STEM OPT Product Security Engineer Jobs
Product Security Engineer roles qualify for STEM OPT because they require a STEM degree in computer science, cybersecurity, or a related field. Your employer must be enrolled in E-Verify, and the 24-month STEM OPT extension gives you up to 36 months total to build experience in threat modeling, secure design, and vulnerability management before pursuing H-1B visa sponsorship.
Find STEM OPT Product Security Engineer JobsOverview
Showing 5 of 5+ Product Security Engineer jobs










See all Product Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Product Security Engineer roles.
Get Access To All Jobs
Who we are looking for
We are looking for a Security Product Manager, Perimeter Defense reporting directly to the Head of Defensive Engineering.
You will define and drive the strategy, roadmap, governance, and security outcomes for Perimeter Defense. Working across Security, GTS, application teams, and infrastructure teams, you will help ensure the organization's perimeter is continuously understood, assessed, protected, and improved.
This role is focused on bringing together multiple security capabilities and stakeholders to deliver measurable security outcomes and reduce perimeter risk.
Why this role is important to us
The team you will be joining is a part of Global Cyber Security, Defensive Engineering, a function that is vital to protecting the firm, its clients, and its critical business services from cyber threats.
As the organization's technology landscape continues to evolve, maintaining visibility into internet-facing assets and ensuring appropriate security controls are in place is increasingly important. This role helps establish a consistent approach to perimeter security by bringing together capabilities such as attack surface management, vulnerability management, web application protection, responsible disclosure, bug bounty programs, and security testing to improve the overall security posture.
What you will be responsible for
As a Security Product Manager, Perimeter Defense, you will:
- Define and maintain the strategy, roadmap, and security outcomes for the Perimeter Defense product.
- Establish visibility into perimeter-facing assets, including applications, infrastructure, domains, APIs, cloud services, and other externally accessible technologies.
- Identify gaps in security coverage and partner with the appropriate teams to drive improvements.
- Partner with GTS product owners and engineering teams to ensure security requirements and priorities are reflected in platform roadmaps.
- Help drive continuous assurance through attack surface management, vulnerability management, security testing, and related security capabilities.
- Define onboarding requirements and security standards for new perimeter-facing services and technologies.
- Establish metrics, reporting, and governance processes to measure effectiveness and communicate risk and progress to leadership.
- Support audit, regulatory, risk, and control assurance activities related to perimeter security.
What we value
These skills will help you succeed in this role:
- Strong communication, collaboration, and stakeholder management skills.
- Ability to translate security risks and requirements into practical business and technology outcomes.
- Understanding of cybersecurity concepts such as vulnerability management, perimeter security, application security, cloud security, or attack surface management.
- Experience coordinating initiatives across multiple teams and stakeholders.
- Strong analytical, problem-solving, and decision-making skills.
Education & Preferred Qualifications
- Bachelor's degree in Information Security, Computer Science, Engineering, Information Technology, or a related field, or equivalent experience.
- Experience in cybersecurity, technology, risk management, product management, or related disciplines.
- Familiarity with security technologies and controls such as vulnerability management, firewalls, web application security, cloud security, or related areas.
- Relevant cybersecurity or product management certifications are a plus.
Additional Requirements
- Ability to work effectively across global teams and multiple stakeholder groups.
- Strong written and verbal communication skills.
- Interest in security, product management, and driving measurable business outcomes.
Work Requirement
- Hybrid work model in accordance with company policy.
- Flexibility to support global teams across multiple time zones as needed.
Salary Range:
$120,000 - $202,500 Annual
The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.
For a full overview, visit https://hrportal.ehr.com/statestreet/Home.
About State Street
Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Job Application Disclosure:
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
See all STEM OPT Product Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT Product Security Engineer Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization as a Product Security Engineer
Verify your CIP code matches security
Check that your degree's Classification of Instructional Programs code falls under an approved STEM category. Computer Science (11.07xx), Information Security (11.1003), or Electrical Engineering (14.10xx) codes all support Product Security Engineer roles. Confirm with your DSO before applying.
Filter job postings by E-Verify status
Before you apply, confirm the employer is enrolled in E-Verify by searching the E-Verify employer search tool directly. Many security-focused employers at defense contractors and financial institutions are enrolled, but startup-stage companies often are not yet.
Build a threat modeling portfolio before interviewing
Product Security Engineer roles require hands-on evidence of secure design work. Document STRIDE or PASTA threat models from coursework or open-source projects. Hiring managers at product companies evaluate these artifacts directly during technical screens.
Use Migrate Mate to target verified sponsors
Search Migrate Mate to find Product Security Engineer roles at employers with active H-1B and STEM OPT filing history. Filtering by E-Verify enrollment and prior sponsorship activity narrows your list to companies already familiar with the I-983 training plan process.
Negotiate your I-983 training plan scope early
Raise the I-983 training plan in the offer stage, not after you start. The plan must list your learning objectives, supervision structure, and how the role ties to your STEM degree. Getting alignment before your start date avoids delays in your DSO's approval.
Time your H-1B registration around cap-gap protection
If your OPT expires between April 1 and September 30, cap-gap extends your work authorization automatically while the H-1B petition is pending. Confirm your employer files the I-129 before your EAD expiration date to stay continuously authorized.
Frequently Asked Questions
Does a cybersecurity or information security degree qualify for STEM OPT in a Product Security Engineer role?
Yes. Degrees in cybersecurity, information security, computer science, electrical engineering, and related STEM fields qualify, provided your degree's CIP code appears on the DHS STEM Designated Degree Program List. Confirm the exact CIP code on your transcript with your DSO before you submit the STEM OPT extension request, since the code on record determines eligibility, not the degree title alone.
What does the I-983 training plan need to include for a Product Security Engineer position?
The I-983 must describe how your day-to-day work as a Product Security Engineer connects to your STEM degree. That means listing specific learning objectives such as threat modeling, vulnerability assessment, or secure development lifecycle practices, identifying your direct supervisor, and explaining how the employer will provide oversight. USCIS and ICE both review these plans during compliance checks, so vague or template language creates risk for you and your employer.
How do I confirm a company hiring Product Security Engineers is enrolled in E-Verify?
Use the E-Verify employer search tool to look up the company by name or location before you apply. E-Verify enrollment is a hard requirement for STEM OPT employers. If a company does not appear in the search results, your DSO cannot approve the training plan, and your STEM OPT extension cannot begin at that employer regardless of the job offer.
Where can I find Product Security Engineer jobs where employers already understand STEM OPT requirements?
Migrate Mate lists Product Security Engineer roles filtered by employers with documented H-1B and STEM OPT sponsorship history. Targeting companies that have already filed LCAs for security engineering roles reduces the back-and-forth of explaining E-Verify enrollment and I-983 obligations to HR teams encountering OPT for the first time.
What happens to my STEM OPT authorization if my H-1B is selected in the lottery but my EAD expires before October 1?
Cap-gap protection extends your work authorization automatically if your OPT EAD expires between April 1 and September 30 and your employer filed an H-1B petition before that expiration date. You can continue working as a Product Security Engineer through September 30 under cap-gap. Your employer must file the I-129 on time, and your cap-gap period does not require a new EAD card.