OPT Information Security Analyst Jobs
Information Security Analyst roles qualify as specialty occupations under OPT, making them strong candidates for H-1B visa sponsorship. Most positions require a degree in cybersecurity, computer science, or information systems. STEM OPT extension eligibility gives you up to 36 months of authorized work, a significant advantage in a field with high employer demand.
Find OPT Information Security Analyst JobsOverview
Showing 5 of 244+ Information Security Analyst jobs










See all 244+ Information Security Analyst Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Information Security Analyst roles.
Get Access To All Jobs
Job Description:
We Deliver the Goods: Competitive pay and benefits, including Day 1 Health & Wellness Benefits, Employee Stock Purchase Plan, 401K Employer Matching, Education Assistance, Paid Time Off, and much more
Growth opportunities performing essential work to support America’s food distribution system
Safe and inclusive working environment, including culture of rewards, recognition, and respect
Position Summary:
Performance Food Group is looking for a talented Information Security Analyst to play a key role in supporting Information and Privacy Risk Management aspects of the company as a member of the Information Security Department. PFG is in the midst of establishing a Risk Management function that focuses on identifying, quantifying, communicating, and tracking risks associated with information assets. Reporting to the Manager of Information Security Risk Management and working with IT and line of business stakeholders, the analyst will have a heavy focus on compliance with internal/external policies/statutes, IT Risk Management, and Third Party Risk.
Position Responsibilities:
- Conduct risk assessments and maintain risk register. Perform assessments of IT controls processes, and systems, identifying gaps and opportunities to enhance design/operational effectiveness while reducing the cost of compliance. Conduct periodic readouts and risk reviews with IT teams and segment/line of business stakeholders to convey risk and influence decision making
- Assist in maintaining security exception lifecycle, including qualifying associated risk, determining compensating controls, communicating with IT and LOB stakeholders.
- Assist in development of evaluative risk frameworks for new and emerging technologies, including but not limited to Artificial Intelligence
- Maintain Business Impact Analysis. Work with IT and LOB teams to maintain Business Impact Analysis, establishing risk categorizations for applications and infrastructure based on mission criticality and sensitivity of hosted data.
- Assist in development and implementation of Enterprise Crown Jewels program. Work with IT, LOB teams, and security control owners to define and govern control parameters for critical applications and technologies.
- KPI/KRI Development and Reporting. Assist in development of control-based Key Risk Indicators and Key Performance Indicators across business segments. Assist in developing associated governance model and metric tiers for consumption by various levels of stakeholders, up to and including the Board of Directors.
- Support IT Risk and exception management governance forums across business segments with varying operational models and business context.
- Support PFG’s Third Party Risk Management Program, assessing third parties for inherent and residual risk based on the nature of their services and their ability to appropriately secure PFG data and provide dependent services.
- Negotiate the inclusion of security requirements into third party contract agreements.
- Develop and Maintain IT Audit and Control documentation.
- Support necessary governance forums (committees, working groups) to ensure sound decision-making and stakeholder communications.
- Identify and report on non-compliance with regulatory mandates (i.e. Sarbanes Oxley section 404 PCI DSS, HIPAA, GDPR, CCPA).
- Support operational audits as necessary.
- Performs other related duties as assigned.
Qualifications
- Bachelors Degree
- 1 - 3 Years of experience
- Experience in developing, communicating, and presenting security or risk concepts to varying audiences
- Experience with evaluating AI initiatives through a security risk lens
- Knowledge of regulatory requirements and frameworks
- Development and implementation of security policies
- Experience conducting security maturity assessments
- Development and implementation of security controls
- Strong teamwork and interpersonal skills
- Experience in assisting with process improvement initiatives
- Hold relevant security certifications or willingness to pursue additional certifications
- Continuous learning mindset
- Experience performing IT and security risk assessments, using both qualitative and quantitative methods to identify, quantify, and communicate risk
- Working knowledge of privacy statutes including the European Union General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA)
- Experience with Data Classification, Data Security, and Data Loss Prevention methods and tools, specifically Microsoft Azure Information Protection
- Strong MS Office skills (specifically PowerPoint, Word, Excel, Project, Visio)
- Strong process analysis and engineering skills
- Experience conducting and documenting business impact analysis, designing and implementing Business Continuity/Disaster Recovery plans
- Experience with IT assurance mandates/frameworks such as Sarbanes-Oxley, CobIT
- Demonstrated leadership skills
- Demonstrated high level of analytical and problem-solving skills
- Excellent written and verbal communication skills
- Ability to influence cross functional and highly matrixed business and IT stakeholders
Company description
Performance Food Group is a customer-centric foodservice distribution leader headquartered in Richmond, Va. Grounded by roots that date back to a grocery peddler in 1885, PFG has a nationwide network of approximately 150 distribution centers, 35,000-plus talented associates, and thousands of valued suppliers across the country. With the goal of helping customers thrive, PFG markets and delivers quality food and related products to independent and chain restaurants, schools, business and industry locations, convenience operations, healthcare facilities, vending distributors, office coffee service distributors, big box retailers, and theaters across the U.S.
