STEM OPT Information Security Analyst Jobs
Information Security Analyst roles qualify for the STEM OPT extension, giving you up to 24 additional months of work authorization beyond your initial OPT period. Your employer must be enrolled in E-Verify, and your degree in computer science, cybersecurity, or a related STEM field must align with the role's CIP code requirements.
Find STEM OPT Information Security Analyst JobsOverview
Showing 5 of 173+ Information Security Analyst jobs










See all 173+ Information Security Analyst Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Information Security Analyst roles.
Get Access To All Jobs
INTRODUCTION
Columbia College Chicago is an acclaimed undergraduate and graduate institution that provides a comprehensive education in the arts, communications, and public relations. We constantly aim to reach our full potential as an educational innovator, incubator of new creative practice and generator of real-world success for young creatives. We are in the heart of Chicago, across the street from historic Grant Park, and housed in some of the most iconic buildings in the South Loop.
Columbia College Chicago is a private urban institution of approximately 4,000 undergraduate and graduate students, four-year College offering a distinctive curriculum that blends liberal arts, creative and media arts and business is currently searching for a(an) INFORMATION SECURITY ENGINEER.
The Information Security Engineer designs, implements, maintains, and supports implementation and ongoing operation of the institution’s systems and data security. This role is responsible for monitoring, analyzing, and responding to cybersecurity threats, as well as assisting in maintaining compliance with regulatory and institutional security standards.
Working closely with Academic and Business stakeholders, the Information Security Engineer helps protect institutional data, information systems, and operational processes by applying security best practices and supporting continuous improvement of the institution’s security posture. This role requires strong analytical skills, attention to detail, and the ability to collaborate across departments.
Flex work options available.
DUTIES & RESPONSIBILITIES:
- Monitor and manage technologies, including SIEM, endpoint protection, EDR, and other security platforms, to detect, analyze, investigate, mitigate, patch and respond to security threats and vulnerabilities.
- Analyze cybersecurity threats and design, architect, implement, and maintain security solutions that protect the confidentiality, integrity, and availability of institutional data and systems.
- Conduct vulnerability scanning and security assessments; analyze findings, document risks, and perform appropriate remediation actions.
- Support and participate in incident response activities by investigating security alerts and incidents, determining impact, escalating issues as appropriate, and assisting with containment, eradication, recovery, and resolution efforts.
- Implement and maintain access controls for sensitive, confidential, and high-security data while supporting identity and access management processes, least-privilege principles, authentication controls, and privileged access security.
- Collaborate to design, implement, and maintain security controls across infrastructure, applications, endpoints, networks, and cloud environments.
- Maintain and enforce information security policies, standards, procedures, and technical controls to ensure compliance with regulatory and institutional requirements.
- Evaluate information security risks associated with new technologies, systems, and implementations and recommend or implement appropriate security controls to mitigate identified risks.
- Manage and support third-party relationships and technology vendors by facilitating communication, evaluating security requirements, monitoring contract and compliance obligations, and assisting with the resolution of security-related issues.
- Conduct or support third-party security risk assessments to evaluate vendor security practices, data protection measures, and compliance with institutional security requirements.
- Support the development and delivery of information security awareness and training programs for faculty, staff, and students.
- Track, analyze, and report on security incidents, vulnerabilities, trends, and metrics to identify areas for improvement and support the ongoing development of the Institution's information security program.
- Stay current with emerging cybersecurity threats, vulnerabilities, technologies, regulatory requirements, and industry best practices, and assess their potential impact on the Institution.
- Perform other related duties and/or responsibilities as assigned or required.
QUALIFICATIONS
- Bachelor’s degree in computer science, Information Systems, cybersecurity, or a related field, or an equivalent combination of education and relevant professional experience.
- 3-5 years of professional experience in information security, cybersecurity operations, IT operations, systems administration, or a related field.
- Experience with Security Information and Event Management (SIEM) platforms such as Humio, Splunk, Microsoft Sentinel, QRadar, or similar security monitoring and log analysis solutions.
- Experience with Endpoint Detection and Response (EDR) and endpoint protection platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, or equivalent technologies.
- Experience with vulnerability management and security assessment processes, including vulnerability scanning, risk assessment, remediation tracking, and risk prioritization.
- Experience with identity and access management (IAM), multi-factor authentication (MFA), privileged access controls, least-privilege principles, and user identity lifecycle management.
- Experience supporting and securing cloud and hybrid environments, including Microsoft 365, Microsoft Entra ID, and related Microsoft security technologies.
- Experience with security monitoring, incident response, threat detection, investigation, containment, remediation, and recovery processes.
- Knowledge of common cybersecurity threats, attack vectors, vulnerabilities, security controls, mitigation strategies, and information security frameworks and industry best practices, including the NIST Cybersecurity Framework, CIS Controls, and applicable regulatory and compliance requirements.
- Ability to analyze security risks and implement or recommend appropriate technical and administrative controls to mitigate identified risks.
- Strong analytical, troubleshooting, critical-thinking, and problem-solving skills, with the ability to investigate security events, assess vulnerabilities, diagnose complex security issues, and identify effective solutions.
- Strong technical aptitude, written and verbal communication skills, and the ability to communicate technical risks, security requirements, and cybersecurity concepts effectively to both technical and non-technical stakeholders.
- Strong organizational, documentation, project coordination, and time management skills, with the ability to manage multiple priorities while maintaining confidentiality and protecting sensitive institutional data.
