STEM OPT Application Security Engineer Jobs
Application Security Engineer roles qualify for STEM OPT because they fall under computer science and engineering CIP codes. Your 24-month STEM OPT extension gives you up to 36 months of total work authorization, provided your employer is enrolled in E-Verify and you file a completed I-983 training plan with your DSO.
Find STEM OPT Application Security Engineer JobsOverview
Showing 5 of 31+ Application Security Engineer jobs










See all 31+ Application Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Application Security Engineer roles.
Get Access To All Jobs
Job Description Summary
For over forty years, HarbourVest has been home to a committed team of professionals with an entrepreneurial spirit and a desire to deliver impactful solutions to our clients and investing partners. As our global firm grows, we continue to add individuals who seek a collaborative, open-door culture that values diversity and innovative thinking.
In our collegial environment that’s marked by low turnover and high energy, you’ll be inspired to grow and thrive. Here, you will be encouraged to build on your strengths and acquire new skills and experiences.
We are committed to fostering an environment of inclusion that promotes mutual respect among all employees. Understanding and valuing these differences optimizes the potential of both the individual and the firm.
HarbourVest is an equal opportunity employer.
This position will be a hybrid work arrangement. You will receive 18 remote workdays per quarter to use at your discretion, subject to manager approval. For example, you may choose to work in the office 4 days per week and take one remote day weekly (typically 13 weeks per quarter), leaving 5 additional remote days to be used as needed.
As a key member of the Security Engineering team, this person will help lead HarbourVest’s Application Security program. The Application Security Engineer (ASE) will serve in a multi-functional role, advising development teams on secure coding and accepted industry procedures. The ASE is responsible for leading SDLC initiatives that include secure code reviews, architecture assessments, and application scanning methods. They will provide end-to-end leadership for application security, working closely within platform teams to advocate for and enhance a strong program focused on application security. In this role, they will help uphold and continuously improve HarbourVest’s high security standards across infrastructure, applications, and operational processes.
The ideal candidate is someone who is:
- Dedicated to protecting sensitive financial data, client information, and critical business systems
- Skilled in navigating regulated financial services settings
- Able to assess and prioritize security concerns by considering their effect on business and financial outcomes
- A collaborative partner to engineering, risk, compliance, and audit teams
- Proactive, diligent, and calm when responding to security incidents
What you will do:
- Identify risks and areas of exposure in applications, SDLC processes, and architecture
- Define guardrails, standards, and secure usage patterns for agentic AI–based coding tools, enabling engineering teams to adopt them safely while managing data exposure, code quality, and security risk
- Perform secure build reviews, threat modeling, and application security testing (SAST, DAST, SCA)
- Identify, assess, and support remediation of vulnerabilities in web applications and APIs
- Partner with engineering teams to promote secure coding standards utilizing CI/CD pipelines and DevSecOps practices
- Support audits, regulatory exams, penetration tests, and security incident response
- Secure and continuously monitor third-party SaaS applications using SSPM tools, ensuring configurations, access controls, and integrations meet HarbourVest security standards
- Establish metrics and reporting to track coverage and effectiveness of security processes
- Enable developers through secure coding guidance, training, and tooling
- And other responsibilities as required!
What you bring:
- Solid understanding of application security principles and OWASP Top 10 risks
- Experience securing web applications, APIs, and microservices in financial environments
- Hands-on experience with AI-assisted coding tools such as Cursor, GitHub Copilot, and ChatGPT Codex, with an understanding of their security implications in enterprise software development
- Proficiency reviewing code in at least one common language (Java, Python, C#, or JavaScript)
- Familiarity with cloud platforms, containers, IaaC, and modern DevSecOps tooling
- Ability to clearly communicate technical risk to both technical and non-technical collaborators
Education Preferred:
- Bachelor’s degree or equivalent experience in Computer Science, Information Security, or a related field
- Security certifications such as CISSP, CSSLP, OSCP, GWAPT, or similar are a plus
Experience:
- 3-5 years of experience in application security or secure software development
- Experience working in controlled sectors such as finance, banking, or fintech
- Exposure to compliance frameworks (e.g., SOC 2, SOX, PCI DSS, GDPR)
LI-Hybrid
Base Salary Range:
$145,000.00 - $155,000.00
This USD base salary range represents only one component of total compensation for this role and is provided in accordance with local requirements. This role is eligible for a discretionary annual bonus, which is determined based on individual and overall firm performance. In addition to salary and bonus, total compensation may include eligibility for long-term reward programs and a comprehensive total rewards package that may include retirement, health, insurance, paid time off, and wellness programs. Our total rewards offerings are influenced by several business factors, and eligibility for certain components will vary by position and geography. Please note the posted ranges do not apply outside the U.S. and should not be converted to other currencies as a proxy for compensation in other countries.
