STEM OPT IT Security Analyst Jobs
IT Security Analyst roles qualify for the 24-month STEM OPT extension if your degree falls under an eligible CIP code in computer science, cybersecurity, or information technology. Your employer must be enrolled in E-Verify and sign your I-983 training plan. That gives you up to 36 months of OPT work authorization to build hands-on security experience.
Find STEM OPT IT Security Analyst JobsOverview
Showing 5 of 24+ IT Security Analyst jobs










See all IT Security Analyst Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new IT Security Analyst roles.
Get Access To All Jobs
INTRODUCTION
The New Mexico Division of Vocational Rehabilitation (NMDVR) is a state-run agency dedicated to assisting individuals with disabilities in achieving employment success. Through services such as vocational counseling, job placement assistance, training and education, assistive technology, and support services, NMDVR aims to enhance the employability and independence of people with various disabilities. Tailoring its programs to meet individual needs, the agency is committed to facilitating competitive employment and fostering independence among its clientele.
This posting will be used for ongoing recruitment and may close at any time. Applicant lists may be screened more than once.
ROLE AND RESPONSIBILITIES
The role of the Senior IT Security Analyst exists to manage and mitigate risks related to security and regulatory compliance, ensuring that the organization operates securely and in accordance with state/federal regulations and industry standards. The position's expertise and responsibilities are crucial for safeguarding NMDVR against internal and external threats.
Under direct supervision of the NMDVR Director, the incumbent of this position will support the agency's information security program through the management and oversight of cybersecurity tools, risk management activities, security audits and assessments, compliance monitoring, incident response, security architecture, disaster recovery planning, continuous improvement initiatives, and employee security awareness and training efforts.
The position will work closely with the Chief Information Officer (CIO) to ensure the proper configuration and security of IT systems, including the protection of information both in transit and at rest, while supporting ongoing vulnerability assessments and periodic penetration testing activities to strengthen the agency's overall cybersecurity posture. The incumbent will also assist in the development and implementation of a comprehensive, risk-based information security program aligned with agency operational and compliance requirements.
-
Oversee the implementation, administration, and maintenance of information security tools and technologies, including firewalls, antivirus solutions, intrusion detection/prevention systems, and access control systems.
-
Monitor emerging cybersecurity threats, vulnerabilities, and industry trends to recommend and implement enhancements to security policies, procedures, controls, and technologies. Collaborate with vendors to evaluate security solutions and ensure compliance with organizational security requirements. Develop, test, and maintain disaster recovery and business continuity plans to support organizational resilience and regulatory compliance.
-
Conduct risk assessments of IT systems, applications, networks, and infrastructure to identify potential vulnerabilities and develop mitigation strategies and risk management plans.
-
Perform security audits, vulnerability assessments, and compliance reviews of IT systems, applications, databases, and networks to identify security weaknesses and ensure adherence to established standards and policies.
-
Monitor and ensure compliance with applicable regulations, standards, and best practices related to information security and data protection, including National Institute of Standards and Technology (NIST) guidelines and Personally Identifiable Information (PII) requirements.
-
Assist in the design, implementation, and maintenance of secure IT architectures, systems, and security controls.
-
Lead and coordinate incident response activities related to cybersecurity events, including investigation, containment, remediation, recovery, and response to security alerts.
-
Develop and deliver cybersecurity awareness and training programs to promote organizational security best practices and employee compliance.
-
Perform other duties as assigned.
MINIMUM QUALIFICATIONS
Bachelor's degree in Computer Science, Management Information Systems (MIS), Information Technology, Engineering, or similar technical degree and three (3) years of experience in IT security or compliance validation (e.g., HIPAA, PCI). Any combination of education from an accredited college or university in a related field and/or direct experience in this occupation totaling seven (7) years may substitute for the required education and experience. A certificate in IT security/forensics (e.g., CISSP, CEH, CCFP, CCSP, HCISPP, SSCP) or regulated compliance (e.g., PCIP, ASV, ISA, QSA) can be used to substitute one (1) year of experience.
EMPLOYMENT REQUIREMENTS
Occasional travel is required.
WORKING CONDITIONS
Work will be performed in an office environment. Many requests will arrive by phone or in-person and the person must be able to speak and respond to the requester clearly. The person will work extended periods seated in front of a computer. The person must be able to operate a computer, keyboard, and mouse. Position requires occasional 1) travel, 2) night/weekend/holiday work, and 3) call-back work.
