OPT Cloud Security Architect Jobs
Cloud Security Architect jobs on OPT require employers willing to sponsor H-1B visas, since your work authorization window is limited to 12 months standard OPT or up to 36 months on STEM OPT extension. Most roles in this field qualify for STEM OPT because they fall under CIP codes tied to computer science or information security.
Find OPT Cloud Security Architect JobsOverview
Showing 5 of 12+ Cloud Security Architect jobs










See all Cloud Security Architect Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Cloud Security Architect roles.
Get Access To All Jobs
INTRODUCTION:
Founded on a legacy of more than 120 years in banking, Bank OZK is much more than just a company. We’re nationally recognized as an industry leader in financial services. That means we combine exceptional service with innovative technologies to deliver smart solutions to our clients across the country. We’re investing in small businesses, fueling economies in local communities and changing skylines in the largest cities across America. Here, we're not simply filling roles. We're fostering even greater careers.
The foundation for a great career starts with an exceptional team and a comprehensive benefits package. We believe in providing our dedicated team members with the best resources to support their physical, mental and financial wellbeing, including generous PTO, 401(k) matching, health, dental, vision (and pet!) insurance as well as special perks and discounts. Learn more about Bank OZK benefits.
JOB PURPOSE & SCOPE:
Responsible for ensuring the secure design, implementation, and operation of Bank OZK’s cloud environments. The Cloud Security Engineer works closely with IT, Labs, Data teams, Third-Party Risk Management, and application owners to implement cloud security controls and enforce compliance with Bank policies and industry regulations.
ESSENTIAL JOB FUNCTIONS:
- Supports the onboarding and risk assessment of new Cloud Service Providers (CSPs) through the Third-Party Risk Management (TPRM) process.
- Evaluates CSP security controls against Bank OZK’s Cloud Security Standard and regulatory requirements, ensuring that proposed cloud solutions meet all legal and compliance criteria before approval.
- Implements and maintains cloud security controls across SaaS, PaaS, and IaaS environments, applying Bank-approved secure configuration baselines (leveraging industry benchmarks like CIS) for cloud resources (VMs, containers, storage, etc.) and enforces “secure-by-default” settings during deployments.
- Collaborates with OZK Technology teams to design cloud architectures that incorporate network segmentation, encryption, and other security best practices from start to completion.
- Integrates cloud platforms and applications with the Bank’s centralized Single Sign-On (SSO) and identity management systems.
- Ensures that cloud activity logs are enabled, collected, and integrated with Bank OZK’s Security Information and Event Management (SIEM) and monitoring systems.
- Develop detections or alert rules to monitor cloud events for signs of compromise or policy violations.
- Investigates and responds to cloud security incidents in coordination with the Security Operations Center (SOC), helping to remediate issues and implement lessons learned.
- Manages cloud environments for security compliance and misconfigurations using automated Cloud Security Posture Management (CSPM) tools or scripts.
- Performs configuration audits and vulnerability scans of cloud assets and works with infrastructure and application teams to remediate identified weaknesses or document risk acceptances according to the Bank’s vulnerability management standards.
- Collaborates with software development teams and Application Security Engineers on secure deployment of cloud-native applications. Ensures cloud-hosted applications follow secure coding and deployment practices aligned with Bank standards (e.g. perform threat modeling, enforce secure SDLC requirements).
- Implements cloud-native application security controls such as web application firewalls (WAFs) for internet-facing apps and ensure proper network restrictions (security groups, private endpoints) for sensitive data stores.
- Embeds security into the CI/CD pipeline and infrastructure-as-code processes. Works with DevOps engineers to implement automated security checks for cloud infrastructure templates and application code (e.g. IaC scanning, container image scanning, secret leakage detection).
- Advises on secure configuration of CI/CD tools and use of secure secret management for pipeline credentials. Promote DevSecOps best practices so that security is an integral part of cloud deployment workflows.
- Provides guidance and training to IT cloud engineers, developers, and business units on cloud security requirements and secure cloud service usage.
- Ensures that cloud security controls and processes are well-documented and ready for audits or examinations.
- Provides evidence of compliance with the Bank’s Cloud Security Standard and applicable regulations during audits (internal, external, or regulatory). Address audit findings or recommendations related to cloud security by implementing corrective actions or process improvements.
- Stays current with relevant regulatory guidelines (e.g. FFIEC cloud computing guidance, NYDFS cybersecurity requirements).
- Stays informed on evolving cloud security threats, tools, and best practices, especially as they relate to financial institutions.
- Proactively recommend and implement enhancements to Bank OZK’s cloud security posture.
- Performs or assigns other tasks and assists other team members as necessary.
KNOWLEDGE, SKILLS & ABILITIES:
- Knowledge of integrating security testing tools into build/deployment pipelines and managing secrets for automation.
- Ability to work with DevOps/CI-CD pipelines and using Infrastructure-as-Code (Terraform, CloudFormation, etc.) in a secure manner.
- Advanced security-minded with the ability to assess risk in cloud architectures.
- Ability to consistently apply principles of confidentiality, integrity, and availability when evaluating cloud solutions and making risk-based decisions aligned with the Bank’s risk appetite.
- Strong diligence in configuring and reviewing cloud settings, logs, and processes to ensure nothing is overlooked. Vigilant in following through on issues until they are fully resolved and verified.
- Strong critical thinking skills to analyze complex technical problems or security events in cloud environments.
- Ability to break down problems, identify patterns or root causes, and develop effective solutions or mitigations.
