviews.
- Developing preventive controls.
Compliance
Support compliance initiatives including:
- NIST CSF 2.0
- NIST SP 800-218 (SSDF)
- NIST SP 800-53
- OWASP ASVS
- PCI DSS
- HIPAA
- SOX
- ISO/IEC 27001
- SOC 2
MINIMUM QUALIFICATION REQUIREMENTS
Education
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field.
- Master's degree preferred.
Experience
- 8–10+ years of cybersecurity experience.
- 5+ years in Application Security.
- 3+ years leading security teams.
- Experience implementing enterprise DevSecOps programs.
- Experience working with Agile and CI/CD environments.
-
Experience with cloud-native application security.
-
Or -
An equivalent competency level acquired through a variation of these qualifications may be considered.
Certificates, Licenses, Registrations
- CISSP
- CSSLP
- GIAC Web Application Penetration Tester (GWAPT)
- GIAC Secure Software Programmer (GSSP)
- Certified Cloud Security Professional (CCSP)
- Certified Information Security Manager (CISM)
- Microsoft Certified: Cybersecurity Architect Expert
- Microsoft Certified: Azure Security Engineer Associate
Korn Ferry Competencies
Leadership Competencies
- Strong people leadership
- Strategic planning
- Executive communication
- Stakeholder management
- Cross-functional collaboration
- Risk-based decision making
- Program management
- Coaching and mentoring
- Conflict resolution
- Continuous improvement mindset
Key Performance Indicators (KPIs)
- Critical vulnerability remediation SLA compliance
- Mean time to remediate (MTTR)
- Percentage of applications covered by SAST, DAST, and SCA
- Security defects identified pre-production
- Reduction in high-risk application vulnerabilities
- CI/CD pipeline security coverage
- Secure code review completion rate
- Threat model completion rate
- Developer secure coding training completion
- Penetration test remediation completion
- Application security maturity score
- Audit and compliance findings related to application security
Physical Requirements
(for US only)
Typical Office Environment requirements include: reading, speaking, hearing, close vision, traverse, bending, sitting, and occasional lifting up to 20 pounds.
Target Pay Range: $121,400.00 to $151,800.00 - Salary to be determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, and alignment with market data
Target Bonus on Base: 15.0
We anticipate this requisition will be open for a minimum of five days, from 09/16/2026. We encourage your prompt application.
At Terumo Blood and Cell Technologies, we provide competitive total reward offerings that consist of compensation, benefits, recognition, along with a wealth of other well-being, work-life and recognition programs which support in unlocking the potential for you and your family. Included in our expansive list of benefits offerings are multiple group medical, dental and vision plans, a robust wellness program, life insurance and disability coverages, also a variety of voluntary programs such as group accident, hospital indemnity, critical illness, pet insurance and much more. To help you save for retirement, we offer a 401(k) plan with a matching contribution and for work-life balance we have vacation and sick time programs for associates. For us, it’s about protecting the personal welfare of our associates and their families, helping to achieve personal goals and offering those extra touches for convenience, security and overall peace of mind.
We are proud to be an Equal Opportunity Affirmative Action Employer. All applicants will be afforded equal opportunity without discrimination because of race, color, religion, sex, gender identity or expression, sexual orientation, marital status, order of protection status, national origin or ancestry, citizenship status, age, physical or mental disability unrelated to ability, military status or an unfavorable discharge from military service.
Job Segment: Testing, Cloud, Developer, Military Intelligence, Computer Science, Technology, Government
See all 96+ H-1B Visa IT Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new H-1B Visa IT Security Engineer Jobs.
Get Access To All JobsTips for Finding H-1B Visa Sponsorship as an IT Security Engineer
Align your credentials to SOC codes
Your LCA is filed under a specific SOC code, typically 15-1212 (Information Security Analysts). Confirm your target employers are filing under that code, not a broader IT category, so prevailing wage levels accurately reflect your role.
Use OFLC Wage Search before negotiating
Look up the prevailing wage for your target metro area using OFLC Wage Search before you receive an offer. Employers must pay at least the DOL wage level tied to your experience, and knowing Level II versus Level III thresholds strengthens your negotiating position.
Target employers with active security clearance programs
Defense contractors and federal IT firms sponsor H-1B roles but often require clearances you can't hold until you're a permanent resident. Filter your search to commercial sector employers or contractors whose roles don't list clearance as a requirement.
Check filing history by occupation on Migrate Mate
Search IT Security Engineer roles on Migrate Mate to see which employers have verified H-1B LCA filing history for this specific occupation, not just general IT roles. That filing history tells you sponsorship is real, not just a checkbox on a job posting.
Get your specialty occupation documentation ready early
USCIS scrutinizes IT security roles for specialty occupation status. Prepare a detailed job duties letter, your transcripts showing a cybersecurity or computer science degree, and any certifications like CISSP or CISM before your employer files the I-129.
Understand the 60-day grace period if you're between jobs
If your H-1B employment ends, you have a 60-day grace period to find a new sponsoring employer and file a transfer petition. Don't wait until day 55 to start the process because your new employer's attorney needs time to prepare the I-129 and LCA.
H-1B Visa IT Security Engineer: Frequently Asked Questions
Does an IT Security Engineer role qualify as a specialty occupation for H-1B purposes?
Yes. USCIS recognizes IT Security Engineer positions as specialty occupations when the role requires at least a bachelor's degree in computer science, information security, or a directly related field. Job postings that list a degree as preferred rather than required can create problems during adjudication, so confirm the offer letter specifies the degree as a minimum requirement before your employer files the I-129.
Which employers sponsor H-1B visas for IT Security Engineers?
Technology companies, financial institutions, healthcare systems, and defense contractors are the most active H-1B sponsors for IT Security Engineer roles. Migrate Mate shows verified LCA filing history by employer and occupation code, so you can identify which specific companies have sponsored this role rather than relying on general reputation. Cap-exempt employers like universities also hire for security roles year-round outside the April lottery window.
How does the H-1B prevailing wage requirement affect IT Security Engineer offers?
Your employer must certify through the LCA that your offered salary meets the DOL prevailing wage for your job title, experience level, and work location. IT Security Engineer wages vary significantly by metro area, so a Level II wage in a lower-cost market will be substantially different from Level III in a high-cost city. Use OFLC Wage Search to look up the exact threshold before you receive an offer.
Can I transfer my H-1B to a new employer if my IT security role changes?
Yes, H-1B portability lets you start working for a new employer once they file a transfer petition, without waiting for approval, as long as your prior H-1B was approved and you haven't fallen out of status. If your new role has meaningfully different duties or a different SOC code than your original petition, your employer's attorney should document the continuity carefully to avoid a Request for Evidence from USCIS.
Do security certifications like CISSP or CISM help with H-1B specialty occupation approval?
Certifications strengthen your petition but don't substitute for a qualifying degree. USCIS evaluates specialty occupation based on whether the role normally requires a specific bachelor's degree, not on professional certifications alone. That said, CISSP and CISM can support arguments about the complexity and specialization of the role, particularly if USCIS issues an RFE questioning whether a general IT degree is directly related to your security-focused duties.