- Ability to collaborate effectively with technical and non-technical stakeholders across the organization and work with cross-functional teams to implement security solutions.
- Experience evaluating security risks associated with third-party vendors, applications, cloud services, and technology implementations is preferred.
- Experience with higher education information security, regulatory requirements, or compliance frameworks, including GLBA, is preferred.
- Relevant industry certifications such as CompTIA Security+, CySA+, CEH, GSEC, SSCP, or equivalent certifications are preferred.
This job description is not intended to be a comprehensive list of all duties, responsibilities, or qualifications associated with the position. Duties and responsibilities may change at any time based on departmental and/or College needs.
Position Minimum Annual Salary: $86,034
Position Maximum Annual Salary: $106,897
The salary range provided in this posting reflects what we reasonably expect to pay for this position. Actual compensation offered or earned is dependent on experience, education and other factors including department budget.
At Columbia, we offer a rewarding work environment for our faculty and staff. We take pride in offering competitive benefits with affordable health, dental and vision coverage; flexible spending accounts; commuter benefit program, life, and accidental, death & dismemberment coverage; paid and unpaid leave options; work/life benefits; educational assistance programs; and retirement and financial planning benefits.
We invite you to join our talented faculty and staff and become part of our collective aspiration to ensure Columbia prepares students for success in their creative fields through innovation, engagement, and real-world experiences.
ADDITIONAL INFORMATION
- Position subject to a background screening
- This is a non-union position
- This is a full-time position
- This position is overtime ineligible
Qualified candidates of all backgrounds are encouraged to apply.
Columbia College Chicago is an equal opportunity employer and complies with all local, state, and federal laws and regulations concerning civil rights. The college does not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national or ethnic origin, age, disability, protected veteran status, genetic information, or other protected classes under the law.
PRIMARY LOCATION
: United States-Illinois-Chicago
JOB
: Information Technology
SCHEDULE
: Full-time
SHIFT
: Day Job
JOB TYPE
: Standard
JOB LEVEL
: Individual Contributor
TRAVEL
: No
See all 173+ STEM OPT Information Security Analyst Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT Information Security Analyst Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization as an Information Security Analyst
Verify your CIP code before applying
Cross-check your degree's CIP code against the DHS STEM Designated Degree Program List to confirm it qualifies for the 24-month extension. Cybersecurity and computer science degrees typically qualify, but information systems degrees vary by institution.
Filter jobs by E-Verify status first
Use Migrate Mate to search Information Security Analyst roles filtered by employers enrolled in E-Verify, the legal prerequisite for your STEM OPT extension. Applying to non-enrolled employers wastes your OPT clock on roles that can't authorize you.
Target employers with active security clearance pipelines
Federal contractors and defense firms hiring Information Security Analysts routinely use E-Verify because federal contracts require it. These employers are structurally more likely to be STEM OPT-compliant than startups or small businesses.
Draft your I-983 training plan before the offer stage
Employers unfamiliar with STEM OPT often stall at the I-983 requirement. Arrive at the offer conversation with a draft training plan tied to specific security analyst competencies so your employer can review and sign without delay.
Confirm your role maps to O*NET code 15-1212
Pull the O*NET profile for Information Security Analysts and document how your job duties match the listed tasks and knowledge areas. USCIS and your DSO may request this alignment to validate your training plan during the extension filing.
Request written E-Verify enrollment confirmation early
Ask your recruiter or HR contact for the employer's E-Verify company ID or a screenshot of their enrollment status before you accept an offer. Verbal assurances aren't enough, and your DSO needs documented proof to process your extension application.
Frequently Asked Questions
Does an Information Security Analyst role qualify for the STEM OPT extension?
Yes, Information Security Analyst positions qualify for the 24-month STEM OPT extension when your degree is in a DHS-designated STEM field such as computer science, cybersecurity, or information technology, and your CIP code appears on the STEM Designated Degree Program List. Your DSO will verify the degree-to-role alignment when processing your extension through SEVIS.
How do I confirm my employer is enrolled in E-Verify?
You can search the E-Verify employer search tool by company name to check enrollment status. Enrollment is a strict legal requirement for STEM OPT employers, not optional. If a company isn't listed, they can't legally employ you under the STEM OPT extension, even if they're willing to sign your I-983 training plan. Always verify before accepting an offer.
What goes into the I-983 training plan for an Information Security Analyst?
Your I-983 must describe how the role develops practical skills tied to your STEM degree, including specific learning objectives, supervision structure, and evaluation methods. For Information Security Analysts, this typically covers security operations, risk assessment, vulnerability management, and incident response. Your employer signs the form and your DSO submits it as part of the extension application to USCIS.
What happens to my work authorization if my employer's H-1B petition is selected in the lottery?
If your employer files an H-1B visa petition during your STEM OPT period and it's selected, cap-gap protection automatically extends your OPT work authorization through September 30 of that year while USCIS adjudicates the petition. You don't need to take any action beyond ensuring your employer files before your OPT EAD expires. USCIS guidance covers the specific conditions that apply.
Where can I find Information Security Analyst jobs where the employer is already set up for STEM OPT?
Migrate Mate lets you search Information Security Analyst roles filtered specifically for E-Verify-enrolled employers, so you're not wasting time applying to companies that can't legally authorize your STEM OPT extension. The platform surfaces employers with demonstrated hiring history for international candidates, which reduces the back-and-forth around I-983 compliance at the offer stage.