STEM OPT Network Security Engineer Jobs
Network Security Engineer roles qualify for the 24-month STEM OPT extension when your degree falls under an eligible CIP code and your employer is enrolled in E-Verify. You'll need a STEM degree in computer science, information security, or a related field, plus a signed I-983 training plan before your extension starts.
Find STEM OPT Network Security Engineer JobsOverview
Showing 5 of 50+ Network Security Engineer jobs










See all 50+ Network Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Network Security Engineer roles.
Get Access To All Jobs
INTRODUCTION
Last year our HCA Healthcare colleagues invested over 156,000 hours volunteering in our communities. As a Network Security Engineer II with HCA Healthcare you can be a part of an organization that is devoted to giving back!
JOB SUMMARY
Support and contribute to the implementation, modernization, standardization and enhancement of network security controls to protect a Fortune 100 enterprise’s infrastructure, patients and data from increasing risk and threats. The position will perform reviews and assess policies for risk and vulnerabilities with assistance from assessments or internal security audits and identify potential hardening opportunities, provide remediation recommendations and solutions and assist in the implementation or configuration changes to support continuous security control maturity and risk reduction. This position will work collaboratively with other IT teams to implement risk management practices, optimize technology solutions, monitor and adjust infrastructure to meet current and future needs, ensure compliance with regulatory requirements, and continuously plan for the future to improve our security posture and control maturity. The ideal candidate will be experienced in network security fundamentals and have a strong understanding of how to develop and implement remediation plans to address identified risks, implement new features and technologies, standardize and optimize existing technologies, establish and maintain baselines, and automate processes wherever possible to increase efficiency and reduce errors.
GENERAL RESPONSIBILITIES
Responsibilities include but are not limited to the following:
-
Assist in the evaluation, recommendation, and implementation of appropriate security measures, including next-generation firewall features, intrusion detection/prevention systems, VPN, network segmentation/zero trust, multifactor and access control mechanisms.
-
Conduct firewall rule reviews, security audits, baseline and best practice compliance, forensic network investigation to support data transmission adherence and implement or oversee recommendations.
-
Support and contribute to network security solutions under the guidance of senior engineers to protect the organization's infrastructure, applications, and data from cyber threats in accordance with regulatory and industry requirements, such as PCI DSS, SOX, NIST, ISO 27000, and HIPAA.
-
Evaluate vulnerability assessments, penetration tests, metrics and security audits to identify potential hardening opportunities and provide remediation recommendations and solutions.
-
Assisting with the implementation of solutions and configuration changes within a large enterprise network under the guidance of senior engineers in support of continuous security control maturity and risk reduction.
-
Participate in incident response and disaster recovery planning and testing.
-
Collaborate with other IT teams to ensure that network security controls are integrated with other systems and applications and are up to security standards.
-
Conduct routine network security audits and control tests on deployed technologies, collecting and consolidating indicators of performance, risks, trends and providing recommendations, baseline and regulatory compliance ratings.
-
Participate in relationships with vendors and contractors to ensure that security services are timely delivered and implemented in alignment to security policies.
-
Collaborate with senior engineers on the development and documentation of security policies and procedures, training and awareness.
-
Assist department leads with training peers on compliance and best practices.
-
Assist with research and design enhancements of automated solutions or best of breed technologies while assisting with integration tests with vendors.
-
Keep up to date with the latest threats and vulnerabilities, as well as relevant regulations and industry best practices, and implement recommendations to improve the organization's security posture and maturity control.
Experience
Qualified candidates must have 3+ years of relevant work experience.
Education
Bachelor’s degree preferred.
OTHER/SPECIAL QUALIFICATIONS
-
Relevant experience with security technologies, such as next-generation firewalls, intrusion detection/prevention systems, VPN, network segmentation, access control mechanisms, and security design, management, best practices, policy, standards in large 1000+ firewall environments.
-
Experience in Checkpoint Firewall, CMA, Provider-1, Maestro, VSX/VSLS, Cloud Guard.
-
Administration of one or many of the following Cisco Network Security Products & Technologies (i.e. Firepower, ASA, VPN, WSA, ISE, Stealthwatch, etc.).
-
Strong understanding of network protocols, topologies, tools, subnetting and architectures.
-
Aptitude in Network Security Policy Management tools (Algosec, Tufin) and/or conducting risk assessments, firewall rule review, and security audits.
-
Strong knowledge of enterprise security technologies and processes (Zscaler, A10, F5, WAF, Advanced Threat Detection Tools, Antibot, Antimalware, Threat Emulation, SIEM, IDS/IPS, Network Packet Analysis, Netflow, etc.).
-
Experience administrating solutions for security standards and frameworks, such as HIPAA, SOX, PCI DSS, HITECH, ISO/IEC 27001, and NIST Cybersecurity Framework.
-
Knowledge of Network Security Management Tools/Technologies (e.g: Splunk, TrustSec, segmentation, syslog, etc.).
-
Excellent verbal and written communication, interpersonal, analytical and problem-solving skills.
-
Ability to work independently and as part of a team.
-
Relevant certifications from ISC2 (CISSP), GIAC (GISP), ISACA (CISA), Cisco Security or CompTIA are a plus.
