STEM OPT Cloud Engineer Jobs
Cloud Engineer roles in infrastructure, DevOps, and platform engineering qualify for STEM OPT's 24-month extension when your degree falls under an eligible CIP code in computer science, engineering, or a related STEM field. Your employer must be enrolled in E-Verify before your extension starts, and you'll need a signed I-983 training plan tied to cloud-specific learning objectives.
Find STEM OPT Cloud Engineer JobsOverview
Showing 5 of 356+ Cloud Engineer jobs










See all 356+ Cloud Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Cloud Engineer roles.
Get Access To All Jobs
INTRODUCTION:
Founded on a legacy of more than 120 years in banking, Bank OZK is much more than just a company. We’re nationally recognized as an industry leader in financial services. That means we combine exceptional service with innovative technologies to deliver smart solutions to our clients across the country. We’re investing in small businesses, fueling economies in local communities and changing skylines in the largest cities across America. Here, we're not simply filling roles. We're fostering even greater careers.
The foundation for a great career starts with an exceptional team and a comprehensive benefits package. We believe in providing our dedicated team members with the best resources to support their physical, mental and financial wellbeing, including generous PTO, 401(k) matching, health, dental, vision (and pet!) insurance as well as special perks and discounts. Learn more about Bank OZK benefits.
JOB PURPOSE & SCOPE:
Responsible for ensuring the secure design, implementation, and operation of Bank OZK’s cloud environments. The Cloud Security Engineer works closely with IT, Labs, Data teams, Third-Party Risk Management, and application owners to implement cloud security controls and enforce compliance with Bank policies and industry regulations.
ESSENTIAL JOB FUNCTIONS:
- Supports the onboarding and risk assessment of new Cloud Service Providers (CSPs) through the Third-Party Risk Management (TPRM) process.
- Evaluates CSP security controls against Bank OZK’s Cloud Security Standard and regulatory requirements, ensuring that proposed cloud solutions meet all legal and compliance criteria before approval.
- Implements and maintains cloud security controls across SaaS, PaaS, and IaaS environments, applying Bank-approved secure configuration baselines (leveraging industry benchmarks like CIS) for cloud resources (VMs, containers, storage, etc.) and enforces “secure-by-default” settings during deployments.
- Collaborates with OZK Technology teams to design cloud architectures that incorporate network segmentation, encryption, and other security best practices from start to completion.
- Integrates cloud platforms and applications with the Bank’s centralized Single Sign-On (SSO) and identity management systems.
- Ensures that cloud activity logs are enabled, collected, and integrated with Bank OZK’s Security Information and Event Management (SIEM) and monitoring systems.
- Develop detections or alert rules to monitor cloud events for signs of compromise or policy violations.
- Investigates and responds to cloud security incidents in coordination with the Security Operations Center (SOC), helping to remediate issues and implement lessons learned.
- Manages cloud environments for security compliance and misconfigurations using automated Cloud Security Posture Management (CSPM) tools or scripts.
- Performs configuration audits and vulnerability scans of cloud assets and works with infrastructure and application teams to remediate identified weaknesses or document risk acceptances according to the Bank’s vulnerability management standards.
- Collaborates with software development teams and Application Security Engineers on secure deployment of cloud-native applications. Ensures cloud-hosted applications follow secure coding and deployment practices aligned with Bank standards (e.g. perform threat modeling, enforce secure SDLC requirements).
- Implements cloud-native application security controls such as web application firewalls (WAFs) for internet-facing apps and ensure proper network restrictions (security groups, private endpoints) for sensitive data stores.
- Embeds security into the CI/CD pipeline and infrastructure-as-code processes. Works with DevOps engineers to implement automated security checks for cloud infrastructure templates and application code (e.g. IaC scanning, container image scanning, secret leakage detection).
- Advises on secure configuration of CI/CD tools and use of secure secret management for pipeline credentials. Promote DevSecOps best practices so that security is an integral part of cloud deployment workflows.
- Provides guidance and training to IT cloud engineers, developers, and business units on cloud security requirements and secure cloud service usage.
- Ensures that cloud security controls and processes are well-documented and ready for audits or examinations.
- Provides evidence of compliance with the Bank’s Cloud Security Standard and applicable regulations during audits (internal, external, or regulatory). Address audit findings or recommendations related to cloud security by implementing corrective actions or process improvements.
- Stays current with relevant regulatory guidelines (e.g. FFIEC cloud computing guidance, NYDFS cybersecurity requirements).
- Stays informed on evolving cloud security threats, tools, and best practices, especially as they relate to financial institutions.
- Proactively recommend and implement enhancements to Bank OZK’s cloud security posture.
- Performs or assigns other tasks and assists other team members as necessary.
KNOWLEDGE, SKILLS & ABILITIES:
- Knowledge of integrating security testing tools into build/deployment pipelines and managing secrets for automation.
- Ability to work with DevOps/CI-CD pipelines and using Infrastructure-as-Code (Terraform, CloudFormation, etc.) in a secure manner.
- Advanced security-minded with the ability to assess risk in cloud architectures.
- Ability to consistently apply principles of confidentiality, integrity, and availability when evaluating cloud solutions and making risk-based decisions aligned with the Bank’s risk appetite.
- Strong diligence in configuring and reviewing cloud settings, logs, and processes to ensure nothing is overlooked. Vigilant in following through on issues until they are fully resolved and verified.
- Strong critical thinking skills to analyze complex technical problems or security events in cloud environments.
- Ability to break down problems, identify patterns or root causes, and develop effective solutions or mitigations.
