OPT Product Security Engineer Jobs
Product Security Engineer jobs are a strong fit for F-1 OPT students with backgrounds in computer science, cybersecurity, or software engineering. Many employers in this field sponsor H-1B visas, and STEM OPT extensions give you up to three years of authorized work to build the experience needed to qualify.
Find OPT Product Security Engineer JobsOverview
Showing 5 of 5+ Product Security Engineer jobs










See all Product Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Product Security Engineer roles.
Get Access To All Jobs
GENERAL INFORMATION
Req #
WD00102309
Career area:
Hardware Engineering
Country/Region:
United States of America
State:
North Carolina
City:
Morrisville
Date:
Thursday, August 6, 2026
Working time:
Full-time
ADDITIONAL LOCATIONS:
* United States of America - North Carolina - Morrisville
WHY WORK AT LENOVO
We are Lenovo. We do what we say. We own what we do. We WOW our customers.
Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).
This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.
DESCRIPTION AND REQUIREMENTS
The Product Supply Chain Security Auditor is responsible for assessing, monitoring, and improving supplier security practices throughout the product supply chain. This role supports the Trusted Supplier Program (TSP) by conducting supplier security audits, evaluating cybersecurity risks, reviewing remediation activities, and ensuring compliance with industry security standards. The ideal candidate combines cybersecurity expertise, audit experience, and strong stakeholder management skills to help strengthen supplier security governance and reduce supply chain risk.
Key Responsibilities:
- Conduct supplier security audits and reassessments under the Trusted Supplier Program (TSP).
- Review supplier audit questionnaires, supporting documentation, and audit evidence.
- Identify, classify, and document audit findings, including observations, recommendations, and non-conformities.
- Track supplier corrective action plans and validate remediation evidence through closure.
- Support supplier re-evaluations and maintain accurate audit records and documentation.
- Monitor supplier security incidents, vulnerability disclosures, regulatory changes, and industry security alerts.
- Prepare audit reports, risk assessments, evidence packages, executive summaries, and management updates.
- Collaborate with Procurement, Product, Legal, Business, and Security teams to enhance supplier security governance and risk management practices.
- Evaluate component-level security risks and provide support to the Product Security Incident Response Team (PSIRT).
BASIC QUALIFICATIONS:
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field.
- 3 to 5 years of experience in one or more of the following areas: Cybersecurity, Third-party risk management, Security auditing, Product security, Supply chain security.
PREFERRED QUALIFICATIONS:
- Strong understanding of: PC architecture and IT systems, Security auditing methodologies, Third-party risk assessments, Evidence review and validation, Vulnerability management, Remediation tracking and verification.
- Knowledge of industry standards and frameworks such as: ISO/IEC 27001, ISO/IEC 27036, ISO 20243 (Open Trusted Technology Provider Standard), NIST SP 800-161.
- Ability to analyze technical findings and translate them into clear, risk-based conclusions and actionable remediation recommendations.
- Strong project management, documentation, communication, and stakeholder management skills.
- Ability to work independently and collaborate effectively with global cross-functional teams in a fast-paced environment.
- Master's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related discipline.
- Experience supporting supplier assurance programs, product security initiatives, or supply chain risk management activities.
- Experience working with global suppliers and cross-functional business stakeholders.
- Professional certifications such as: CISA (Certified Information Systems Auditor), CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CRISC (Certified in Risk and Information Systems Control), ISO/IEC 27001 Lead Auditor.
- Familiarity with product security incident response processes and vulnerability disclosure programs.
- Advanced knowledge of cybersecurity governance, compliance, audit reporting, and risk management best practices.
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.
ADDITIONAL LOCATIONS:
United States of America - North Carolina - Morrisville
United States of America
United States of America - North Carolina
United States of America - North Carolina - Morrisville
See all OPT Product Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new OPT Product Security Engineer Jobs.
Get Access To All JobsTips for Finding OPT Sponsorship as a Product Security Engineer
Target companies with dedicated security teams
Large tech companies and fintech firms with established product security functions are far more likely to sponsor visas than early-stage startups. Look for organizations that have filed H-1B petitions for security engineering roles in previous years.
Frame your experience around product risk, not just tools
Employers want engineers who understand how security fits into the product lifecycle. Highlight threat modeling, secure design reviews, or vulnerability triage work rather than listing certifications alone. That framing signals engineering judgment, not just technical skill.
Get your STEM OPT extension filed early
Product Security Engineer qualifies as a STEM role under CIP code 11.0701 (Computer Science). File your STEM OPT extension at least 90 days before your initial OPT expires to avoid any gap in work authorization during your job search.
Address sponsorship directly in your cover letter
Many hiring managers assume international candidates require expensive or complicated sponsorship. A single sentence clarifying that you're authorized to work on OPT and eligible for H-1B sponsorship removes that uncertainty before it becomes a reason to pass on your application.
Pursue roles on the product engineering side, not just IT security
Product Security Engineers embedded in software development teams are more likely to be hired by engineering-forward companies that sponsor visas routinely. IT or compliance-focused security roles often sit in departments with less H-1B filing history.
Build a portfolio of documented security work
Open-source security tooling contributions, CVE disclosures, or documented bug bounty findings give hiring managers concrete evidence of your skills. This is especially useful when competing against candidates who already hold full work authorization.
Product Security Engineer OPT: Frequently Asked Questions
Does Product Security Engineer qualify for a STEM OPT extension?
Yes. Product Security Engineer roles fall under STEM-designated fields, most commonly computer science (CIP code 11.0701) or computer and information systems security (CIP code 11.1003). If your degree is in one of these fields, you're eligible to apply for a 24-month STEM OPT extension, giving you up to three years of total OPT work authorization.
Do employers commonly sponsor H-1B visas for Product Security Engineers?
Yes. Product Security Engineer is classified as a specialty occupation under USCIS guidelines because it requires a bachelor's degree or higher in a specific technical field. Large technology companies, financial institutions, and healthcare organizations with mature security programs file H-1B petitions for this role regularly. You can browse companies currently hiring on Migrate Mate to identify those with a track record of sponsorship.
Can I work as a Product Security Engineer on day-one OPT before finding a STEM employer?
Yes, as long as your employment is directly related to your degree field. Your initial 12-month OPT period doesn't require a formal training plan. Once you move to a STEM OPT extension, your employer must be E-Verify enrolled and you'll need a signed training plan (Form I-983) on file. Confirm your employer's E-Verify status before accepting an offer.
What degree backgrounds typically qualify for Product Security Engineer roles on OPT?
Most Product Security Engineer positions require a degree in computer science, computer engineering, information security, or a closely related field. Some employers also accept electrical engineering or mathematics degrees when the candidate has demonstrated security experience. Your OPT work authorization must be tied to your specific degree field, so confirm the role aligns before applying.
How should I handle the sponsorship question if an employer says they don't sponsor visas?
Clarify that you're currently authorized to work on OPT and won't need sponsorship immediately. Many employers who say they don't sponsor are actually unfamiliar with OPT. If they're unwilling to consider future H-1B sponsorship at all, it's worth moving on. Focus your search on companies that have sponsored security engineering roles before.