See all 31+ STEM OPT Application Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT Application Security Engineer Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization as an Application Security Engineer
Verify your degree CIP code first
Check that your degree's CIP code falls under an approved STEM category before applying. Computer science (11.xx), information security (11.1003), and engineering (14.xx) codes all qualify, but some interdisciplinary degrees don't. Confirm eligibility with your DSO before targeting roles.
Confirm E-Verify enrollment before accepting offers
Any employer who hires you on STEM OPT must be enrolled in E-Verify, not just willing to enroll. Ask recruiters directly and verify through the E-Verify employer search before signing anything. A non-enrolled employer disqualifies your extension regardless of role fit.
Target security teams at regulated industries
Financial services, healthcare, and defense contractors face strict compliance mandates that create standing demand for application security engineers. These industries file consistent STEM OPT training plans and are familiar with I-983 requirements, reducing delays after you receive an offer.
Build your I-983 training plan around AppSec milestones
Don't wait until offer acceptance to draft your I-983. Map your planned work to specific learning objectives tied to secure SDLC, penetration testing, or threat modeling. A well-prepared training plan speeds DSO approval and signals readiness to compliance-aware employers.
Use Migrate Mate to find E-Verify employers hiring AppSec engineers
Filter your search on Migrate Mate by employers with confirmed E-Verify enrollment and active application security roles. This cuts time spent vetting employers manually and surfaces companies already familiar with STEM OPT filing requirements.
File your extension request 90 days before OPT expiration
USCIS requires your STEM OPT extension application to be submitted at least 90 days before your initial OPT EAD expires. Missing this window means a gap in work authorization. Your DSO must recommend the extension in SEVIS before you file Form I-765.
Frequently Asked Questions
Does an Application Security Engineer role qualify for the STEM OPT extension?
Yes, if your degree is in a qualifying STEM field such as computer science, information security, or software engineering. The role itself must also provide structured learning tied to your degree, which you document in the I-983 training plan. Application security work typically maps cleanly to these requirements because it involves technically complex, degree-relevant skills. Your DSO makes the final eligibility determination based on your specific degree CIP code.
What E-Verify requirements does my employer need to meet for STEM OPT?
Your employer must be actively enrolled in E-Verify at the time you begin work on the STEM OPT extension. Enrollment after hiring does not satisfy this requirement retroactively. You can check employer enrollment status through the E-Verify employer search tool. The employer must also sign your I-983 training plan, confirming they will provide the documented learning experience for the full extension period.
What goes into the I-983 training plan for an Application Security Engineer?
The I-983 requires you to describe specific training goals tied to your STEM degree, the skills you'll develop, and how the employer will supervise and evaluate your progress. For an application security role, this typically includes objectives around secure code review, vulnerability assessment, threat modeling, or incident response. The employer's designated supervisor signs the plan, and you submit it to your DSO before the extension begins. You also file an evaluation update at the 12-month mark.
How does cap-gap protection apply if my employer files an H-1B petition while I'm on STEM OPT?
If your employer files an H-1B visa petition before your STEM OPT EAD expires and you're selected in the lottery, cap-gap automatically extends your work authorization through September 30 of that fiscal year. You don't need to file separately for cap-gap. Your I-20 should be updated by your DSO to reflect the cap-gap period. USCIS confirms the underlying rules governing this extension, so verify your specific dates with your DSO.
Where can I find Application Security Engineer jobs where employers already understand STEM OPT?
Migrate Mate lists application security roles filtered by employers enrolled in E-Verify, which is the baseline requirement for your STEM OPT extension. Searching there saves time compared to screening employers manually. Look for roles at companies in regulated sectors like finance or healthcare, where dedicated security teams and compliance infrastructure mean faster I-983 processing and less employer education required on your end.