STEM OPT Product Security Engineer Jobs
Product Security Engineer roles qualify for STEM OPT because they require a STEM degree in computer science, cybersecurity, or a related field. Your employer must be enrolled in E-Verify, and the 24-month STEM OPT extension gives you up to 36 months total to build experience in threat modeling, secure design, and vulnerability management before pursuing H-1B visa sponsorship.
Find STEM OPT Product Security Engineer JobsOverview
Showing 5 of 85+ Product Security Engineer jobs










See all 85+ Product Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Product Security Engineer roles.
Get Access To All Jobs
COMPANY OVERVIEW
KKR is a leading global investment firm that offers alternative asset management as well as capital markets and insurance solutions. KKR aims to generate attractive investment returns by following a patient and disciplined investment approach, employing world-class people, and supporting growth in its portfolio companies and communities. KKR sponsors investment funds that invest in private equity, credit and real assets and has strategic partners that manage hedge funds. KKR’s insurance subsidiaries offer retirement, life and reinsurance products under the management of Global Atlantic Financial Group. References to KKR’s investments may include the activities of its sponsored funds and insurance subsidiaries.
TEAM OVERVIEW
KKR's Technology organization is a group of passionate technologists and product managers, unified by a shared mission to deliver exceptional products and solutions that drive value for our stakeholders, clients, and investors. Our passion for technology and innovation fuels our commitment to creating high-quality, impactful solutions that address complex challenges and meet the evolving needs of our sophisticated businesses.
Teamwork is at the core of the organization’s success. We thrive on open collaboration and continuous learning, driving a culture that values diversity of thought and collective achievement. Our global footprint fosters the integration of a diverse set of ideas and viewpoints in product and solution delivery, allowing us to design more comprehensive solutions that are adaptable and scalable. We optimize for impact, prioritizing and delivering solutions with excellence while remaining agile in response to the evolving needs of our businesses.
Position Summary
KKR is seeking an experienced Product Security Professional. This role offers exciting opportunities for growth and impact as KKR scales its business and continues to innovate. As a Security Analyst, you will be responsible for designing, implementing, and maintaining security measures across our environment specific to our internally developed applications and external facing applications. You must be proficient in troubleshooting, vulnerability management, cloud security, application security, and have a deep understanding of a wide range of systems and be capable of leading other teams in these efforts. You will work closely with IT and other business units to ensure our security posture remains strong, aligned with industry best practices, and compliant with regulatory requirements. You will also be looking over the horizon, identifying future needs and exploring leading edge solutions.
Responsibilities:
- Conduct application security assessments and penetration tests to identify vulnerabilities and security issues.
- Work closely with the software development team to ensure that secure coding practices are implemented throughout the application development lifecycle.
- Design and implement security solutions to protect applications from potential threats.
- Provide guidance and recommendations on application security best practices.
- Maintain knowledge of the latest security trends, threats, and countermeasures.
- Participate in incident response and handling activities related to application security incidents.
- Conduct security awareness and training sessions for the development team to promote secure coding practices.
- Develop and maintain application security standards, policies, and procedures.
- Report and document security findings and remediation activities.
- Integrate security tools and practices into the continuous integration/continuous delivery (CI/CD) pipeline.
QUALIFICATIONS
- Bachelor's degree in computer science, information technology, or a related field.
- Proven experience as an Application Security Engineer or similar role.
- Strong understanding of software development life cycle (SDLC) and secure coding practices.
- Proficiency in conducting security assessments and penetration tests.
- Experience with security tools and technologies such as firewalls, VPNs, intrusion detection/prevention systems (IDS/IPS), and network access control (NAC).
- Knowledge of regulatory requirements and industry best practices related to application security.
- Experience with cloud security and DevSecOps practices.
- Familiarity with OWASP Top Ten and other security frameworks.
- Team-player who enjoys working in a collaborative and collegial environment and is an active contributor as part of a global team.
- Ability to work calmly under pressure and meet deadlines and solve problems requiring creativity, initiative and drive; self-motivated and enjoys a sense of pride in their accomplishments.
- Ability to present ideas in a user-friendly, business-friendly and technical language.
- Strategic self-starter with an innovative mindset and outstanding attention to detail.
LI-ONSITE
This is the expected annual base salary range for this Boston-based position. Actual salaries may vary based on factors, such as skill, experience, and qualification for the role. Employees may be eligible for a discretionary bonus, based on factors such as individual and team performance.