Performance Food Group and/or its subsidiaries (individually or collectively, the "Company") provides equal employment opportunity (EEO) to all applicants and employees, regardless of race, color, national origin, sex, marital status, pregnancy, sexual orientation, gender identity, religion, age, disability, genetic information, veteran status, and any other characteristic protected by applicable local, state and federal laws and regulations. Please click on the following links to review: (1) our EEO Policy; (2) the "EEO is the Law" poster and supplement; and (3) the Pay Transparency Policy Statement.
See all 244+ OPT Information Security Analyst Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new OPT Information Security Analyst Jobs.
Get Access To All JobsTips for Finding OPT Sponsorship as an Information Security Analyst
Target employers with active H-1B filing histories
Large financial institutions, federal contractors, and technology firms file H-1B visa petitions for security analysts regularly. Focusing your search on employers with documented sponsorship histories improves your odds of securing a role that leads to long-term status.
Pursue relevant security certifications before applying
CompTIA Security+, CISSP, and CEH are widely recognized in job postings. Holding at least one certification signals technical readiness and strengthens your case as a specialty occupation worker, which matters when employers evaluate OPT sponsorship decisions.
Clarify your STEM OPT eligibility in your application
Degrees in computer science, information systems, or cybersecurity typically qualify for the 24-month STEM OPT extension. Mentioning your 36 months of total authorization upfront reduces employer hesitation about hiring someone on a shorter work window.
Focus on roles with a clear degree-to-job alignment
H-1B specialty occupation approval depends on your degree field matching the role. Information Security Analyst positions requiring a cybersecurity or IT degree are well-suited. Roles that accept any bachelor's degree regardless of field carry more risk for sponsorship.
Address the timing gap around the H-1B lottery early
The H-1B lottery runs in March for an October 1 start date. If your OPT expires before October, ask employers about cap-exempt options or OPT extension coverage. Having this conversation early prevents surprises late in the hiring process.
Build hands-on experience with in-demand security tools
Employers sponsoring OPT candidates want demonstrated skill, not just coursework. Experience with SIEM platforms, vulnerability scanners, or incident response frameworks makes your profile more compelling and gives employers confidence in investing in your sponsorship.
Information Security Analyst OPT: Frequently Asked Questions
Does an Information Security Analyst role qualify as a STEM OPT job?
Yes. Information Security Analyst is classified under CIP code 11.1003 (Computer and Information Systems Security) and SOC code 15-1212, both of which appear on the STEM Designated Degree Program list. If your degree is in cybersecurity, computer science, or information systems, you're eligible to apply for the 24-month STEM OPT extension, giving you up to 36 months of total work authorization.
Which types of employers are most likely to sponsor Information Security Analysts on OPT?
Federal contractors, financial services firms, healthcare systems, and large technology companies are the most consistent sponsors for this role. These industries face strict compliance and data protection requirements, creating sustained demand for security analysts. You can browse OPT-friendly Information Security Analyst positions on Migrate Mate, which filters for employers open to work authorization sponsorship.
Can I work as a contractor or consultant in cybersecurity on OPT?
OPT requires that your employment be directly related to your degree field, but it does not require a traditional full-time position with a single employer. Contract and consulting arrangements can qualify as long as the work is consistent with your field of study. However, self-employment and staffing agency placements where you work at a third-party client site require careful review with your DSO before accepting.
How does the specialty occupation requirement affect H-1B eligibility for security analysts?
For an H-1B petition to succeed, the employer must demonstrate that the position requires a bachelor's degree or higher in a specific field. Information Security Analyst roles that specify a cybersecurity, computer science, or information systems degree in the job description satisfy this requirement clearly. Roles where the employer accepts any degree regardless of field are harder to approve and may face USCIS scrutiny.
What should I do if my OPT expires before an H-1B cap decision is made?
If you're selected in the H-1B lottery with an October 1 start date but your OPT expires beforehand, you may be eligible for a cap-gap extension that bridges the gap automatically. The cap-gap covers F-1 students whose OPT expires between April 1 and September 30 of the same year the H-1B was filed. Your DSO can issue an updated I-20 reflecting the extension once your employer files the H-1B petition.