STEM OPT Information Security Intern Jobs
Information Security Intern roles qualify for STEM OPT when your degree falls under a STEM-designated CIP code, giving you up to 24 months of extended work authorization beyond your initial OPT year. Your employer must be enrolled in E-Verify before you can start, and you'll need a signed I-983 training plan on file with your DSO.
Find STEM OPT Information Security Intern JobsOverview
Showing 5 of 173+ Information Security Intern jobs










See all 173+ Information Security Intern Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Information Security Intern roles.
Get Access To All Jobs
INTRODUCTION
Columbia College Chicago is an acclaimed undergraduate and graduate institution that provides a comprehensive education in the arts, communications, and public relations. We constantly aim to reach our full potential as an educational innovator, incubator of new creative practice and generator of real-world success for young creatives. We are in the heart of Chicago, across the street from historic Grant Park, and housed in some of the most iconic buildings in the South Loop.
Columbia College Chicago is a private urban institution of approximately 4,000 undergraduate and graduate students, four-year College offering a distinctive curriculum that blends liberal arts, creative and media arts and business is currently searching for a(an) INFORMATION SECURITY ENGINEER.
The Information Security Engineer designs, implements, maintains, and supports implementation and ongoing operation of the institution’s systems and data security. This role is responsible for monitoring, analyzing, and responding to cybersecurity threats, as well as assisting in maintaining compliance with regulatory and institutional security standards.
Working closely with Academic and Business stakeholders, the Information Security Engineer helps protect institutional data, information systems, and operational processes by applying security best practices and supporting continuous improvement of the institution’s security posture. This role requires strong analytical skills, attention to detail, and the ability to collaborate across departments.
Flex work options available.
DUTIES & RESPONSIBILITIES:
- Monitor and manage technologies, including SIEM, endpoint protection, EDR, and other security platforms, to detect, analyze, investigate, mitigate, patch and respond to security threats and vulnerabilities.
- Analyze cybersecurity threats and design, architect, implement, and maintain security solutions that protect the confidentiality, integrity, and availability of institutional data and systems.
- Conduct vulnerability scanning and security assessments; analyze findings, document risks, and perform appropriate remediation actions.
- Support and participate in incident response activities by investigating security alerts and incidents, determining impact, escalating issues as appropriate, and assisting with containment, eradication, recovery, and resolution efforts.
- Implement and maintain access controls for sensitive, confidential, and high-security data while supporting identity and access management processes, least-privilege principles, authentication controls, and privileged access security.
- Collaborate to design, implement, and maintain security controls across infrastructure, applications, endpoints, networks, and cloud environments.
- Maintain and enforce information security policies, standards, procedures, and technical controls to ensure compliance with regulatory and institutional requirements.
- Evaluate information security risks associated with new technologies, systems, and implementations and recommend or implement appropriate security controls to mitigate identified risks.
- Manage and support third-party relationships and technology vendors by facilitating communication, evaluating security requirements, monitoring contract and compliance obligations, and assisting with the resolution of security-related issues.
- Conduct or support third-party security risk assessments to evaluate vendor security practices, data protection measures, and compliance with institutional security requirements.
- Support the development and delivery of information security awareness and training programs for faculty, staff, and students.
- Track, analyze, and report on security incidents, vulnerabilities, trends, and metrics to identify areas for improvement and support the ongoing development of the Institution's information security program.
- Stay current with emerging cybersecurity threats, vulnerabilities, technologies, regulatory requirements, and industry best practices, and assess their potential impact on the Institution.
- Perform other related duties and/or responsibilities as assigned or required.
QUALIFICATIONS
- Bachelor’s degree in computer science, Information Systems, cybersecurity, or a related field, or an equivalent combination of education and relevant professional experience.
- 3-5 years of professional experience in information security, cybersecurity operations, IT operations, systems administration, or a related field.
- Experience with Security Information and Event Management (SIEM) platforms such as Humio, Splunk, Microsoft Sentinel, QRadar, or similar security monitoring and log analysis solutions.
- Experience with Endpoint Detection and Response (EDR) and endpoint protection platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, or equivalent technologies.
- Experience with vulnerability management and security assessment processes, including vulnerability scanning, risk assessment, remediation tracking, and risk prioritization.
- Experience with identity and access management (IAM), multi-factor authentication (MFA), privileged access controls, least-privilege principles, and user identity lifecycle management.
- Experience supporting and securing cloud and hybrid environments, including Microsoft 365, Microsoft Entra ID, and related Microsoft security technologies.
- Experience with security monitoring, incident response, threat detection, investigation, containment, remediation, and recovery processes.
- Knowledge of common cybersecurity threats, attack vectors, vulnerabilities, security controls, mitigation strategies, and information security frameworks and industry best practices, including the NIST Cybersecurity Framework, CIS Controls, and applicable regulatory and compliance requirements.
- Ability to analyze security risks and implement or recommend appropriate technical and administrative controls to mitigate identified risks.
- Strong analytical, troubleshooting, critical-thinking, and problem-solving skills, with the ability to investigate security events, assess vulnerabilities, diagnose complex security issues, and identify effective solutions.
- Strong technical aptitude, written and verbal communication skills, and the ability to communicate technical risks, security requirements, and cybersecurity concepts effectively to both technical and non-technical stakeholders.