Base Salary Range
$135,000 - $170,000 USD
KKR is an equal opportunity employer. Individuals seeking employment are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, sexual orientation, or any other category protected by applicable law.
KKR will provide reasonable accommodations as required by applicable federal, state, and/or local laws. Individuals seeking an accommodation for the application or interview process should email Benefits@kkr.com. Emails sent for unrelated issues, such as following up on an application, will not receive a response.
If you are a qualified individual with a disability or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to use or access https://www.kkr.com/careers because of your disability. You can request reasonable accommodations by sending an email to Benefits@kkr.com. Only emails left for this purpose will be returned.
Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. This notice applies only to applicants and employees who work or will work in Massachusetts, in accordance with applicable state law.
See all 85+ STEM OPT Product Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT Product Security Engineer Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization as a Product Security Engineer
Verify your CIP code matches security
Check that your degree's Classification of Instructional Programs code falls under an approved STEM category. Computer Science (11.07xx), Information Security (11.1003), or Electrical Engineering (14.10xx) codes all support Product Security Engineer roles. Confirm with your DSO before applying.
Filter job postings by E-Verify status
Before you apply, confirm the employer is enrolled in E-Verify by searching the E-Verify employer search tool directly. Many security-focused employers at defense contractors and financial institutions are enrolled, but startup-stage companies often are not yet.
Build a threat modeling portfolio before interviewing
Product Security Engineer roles require hands-on evidence of secure design work. Document STRIDE or PASTA threat models from coursework or open-source projects. Hiring managers at product companies evaluate these artifacts directly during technical screens.
Use Migrate Mate to target verified sponsors
Search Migrate Mate to find Product Security Engineer roles at employers with active H-1B and STEM OPT filing history. Filtering by E-Verify enrollment and prior sponsorship activity narrows your list to companies already familiar with the I-983 training plan process.
Negotiate your I-983 training plan scope early
Raise the I-983 training plan in the offer stage, not after you start. The plan must list your learning objectives, supervision structure, and how the role ties to your STEM degree. Getting alignment before your start date avoids delays in your DSO's approval.
Time your H-1B registration around cap-gap protection
If your OPT expires between April 1 and September 30, cap-gap extends your work authorization automatically while the H-1B petition is pending. Confirm your employer files the I-129 before your EAD expiration date to stay continuously authorized.
Frequently Asked Questions
Does a cybersecurity or information security degree qualify for STEM OPT in a Product Security Engineer role?
Yes. Degrees in cybersecurity, information security, computer science, electrical engineering, and related STEM fields qualify, provided your degree's CIP code appears on the DHS STEM Designated Degree Program List. Confirm the exact CIP code on your transcript with your DSO before you submit the STEM OPT extension request, since the code on record determines eligibility, not the degree title alone.
What does the I-983 training plan need to include for a Product Security Engineer position?
The I-983 must describe how your day-to-day work as a Product Security Engineer connects to your STEM degree. That means listing specific learning objectives such as threat modeling, vulnerability assessment, or secure development lifecycle practices, identifying your direct supervisor, and explaining how the employer will provide oversight. USCIS and ICE both review these plans during compliance checks, so vague or template language creates risk for you and your employer.
How do I confirm a company hiring Product Security Engineers is enrolled in E-Verify?
Use the E-Verify employer search tool to look up the company by name or location before you apply. E-Verify enrollment is a hard requirement for STEM OPT employers. If a company does not appear in the search results, your DSO cannot approve the training plan, and your STEM OPT extension cannot begin at that employer regardless of the job offer.
Where can I find Product Security Engineer jobs where employers already understand STEM OPT requirements?
Migrate Mate lists Product Security Engineer roles filtered by employers with documented H-1B and STEM OPT sponsorship history. Targeting companies that have already filed LCAs for security engineering roles reduces the back-and-forth of explaining E-Verify enrollment and I-983 obligations to HR teams encountering OPT for the first time.
What happens to my STEM OPT authorization if my H-1B is selected in the lottery but my EAD expires before October 1?
Cap-gap protection extends your work authorization automatically if your OPT EAD expires between April 1 and September 30 and your employer filed an H-1B petition before that expiration date. You can continue working as a Product Security Engineer through September 30 under cap-gap. Your employer must file the I-129 on time, and your cap-gap period does not require a new EAD card.