OPT Security Manager Jobs
Security Manager jobs on OPT require employers to sponsor or extend your work authorization before your EAD expires. Most roles sit in corporate security, healthcare, or critical infrastructure, where a bachelor's degree in security management, criminal justice, or a related field is standard. STEM OPT extension eligibility varies by degree classification.
Find OPT Security Manager JobsOverview
Showing 5 of 579+ Security Manager jobs










See all 579+ Security Manager Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Security Manager roles.
Get Access To All Jobs
Job Description
We are seeking a Security Software Engineer to build and harden software systems supporting DoD programs operating under CMMC/NIST 800-171/FedRAMP compliance requirements. You will embed security across the SDLC—from design and code review through CI/CD and cloud deployment—working alongside engineering, DevSecOps, and IT teams in a regulated, cloud-native environment (AWS Commercial and GovCloud, Azure GCC High).
Responsibilities
- Core Engineering & Secure Development
- Design and develop secure software with a security-first mindset baked into every phase of the SDLC.
- Apply secure coding standards, threat modeling, and vulnerability mitigation aligned to NIST 800-53 and CMMC Level 2/3 controls.
- Conduct architecture reviews and code hardening to address OWASP Top 10 and DoD STIGs.
-
Automate security gates in CI/CD pipelines (SAST, DAST, dependency scanning, secrets detection).
-
Security Architecture & Controls
- Design secure system and API architectures for multi-tenant cloud environments, including GCC High and FedRAMP-authorized platforms.
- Implement IAM controls, JIT provisioning, SSO/SAML/OIDC flows, and least-privilege authorization frameworks (e.g., Cognito, Azure AD).
-
Instrument applications with security logging and monitoring that satisfies audit and continuous monitoring requirements (AU/SI control families).
-
Vulnerability Management & Response
- Lead code reviews, SAST/DAST scans, and targeted penetration testing; document findings against control frameworks.
- Triage and remediate vulnerabilities within POA&M timelines; maintain artifact evidence for compliance assessments.
-
Support incident response for application-layer events; contribute to after-action reports and corrective action plans.
-
Cross-functional Collaboration
- Serve as the embedded security champion for engineering squads, raising the security bar through mentorship and code review culture.
- Develop and deliver security training and runbooks tailored to engineering and DevOps team members.
- Collaborate with DevOps/SRE to enforce secure IaC, WAF rules, network controls, and runtime monitoring across AWS and Azure environments.
Required Qualifications
- Bachelor’s degree in Computer Science, Engineering, or related field—or equivalent experience.
- 3+ years of software engineering experience with a strong focus on security.
- Proficiency in one or more programming languages (e.g., JavaScript/TypeScript, Python, Go, C#).
- Experience with secure coding practices and frameworks.
- Strong understanding of application security principles, including:
- OWASP Top 10
- Secure API/REST design
- Cryptography fundamentals
- Authentication/authorization patterns
- Experience with code scanning tools (SAST/DAST), threat modeling, and penetration testing.
- Familiarity with NIST 800-171, CMMC, or FedRAMP security control requirements and evidence collection.
- Hands-on experience with AWS and/or Azure security services (IAM, WAF, Security Hub, Defender, Sentinel); GCC High or GovCloud experience a plus.
Preferred Qualifications
- Experience with container security (Docker, ECS).
- Working knowledge of Zero Trust Architecture principles.
- Experience building DevSecOps pipelines in regulated environments; familiarity with tools like Prisma, Checkov, Snyk, or Aqua.
- Relevant certifications (any of the following):
- CISSP, CSSLP, or CASP+
- OSCP
- CEH
- GIAC (GWAPT, GSEC, GWEB) or CCP/CCA (UK Cyber Essentials equivalent)
- Experience securing microservices or event-driven architectures on ECS; background in federal or cleared environments preferred.
See all 579+ OPT Security Manager Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new OPT Security Manager Jobs.
Get Access To All JobsTips for Finding OPT Sponsorship as a Security Manager
Target industries with structured compliance teams
Hospitals, financial institutions, and federal contractors regularly hire Security Managers and have HR teams experienced with OPT work authorization. These employers are far less likely to dismiss your application over visa status than smaller firms.
Lead with your EAD timeline upfront
Security roles often involve background checks and extended onboarding. Tell recruiters your exact OPT expiration date early so they can confirm timelines align before investing weeks in the hiring process for both sides.
Clarify whether your degree qualifies for STEM OPT
Security Management programs under CIP code 43.0116 are STEM-designated, giving you a 24-month extension. Confirm your specific degree program's CIP code with your DSO before assuming you qualify for the longer authorization period.
Emphasize certifications that reduce employer hesitation
Credentials like CPP, PSP, or CISSP signal professional credibility and reduce the perceived risk of sponsoring an international hire. Employers weigh whether you're worth the administrative effort, and certifications shift that calculation in your favor.
Frame H-1B sponsorship as a long-term retention tool
Security Managers who understand operations deeply are expensive to replace. When discussing your future with hiring managers, frame H-1B visa sponsorship as protecting their investment in training you, not as a favor you're asking for.
Research employers before applying, not after
Check whether a company has previously sponsored H-1B visas using OFLC disclosure data before you apply. Employers with no sponsorship history require a much longer conversation than those who've done it multiple times before.
Security Manager OPT: Frequently Asked Questions
Can I work as a Security Manager on OPT?
Yes, as long as your job is directly related to your degree field and you have a valid EAD. Security Manager roles typically qualify under degrees in security management, criminal justice, or business administration. Your DSO must confirm the role meets the OPT employment definition before you start.
Does a Security Manager role qualify for the STEM OPT extension?
It depends on your degree, not your job title. If your program falls under a STEM-designated CIP code, such as 43.0116 for Security and Loss Prevention Services, you may qualify for the 24-month extension. Your employer also needs to be enrolled in E-Verify. Confirm your CIP code with your DSO before counting on the extension.
How do I find Security Manager jobs that are open to OPT students?
Migrate Mate is built specifically for F-1 OPT and visa-sponsored job seekers and lists Security Manager roles from employers with sponsorship history. Searching general job boards surfaces openings with no indication of sponsorship willingness, which wastes significant time during a period when your OPT clock is running.
Will employers sponsor H-1B for a Security Manager role?
Some will. Employers in healthcare, finance, and critical infrastructure who rely on experienced Security Managers tend to be more willing to sponsor because turnover is costly. Your strongest positioning is demonstrating institutional knowledge and operational continuity that would be difficult to replace, making the sponsorship cost worthwhile for the employer.
Can I switch employers while working as a Security Manager on OPT?
Yes, but you must report the change to your DSO within 10 days and update your SEVIS record. The new role must also be directly related to your degree field. If you have STEM OPT, your new employer must be enrolled in E-Verify and you'll need to file an updated Form I-983 training plan.