STEM OPT Information Security Engineer Jobs
Information Security Engineer roles sit squarely within STEM OPT eligibility, letting you work for up to 36 months on your F-1 authorization if your employer is enrolled in E-Verify. A STEM degree in computer science, information assurance, or a related CIP-coded field unlocks the 24-month extension. Every employer on this page is verified to hire STEM OPT students.
Find STEM OPT Information Security Engineer JobsOverview
Showing 5 of 173+ Information Security Engineer jobs










See all 173+ Information Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Information Security Engineer roles.
Get Access To All Jobs
INTRODUCTION
Columbia College Chicago is an acclaimed undergraduate and graduate institution that provides a comprehensive education in the arts, communications, and public relations. We constantly aim to reach our full potential as an educational innovator, incubator of new creative practice and generator of real-world success for young creatives. We are in the heart of Chicago, across the street from historic Grant Park, and housed in some of the most iconic buildings in the South Loop.
Columbia College Chicago is a private urban institution of approximately 4,000 undergraduate and graduate students, four-year College offering a distinctive curriculum that blends liberal arts, creative and media arts and business is currently searching for a(an) INFORMATION SECURITY ENGINEER.
The Information Security Engineer designs, implements, maintains, and supports implementation and ongoing operation of the institution’s systems and data security. This role is responsible for monitoring, analyzing, and responding to cybersecurity threats, as well as assisting in maintaining compliance with regulatory and institutional security standards.
Working closely with Academic and Business stakeholders, the Information Security Engineer helps protect institutional data, information systems, and operational processes by applying security best practices and supporting continuous improvement of the institution’s security posture. This role requires strong analytical skills, attention to detail, and the ability to collaborate across departments.
Flex work options available.
DUTIES & RESPONSIBILITIES:
- Monitor and manage technologies, including SIEM, endpoint protection, EDR, and other security platforms, to detect, analyze, investigate, mitigate, patch and respond to security threats and vulnerabilities.
- Analyze cybersecurity threats and design, architect, implement, and maintain security solutions that protect the confidentiality, integrity, and availability of institutional data and systems.
- Conduct vulnerability scanning and security assessments; analyze findings, document risks, and perform appropriate remediation actions.
- Support and participate in incident response activities by investigating security alerts and incidents, determining impact, escalating issues as appropriate, and assisting with containment, eradication, recovery, and resolution efforts.
- Implement and maintain access controls for sensitive, confidential, and high-security data while supporting identity and access management processes, least-privilege principles, authentication controls, and privileged access security.
- Collaborate to design, implement, and maintain security controls across infrastructure, applications, endpoints, networks, and cloud environments.
- Maintain and enforce information security policies, standards, procedures, and technical controls to ensure compliance with regulatory and institutional requirements.
- Evaluate information security risks associated with new technologies, systems, and implementations and recommend or implement appropriate security controls to mitigate identified risks.
- Manage and support third-party relationships and technology vendors by facilitating communication, evaluating security requirements, monitoring contract and compliance obligations, and assisting with the resolution of security-related issues.
- Conduct or support third-party security risk assessments to evaluate vendor security practices, data protection measures, and compliance with institutional security requirements.
- Support the development and delivery of information security awareness and training programs for faculty, staff, and students.
- Track, analyze, and report on security incidents, vulnerabilities, trends, and metrics to identify areas for improvement and support the ongoing development of the Institution's information security program.
- Stay current with emerging cybersecurity threats, vulnerabilities, technologies, regulatory requirements, and industry best practices, and assess their potential impact on the Institution.
- Perform other related duties and/or responsibilities as assigned or required.
QUALIFICATIONS
- Bachelor’s degree in computer science, Information Systems, cybersecurity, or a related field, or an equivalent combination of education and relevant professional experience.
- 3-5 years of professional experience in information security, cybersecurity operations, IT operations, systems administration, or a related field.
- Experience with Security Information and Event Management (SIEM) platforms such as Humio, Splunk, Microsoft Sentinel, QRadar, or similar security monitoring and log analysis solutions.
- Experience with Endpoint Detection and Response (EDR) and endpoint protection platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, or equivalent technologies.
- Experience with vulnerability management and security assessment processes, including vulnerability scanning, risk assessment, remediation tracking, and risk prioritization.
- Experience with identity and access management (IAM), multi-factor authentication (MFA), privileged access controls, least-privilege principles, and user identity lifecycle management.
- Experience supporting and securing cloud and hybrid environments, including Microsoft 365, Microsoft Entra ID, and related Microsoft security technologies.
- Experience with security monitoring, incident response, threat detection, investigation, containment, remediation, and recovery processes.
- Knowledge of common cybersecurity threats, attack vectors, vulnerabilities, security controls, mitigation strategies, and information security frameworks and industry best practices, including the NIST Cybersecurity Framework, CIS Controls, and applicable regulatory and compliance requirements.
- Ability to analyze security risks and implement or recommend appropriate technical and administrative controls to mitigate identified risks.
- Strong analytical, troubleshooting, critical-thinking, and problem-solving skills, with the ability to investigate security events, assess vulnerabilities, diagnose complex security issues, and identify effective solutions.
- Strong technical aptitude, written and verbal communication skills, and the ability to communicate technical risks, security requirements, and cybersecurity concepts effectively to both technical and non-technical stakeholders.
- Strong organizational, documentation, project coordination, and time management skills, with the ability to manage multiple priorities while maintaining confidentiality and protecting sensitive institutional data.