- Strong organizational, documentation, project coordination, and time management skills, with the ability to manage multiple priorities while maintaining confidentiality and protecting sensitive institutional data.
- Ability to collaborate effectively with technical and non-technical stakeholders across the organization and work with cross-functional teams to implement security solutions.
- Experience evaluating security risks associated with third-party vendors, applications, cloud services, and technology implementations is preferred.
- Experience with higher education information security, regulatory requirements, or compliance frameworks, including GLBA, is preferred.
- Relevant industry certifications such as CompTIA Security+, CySA+, CEH, GSEC, SSCP, or equivalent certifications are preferred.
This job description is not intended to be a comprehensive list of all duties, responsibilities, or qualifications associated with the position. Duties and responsibilities may change at any time based on departmental and/or College needs.
Position Minimum Annual Salary: $86,034
Position Maximum Annual Salary: $106,897
The salary range provided in this posting reflects what we reasonably expect to pay for this position. Actual compensation offered or earned is dependent on experience, education and other factors including department budget.
At Columbia, we offer a rewarding work environment for our faculty and staff. We take pride in offering competitive benefits with affordable health, dental and vision coverage; flexible spending accounts; commuter benefit program, life, and accidental, death & dismemberment coverage; paid and unpaid leave options; work/life benefits; educational assistance programs; and retirement and financial planning benefits.
We invite you to join our talented faculty and staff and become part of our collective aspiration to ensure Columbia prepares students for success in their creative fields through innovation, engagement, and real-world experiences.
ADDITIONAL INFORMATION
- Position subject to a background screening
- This is a non-union position
- This is a full-time position
- This position is overtime ineligible
Qualified candidates of all backgrounds are encouraged to apply.
Columbia College Chicago is an equal opportunity employer and complies with all local, state, and federal laws and regulations concerning civil rights. The college does not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national or ethnic origin, age, disability, protected veteran status, genetic information, or other protected classes under the law.
PRIMARY LOCATION
: United States-Illinois-Chicago
JOB
: Information Technology
SCHEDULE
: Full-time
SHIFT
: Day Job
JOB TYPE
: Standard
JOB LEVEL
: Individual Contributor
TRAVEL
: No
See all 173+ STEM OPT Information Security Intern Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT Information Security Intern Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization as an Information Security Intern
Verify your CIP code covers cybersecurity
Check your official transcript against the DHS STEM Designated Degree Program List before applying. Degrees in Computer Science, Information Assurance, or Electrical Engineering typically qualify, but Information Systems degrees vary by institution and CIP code.
Confirm E-Verify enrollment before accepting offers
Ask the recruiter for the company's E-Verify Company ID or check enrollment status directly through E-Verify before signing anything. An employer who can't provide that ID cannot legally employ you on STEM OPT, regardless of how the offer reads.
Request a security-clearance policy in writing
Many federal contractor roles in information security require clearance eligibility, which non-U.S. citizens cannot obtain. Get the employer's citizenship and clearance requirements in writing before investing time in their interview process.
Map your training plan to SOC code 15-1212
Your I-983 must tie your learning objectives to specific information security tasks. Use O*NET's profile for Information Security Analysts to pull recognized tasks and knowledge areas your supervisor can reference when completing the training plan.
File your STEM OPT extension 90 days early
USCIS recommends submitting your I-765 extension at least 90 days before your initial OPT expires. Your DSO must issue an updated I-20 first, so build that lead time into your job search timeline and don't wait until you have an offer.
Use Migrate Mate to target verified sponsors
Filter your search on Migrate Mate to surface employers with confirmed E-Verify enrollment and active STEM OPT hiring history in security roles. That removes the guesswork of cold-applying to companies that will reject you at the offer stage.
Frequently Asked Questions
Does an Information Security Intern role qualify for the STEM OPT extension?
It qualifies if your underlying degree is on the DHS STEM Designated Degree Program List and the internship maps to a STEM field of study. The role itself doesn't determine eligibility on its own. Your DSO confirms eligibility based on your CIP code when issuing the updated I-20 for the I-765 extension application.
What E-Verify requirement applies to my employer for STEM OPT?
Your employer must be actively enrolled in E-Verify at the worksite where you'll be based before your STEM OPT start date. Enrollment at the company's headquarters doesn't automatically cover a subsidiary or separate office location. Confirm the specific worksite's E-Verify status with HR before your start date, not after.
What should my I-983 training plan include for an information security internship?
The I-983 must describe specific learning objectives tied to your STEM degree, not just your daily job tasks. For an information security role, that means listing skills like network threat analysis, vulnerability assessment, or security operations that directly connect to your degree's coursework. Your supervisor signs off on the plan and must evaluate your progress every six months.
How does cap-gap protection work if my employer files an H-1B petition for me after this internship?
If you're selected in the H-1B lottery and your employer files a timely petition before your OPT EAD expires, cap-gap automatically extends your work authorization through September 30 of that year. You can continue working in the information security role during cap-gap as long as the petition remains pending and your status is maintained.
Where can I find Information Security Intern roles from employers who are already set up for STEM OPT?
Migrate Mate filters listings to show employers with confirmed E-Verify enrollment, which is the baseline requirement for any STEM OPT placement. Searching there saves you from applying to roles where the employer will stall or rescind an offer once they realize the STEM OPT compliance steps they need to complete.