PHYSICAL DEMANDS/WORKING CONDITIONS
Position expectations are nominal supervision required due to design, service and support knowledge/skillsets.
- Position may require periodic after hours work and light travel at times with little notice and requires sitting for extended periods.
Benefits
HCA Healthcare offers a total rewards package that supports the health, life, career and retirement of our colleagues. The available plans and programs include:
-
Comprehensive benefits for medical, prescription drug, dental, vision, behavioral health and telemedicine services.
-
Wellbeing support, including free counseling and referral services.
-
Time away from work programs for paid time off, paid family leave, long- and short-term disability coverage and leaves of absence.
-
Savings and retirement resources, including a 401(k) Plan with a 100% match on 3% to 9% of pay (based on years of service), Employee Stock Purchase Plan, flexible spending accounts, preferred banking partnerships, retirement readiness tools, rollover support and financial wellbeing counseling.
-
Education support through tuition assistance, student loan assistance, certification support, dependent scholarships and a partnership with Galen College of Nursing.
-
Additional benefits for fertility and family building, adoption assistance, life insurance, supplemental health protection plans, auto and home insurance, legal counseling, identity theft protection and consumer discounts.
Learn more about Employee Benefits.
Note: Eligibility for benefits may vary by location.
HCA Healthcare has been recognized as one of the World's Most Ethical Companies® by the Ethisphere Institute more than ten times. In recent years, HCA Healthcare spent an estimated $3.7 billion in cost for the delivery of charitable care, uninsured discounts, and other uncompensated expenses.
"There is so much good to do in the world and so many different ways to do it." - Dr. Thomas Frist, Sr.
HCA Healthcare Co-Founder
Be a part of an organization that invests in you! We are reviewing applications for our Network Security Engineer II opening. Qualified candidates will be contacted for interviews. Submit your application and help us raise the bar in patient care!
We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
See all 50+ STEM OPT Network Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT Network Security Engineer Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization as a Network Security Engineer
Verify your CIP code qualifies first
Check your degree's Classification of Instructional Programs code against the DHS STEM Designated Degree Program List before applying. Computer science, cybersecurity, and information assurance codes typically qualify, but electrical engineering or mathematics degrees may require your DSO to confirm eligibility.
Confirm E-Verify enrollment before accepting offers
Your employer must be actively enrolled in E-Verify before your STEM OPT extension can begin. Search the E-Verify employer search tool or ask the recruiter for their E-Verify Company ID number during the offer stage, not after signing.
Build a network security credential portfolio early
Certifications like CISSP, CompTIA Security+, or CEH signal to hiring managers that your skills transfer directly to U.S. enterprise security environments. Employers filing I-983 training plans for network security roles expect documented technical competencies tied to specific learning objectives.
Target employers with active LCA filings in security roles
Search Migrate Mate to identify employers who have filed Labor Condition Applications for network security or information security positions. LCA filing history shows which companies have already navigated STEM OPT and H-1B visa sponsorship for similar roles.
Draft your I-983 training objectives before the offer stage
Network security engineers can map training goals to specific NIST frameworks, SOC operations, or penetration testing projects your employer will assign. Having a draft ready speeds up the employer sign-off process and signals you understand the STEM OPT training plan requirement.
Time your extension filing to protect cap-gap coverage
If your employer files an H-1B petition before your OPT expires, cap-gap rules extend your work authorization through September 30 of that year. File your STEM OPT extension at least 90 days before your initial OPT end date to avoid any gap in authorization.
Frequently Asked Questions
Does my degree qualify me for the STEM OPT extension as a network security engineer?
Your degree qualifies if it appears on the DHS STEM Designated Degree Program List. Degrees in computer science, cybersecurity, information assurance, electrical engineering, and applied mathematics commonly support network security roles. Check the specific Classification of Instructional Programs code on your degree with your DSO, since the job title alone doesn't determine eligibility.
What does the I-983 training plan need to cover for a network security engineer role?
Your I-983 must describe specific learning objectives tied to your actual job duties, not a generic job description. For network security engineers, that means outlining training in areas like intrusion detection, firewall management, vulnerability assessment, or incident response. Your employer signs the plan and must evaluate your progress at the six-month and twelve-month marks throughout the extension period.
How do I confirm my employer is enrolled in E-Verify before my STEM OPT extension starts?
Ask the recruiter or HR contact for the company's E-Verify Company ID number during the offer stage. You can also search the E-Verify employer search tool using the company name to confirm active enrollment. If the employer isn't enrolled, they cannot legally employ you on a STEM OPT extension, and enrollment must be completed before your extension begins.
How does cap-gap work if I'm on STEM OPT and my employer files an H-1B petition?
If your employer files a timely H-1B petition before your STEM OPT expires, cap-gap provisions automatically extend your work authorization through September 30 of the fiscal year the petition is pending. You can continue working in your network security engineer role during this period. USCIS provides guidance on the specific timely filing requirements that trigger cap-gap protection.
Where can I find network security engineer jobs where employers are already familiar with STEM OPT?
Migrate Mate filters network security engineer listings by employers with verified E-Verify enrollment and LCA filing history, so you can target companies that have already sponsored STEM OPT and H-1B workers in security roles. This reduces the back-and-forth of explaining authorization requirements to employers who haven't hired international graduates before.