- Ability to collaborate effectively with technical and non-technical stakeholders across the organization and work with cross-functional teams to implement security solutions.
- Experience evaluating security risks associated with third-party vendors, applications, cloud services, and technology implementations is preferred.
- Experience with higher education information security, regulatory requirements, or compliance frameworks, including GLBA, is preferred.
- Relevant industry certifications such as CompTIA Security+, CySA+, CEH, GSEC, SSCP, or equivalent certifications are preferred.
This job description is not intended to be a comprehensive list of all duties, responsibilities, or qualifications associated with the position. Duties and responsibilities may change at any time based on departmental and/or College needs.
Position Minimum Annual Salary: $86,034
Position Maximum Annual Salary: $106,897
The salary range provided in this posting reflects what we reasonably expect to pay for this position. Actual compensation offered or earned is dependent on experience, education and other factors including department budget.
At Columbia, we offer a rewarding work environment for our faculty and staff. We take pride in offering competitive benefits with affordable health, dental and vision coverage; flexible spending accounts; commuter benefit program, life, and accidental, death & dismemberment coverage; paid and unpaid leave options; work/life benefits; educational assistance programs; and retirement and financial planning benefits.
We invite you to join our talented faculty and staff and become part of our collective aspiration to ensure Columbia prepares students for success in their creative fields through innovation, engagement, and real-world experiences.
ADDITIONAL INFORMATION
- Position subject to a background screening
- This is a non-union position
- This is a full-time position
- This position is overtime ineligible
Qualified candidates of all backgrounds are encouraged to apply.
Columbia College Chicago is an equal opportunity employer and complies with all local, state, and federal laws and regulations concerning civil rights. The college does not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national or ethnic origin, age, disability, protected veteran status, genetic information, or other protected classes under the law.
PRIMARY LOCATION
: United States-Illinois-Chicago
JOB
: Information Technology
SCHEDULE
: Full-time
SHIFT
: Day Job
JOB TYPE
: Standard
JOB LEVEL
: Individual Contributor
TRAVEL
: No
See all 173+ STEM OPT Information Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT Information Security Engineer Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization as an Information Security Engineer
Confirm your CIP code before applying
Pull up your transcript and cross-reference your degree's Classification of Instructional Programs code against the DHS STEM OPT designated degree list. Computer science, cybersecurity, and information assurance CIP codes all qualify, but information systems codes sometimes don't.
Screen employers for E-Verify enrollment first
Before any application, look up the employer in the E-Verify employer search tool to confirm active enrollment. An employer that isn't enrolled cannot legally hire you on STEM OPT, and retroactive enrollment after your start date won't satisfy the requirement.
Draft your I-983 training plan before offer stage
Security engineers often cover multiple domains like penetration testing, incident response, and cloud security. Map each responsibility to a specific learning objective in your I-983 draft now so negotiations over job duties don't delay your DSO's signature later.
Search Migrate Mate to filter verified STEM OPT employers
Use Migrate Mate to browse Information Security Engineer roles at employers already confirmed to hire STEM OPT students. Filtering by E-Verify status at the search stage saves you from pursuing leads that will stall at the authorization check.
Target companies with active security clearance pipelines
Defense contractors and federal IT vendors frequently hire information security engineers and tend to maintain continuous E-Verify enrollment as a government contracting requirement. That institutional enrollment habit reduces the risk of a last-minute E-Verify gap on your start date.
Negotiate your start date around OPT cap-gap timing
If your initial OPT expires while an H-1B visa petition is pending, the cap-gap rule extends your work authorization through September 30. Confirm with your DSO that your Information Security Engineer offer letter start date falls within that protected window before signing.
Frequently Asked Questions
Does an Information Security Engineer role qualify for STEM OPT?
Yes, if your underlying degree carries a qualifying CIP code. Degrees in computer science, cybersecurity, information assurance, and electrical engineering are on the DHS STEM designated degree list and support the 24-month STEM OPT extension. General information systems or business IT degrees may not qualify, so verify your specific CIP code with your DSO before accepting an offer.
What does the E-Verify requirement mean for my job search?
Every employer who hires you on STEM OPT must be enrolled in E-Verify for the specific site where you'll work. You can confirm enrollment through the E-Verify employer search tool before applying. If an employer is not enrolled, they cannot sponsor your STEM OPT extension regardless of how qualified you are. Use Migrate Mate to find Information Security Engineer roles at employers who already meet this requirement.
How does the I-983 training plan work for information security roles?
Your employer and DSO co-sign the I-983, which documents the formal training relationship between your security engineering duties and your STEM degree. You and your supervisor must complete a self-evaluation every six months and a full evaluation at the end of the training period. Information security roles with duties spread across multiple domains, such as cloud security, compliance, and incident response, require each area to be reflected in the I-983 learning objectives.
Can I switch employers mid-STEM OPT if I get a better security engineering offer?
Yes, but the transition requires your DSO to update your I-20 to reflect the new employer before your last day at the current job. The new employer must also be enrolled in E-Verify and willing to co-sign a revised I-983 training plan. There's no grace period between employers on STEM OPT, so the paperwork must be completed before your first day at the new company.
What happens to my STEM OPT authorization if an H-1B is filed on my behalf?
If your employer files an H-1B petition before your OPT expires and it's selected in the lottery, the cap-gap rule automatically extends your work authorization through September 30 of that year. You can keep working as an Information Security Engineer throughout that period without any interruption. USCIS issues a cap-gap extension automatically when the petition is timely filed, but confirm the status with your DSO so your I-20 reflects the extension correctly.