SUPPLEMENTAL INFORMATION
Do you know what Total Compensation is? Click here
Agency Contact Information: Tina Montoya (505) 264-3944 Email
For information on Statutory Requirements for this position, click the Classification Description link on the job advertisement.
The NMDVR is an equal opportunity employer. Applicants selected for an interview must notify the NMDVR of the need for a reasonable accommodation by informing the agency contact listed in the job posting.
BARGAINING UNIT POSITION
This position is not covered by a collective bargaining agreement.
See all STEM OPT IT Security Analyst Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT IT Security Analyst Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization as an IT Security Analyst
Verify your degree's CIP code eligibility
Check that your degree's Classification of Instructional Programs code appears on the official STEM Designated Degree Program List. Computer science, cybersecurity, and information systems degrees typically qualify, but program names vary by school and can affect your extension eligibility.
Confirm E-Verify enrollment before accepting offers
Ask your recruiter or HR contact directly whether the company is enrolled in E-Verify before you advance past the offer stage. STEM OPT requires E-Verify enrollment, and not every employer with a security practice has completed that registration.
Target employers with active security clearance pipelines
Federal contractors and defense-adjacent firms file LCAs for IT Security Analyst roles at high volume. Filter for employers who have filed recent LCAs through DOL, since active filings signal they already know the paperwork requirements for employing F-1 students.
Search Migrate Mate for E-Verify verified security roles
Filter your search on Migrate Mate to surface IT Security Analyst positions at employers already enrolled in E-Verify. That single filter removes the friction of vetting each company manually and keeps your application pipeline focused on eligible roles.
Structure your I-983 training plan around SOC code duties
When drafting your I-983 with your employer, align the listed training goals to the SOC 15-1212 duties documented in O*NET. Supervisors unfamiliar with I-983 requirements respond better when the training objectives map directly to defined job tasks rather than generic skill goals.
Time your extension request against your OPT end date
Your DSO must recommend the STEM OPT extension at least 90 days before your current OPT EAD expires. File the I-765 with USCIS promptly after that recommendation, since USCIS processing can run several months and a late filing risks a work authorization gap.
Frequently Asked Questions
Does an IT Security Analyst role qualify for the STEM OPT extension?
Yes, if your employer is enrolled in E-Verify and your degree carries an eligible CIP code. IT Security Analyst positions fall under SOC code 15-1212, and degrees in computer science, cybersecurity, information systems, or closely related STEM fields typically qualify. Confirm your specific CIP code on the official STEM Designated Degree Program List maintained by the Department of Homeland Security.
What does the I-983 training plan cover for an IT Security Analyst position?
The I-983 documents the practical training your employer will provide, how it connects to your STEM degree, and how your supervisor will evaluate your progress. For IT Security Analyst roles, training goals typically cover threat monitoring, vulnerability assessment, incident response, or security compliance work. Your employer signs the form, and your DSO submits it to update your SEVIS record before your extension begins.
How do I verify that a potential employer is enrolled in E-Verify?
Ask HR or your recruiter directly whether the company has an active E-Verify account, and request the E-Verify company ID if you want to confirm enrollment. E-Verify enrollment is a hard requirement for STEM OPT employers, not an optional credential. Some employers in the security sector are enrolled at the parent company level but not at subsidiary locations, so ask specifically about the office where you would work.
Can I work as an IT Security Analyst while my STEM OPT extension application is pending?
Yes, if you filed your I-765 before your current OPT EAD expired, the cap-gap provision extends your work authorization automatically while USCIS adjudicates your application. Your authorization is tied to the timely and pending status of your extension filing. Carry your SEVIS I-20 showing the DSO-recommended extension alongside your expired EAD as combined proof of continued authorization.
Where can I find IT Security Analyst jobs where the employer already understands STEM OPT requirements?
Migrate Mate filters IT Security Analyst listings to show employers enrolled in E-Verify, which removes the most common hiring obstacle for STEM OPT students. Targeting employers with existing STEM OPT or H-1B visa filing history also signals that their HR teams are already familiar with the I-983 process, the 90-day reporting obligations, and the practical training documentation USCIS expects.