- Ability to effectively communicate technical cloud security issues into business impact terms.
- Excellent interpersonal skills with an ability to work collaboratively on cross-functional teams, clearly articulate recommendations, and influence secure outcomes without formal authority.
- Ability to work in a fast-paced, evolving environment. Able to adjust to new cloud services, threats, and regulatory requirements as they emerge, updating strategies and tactics accordingly.
- Ability to be self-motivated and proactive. Takes ownership of projects and problems; drives improvements in cloud security practices without waiting for direction. Demonstrates a strong sense of responsibility and ethics, especially important in handling sensitive systems and data.
- Ability to demonstrate initiative to accomplish work objectives.
BASIC QUALIFICATIONS:
- Bachelor’s degree in Information Systems or related field; or commensurate work experience, required.
- Three (3) years’ work experience in a regulated financial institution or other heavily regulated environment, required.
- Familiarity with banking-specific security considerations and third-party risk management practices for cloud services, required.
- Professional security certifications related to cloud and information security (e.g., CCSP, CISSP, AWS/Azure Security Engineer, or CompTIA Security+), preferred.
JOB EXPECTATIONS:
Operate customary equipment and technology used in a business environment, with or without accommodation.
Note: This description is not an exhaustive list of all job functions, duties, skills, and job standards required. Other job functions, duties, skills, and standards may be added. Management reserves the right to add or change the job requirements at any time.
LI-KC1
EEO STATEMENT:
Bank OZK is an equal opportunity employer and gives consideration for employment to qualified applicants without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity, disability status, protected veteran status, or any other characteristic protected by federal, state, and local law. Member FDIC.
See all OPT Cloud Security Architect Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new OPT Cloud Security Architect Jobs.
Get Access To All JobsTips for Finding OPT Sponsorship in Cloud Security Architect
Target STEM OPT-eligible roles explicitly
Cloud Security Architect positions almost universally qualify for the STEM OPT extension under CIP codes 11.0101 or 14.0901. Confirm your degree field qualifies before applying so you can accurately tell employers you have up to three years of work authorization.
Prioritize large cloud-first employers
Companies with established cloud infrastructure teams, such as financial institutions, healthcare systems, and technology firms, are far more likely to have H-1B sponsorship pipelines already in place. Smaller startups often lack the legal infrastructure to sponsor efficiently.
Lead with certifications that signal immediate value
Certifications like AWS Security Specialty, CCSP, or Google Professional Cloud Security Engineer reduce employer hesitation about sponsorship costs. They demonstrate job-ready expertise and help justify the business case for sponsoring your H-1B petition.
Address your OPT timeline proactively in interviews
Bring up your authorization window yourself rather than waiting for employers to ask. Framing it clearly, including your STEM extension eligibility, removes ambiguity and positions you as someone who understands the process and has planned accordingly.
Build relationships within cloud security communities
Engage with cloud security professional groups and conferences where hiring managers participate directly. Referrals from trusted colleagues significantly reduce employer skepticism about sponsorship, because the candidate is already a known quantity before the conversation begins.
Research employer H-1B filing history before applying
The Department of Labor publishes LCA disclosure data showing which employers have filed for H-1B workers in cloud and security roles. Applying to employers with a consistent filing history dramatically increases your chances of receiving a sponsorship offer.
Cloud Security Architect OPT: Frequently Asked Questions
Do Cloud Security Architect jobs typically qualify for the STEM OPT extension?
Yes. Cloud Security Architect roles are classified under computer and information systems or engineering fields, which qualify for STEM OPT under CIP codes like 11.0101 (Computer and Information Sciences) and 14.0901 (Computer Engineering). If your degree falls under one of these codes, you're eligible for a 24-month STEM extension on top of your initial 12-month OPT, giving you up to 36 months of work authorization to secure H-1B sponsorship.
How hard is it to find Cloud Security Architect jobs that sponsor H-1B visas?
It's competitive but realistic. Cloud security is a high-demand specialty with a genuine talent shortage, which makes employers more willing to invest in sponsorship compared to generalist IT roles. Focusing your search on employers with a documented history of H-1B filings is the most effective filter. Migrate Mate is built specifically for OPT students and surfaces Cloud Security Architect roles from employers who actively sponsor visas, so you're not applying blind.
Can I work as a Cloud Security Architect on OPT without H-1B sponsorship right away?
Yes. During your OPT period, you're authorized to work full-time for any employer in a role related to your degree field without an H-1B petition. Sponsorship only becomes necessary when your OPT expires. If you qualify for STEM OPT, you have up to 36 months to find an employer who will file your H-1B petition before the deadline. Your employer must also enroll in E-Verify to support your STEM OPT extension.
What degree backgrounds support an OPT application for Cloud Security Architect roles?
The most common qualifying degrees include Computer Science, Cybersecurity, Information Systems, Computer Engineering, and Electrical Engineering. USCIS and employers both look for a direct connection between your degree field and the job duties. Cloud Security Architects who hold degrees in cybersecurity or computer science have the clearest path, but adjacent fields like information assurance or systems engineering can also qualify if the role description maps closely to your academic training.
What should I know about the E-Verify requirement for STEM OPT in this role?
For your STEM OPT extension to be valid, your employer must be enrolled in E-Verify, the federal electronic work authorization verification system. This is a non-negotiable requirement, not a preference. Before accepting a Cloud Security Architect offer contingent on STEM OPT, confirm the employer is actively enrolled in E-Verify. Many large technology and financial employers already are, but smaller firms or newer startups may not be, which would make you ineligible for the STEM extension regardless of your degree.