- Ability to effectively communicate technical cloud security issues into business impact terms.
- Excellent interpersonal skills with an ability to work collaboratively on cross-functional teams, clearly articulate recommendations, and influence secure outcomes without formal authority.
- Ability to work in a fast-paced, evolving environment. Able to adjust to new cloud services, threats, and regulatory requirements as they emerge, updating strategies and tactics accordingly.
- Ability to be self-motivated and proactive. Takes ownership of projects and problems; drives improvements in cloud security practices without waiting for direction. Demonstrates a strong sense of responsibility and ethics, especially important in handling sensitive systems and data.
- Ability to demonstrate initiative to accomplish work objectives.
BASIC QUALIFICATIONS:
- Bachelor’s degree in Information Systems or related field; or commensurate work experience, required.
- Three (3) years’ work experience in a regulated financial institution or other heavily regulated environment, required.
- Familiarity with banking-specific security considerations and third-party risk management practices for cloud services, required.
- Professional security certifications related to cloud and information security (e.g., CCSP, CISSP, AWS/Azure Security Engineer, or CompTIA Security+), preferred.
JOB EXPECTATIONS:
Operate customary equipment and technology used in a business environment, with or without accommodation.
Note: This description is not an exhaustive list of all job functions, duties, skills, and job standards required. Other job functions, duties, skills, and standards may be added. Management reserves the right to add or change the job requirements at any time.
LI-KC1
EEO STATEMENT:
Bank OZK is an equal opportunity employer and gives consideration for employment to qualified applicants without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity, disability status, protected veteran status, or any other characteristic protected by federal, state, and local law. Member FDIC.
See all 356+ STEM OPT Cloud Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT Cloud Engineer Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization as a Cloud Engineer
Verify your CIP code matches cloud engineering
Check your degree's CIP code against the DHS STEM Designated Degree Program List before applying. Degrees in computer science, computer engineering, and information systems typically qualify, but applied computing or IT management programs sometimes fall outside the list.
Confirm E-Verify enrollment before accepting offers
Ask your recruiter for the employer's E-Verify Company ID number and cross-check it through the E-Verify employer search before signing anything. A company that isn't enrolled can't legally employ you on STEM OPT, even if they're otherwise enthusiastic about hiring you.
Align your I-983 goals to cloud certification tracks
When drafting your I-983 training plan, map your learning objectives to specific cloud certifications like AWS Solutions Architect or Google Cloud Professional. USCIS reviewers look for measurable, role-specific goals, not vague references to gaining technical experience.
Target employers with active STEM OPT infrastructure
Use Migrate Mate to filter Cloud Engineer roles by employers with verified E-Verify enrollment and a history of hiring OPT students. This cuts the research time on employer eligibility and surfaces openings at companies already familiar with the I-983 process.
Time your H-1B registration to your OPT end date
If your STEM OPT expires before October 1 of your cap-gap year, the cap-gap rule extends your work authorization automatically once USCIS receives your H-1B visa petition. File as early in the registration window as possible to maximize that buffer.
Use the OFLC Wage Search to negotiate cloud role pay
Look up the prevailing wage for your specific cloud engineering role and metro area using the OFLC Wage Search before your offer call. The DOL wage level your employer files at is public record, and knowing it in advance strengthens your negotiating position.
Frequently Asked Questions
Does my degree qualify me for the STEM OPT extension as a Cloud Engineer?
Your degree qualifies if it appears on the DHS STEM Designated Degree Program List, which covers fields like computer science, computer engineering, electrical engineering, and information science. Cloud Engineering roles are classified under SOC codes tied to software development and systems architecture, so most STEM graduates working in cloud infrastructure meet the degree-to-role alignment requirement. Check your degree's CIP code against the current DHS list to confirm before your DSO submits the I-20 recommendation.
What E-Verify requirement applies to Cloud Engineer employers on STEM OPT?
Your employer must be actively enrolled in E-Verify before your STEM OPT extension start date. Enrollment after the fact doesn't satisfy the requirement. You can verify enrollment status through the E-Verify employer search using the company's legal name or EIN. If a company operates through a staffing agency or professional employer organization, the E-Verify enrollment must belong to the entity that signs your I-983, not a parent or affiliated company.
How do I write an I-983 training plan for a Cloud Engineer role?
Your I-983 must identify specific cloud engineering skills you'll develop, the projects or systems you'll work on, and how your employer will supervise and evaluate your progress. Generic language like 'gaining experience in cloud technologies' won't pass scrutiny. Tie each learning objective to concrete deliverables, such as designing a multi-region deployment pipeline or completing an AWS or Azure architecture project, and include a supervisor name with reporting frequency. USCIS can request the I-983 during an inspection, so specificity matters.
What happens to my STEM OPT if I change Cloud Engineer employers?
You can switch employers during your STEM OPT period, but the new employer must also be enrolled in E-Verify, and you must submit a new I-983 training plan signed by both you and the new employer within ten days of starting. Your DSO needs to update your SEVIS record to reflect the change. You cannot start work with the new employer until the I-983 is submitted, so plan the transition timeline carefully to avoid an unauthorized employment gap.
Where can I find Cloud Engineer jobs that already support STEM OPT hiring?
Migrate Mate surfaces Cloud Engineer roles at employers with confirmed E-Verify enrollment, so you're not spending time vetting companies that can't legally hire you on STEM OPT. Roles on the platform are filtered for the specific requirements your extension depends on, which matters when your job search timeline is tied to an OPT end date and you can't afford to lose weeks on employers who haven't set up the required E-Verify infrastructure.