STEM OPT Security Engineer Jobs
Security Engineer roles fall squarely within STEM OPT eligibility, giving you up to 24 months of extended work authorization beyond your initial OPT period. Your employer must be enrolled in E-Verify, and your degree in computer science, information security, or a related STEM field must align with the role's CIP code to qualify.
Find STEM OPT Security Engineer JobsOverview
Showing 5 of 262+ Security Engineer jobs










See all 262+ Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Security Engineer roles.
Get Access To All Jobs
POWER UP A CAREER WITH US
Our people power everything we do.
At Tampa Electric, dependable electricity starts with dedicated individuals whose talent, skill and passion drive our success. We’ve been lighting the way for West Central Florida for more than 125 years—and we’re just getting started.
Join us and build a rewarding career with competitive pay, comprehensive benefits and a culture that supports your growth. Your potential finds its purpose at Tampa Electric.
We proudly deliver 99.98% electric service reliability to nearly 860,000 customers across 2,000 square miles of Hillsborough County and parts of Polk, Pasco and Pinellas counties. Through innovation and strategic investments, we’re creating a cleaner, brighter energy future—while delivering exceptional service every step of the way.
We reflect the communities we serve and foster a workplace where every employee feels welcomed, valued and engaged. Join our team of energy experts and help shape the future of power.
Storm Duty Requirements
Tampa Electric and its sister companies serve a role in providing critical services to our community during an emergency. Team members are required to participate in the response/recovery activities related to emergencies/disasters to maintain service to our Tampa Electric customers. Team members are required to work in their normal job duties or other assigned activities. Proper compensation will be made in accordance with the company's rules and procedures.
Responding to storms will be considered a condition of employment.
Tampa Electric is proud to be an Equal Opportunity Employer. To learn more, please click on link below:
Disclosure Statements
Title: IAM Security Engineer
Company: Tampa Electric Company
Location: Bearss Operations Center
State and City: Florida - LUTZ
Shift: 8 Hr. X 5 Days
TITLE: IAM Security Technologist Progression
PERFORMANCE COACH: Manager/Sr. Manager Cyber Protection
COMPANY: Tampa Electric Company
DEPARTMENT: Technology
Note that this position can be hired at any level within the job family progression based in Education and years of Experience.
FOCUS AREAS:
- Strong hands-on Saviynt IGA experience, including identity lifecycle management, access reviews, application onboarding and integrations
- CyberArk PAM experience
- Microsoft Entra ID / Active Directory, RBAC and access governance
- IAM integrations, connectors, APIs, scripting and automation
- Ability to work strategically while also being hands-on and extend support for implementations and activities outside the standard MSS scope
IAM Security Technologist Associate
POSITION CONCEPT
The IAM Security Technologist Associate is responsible for supporting the company’s information security systems, ensuring that all procedures are followed on a daily, weekly, and monthly basis. Supports all systems used to secure the enterprise information technology assets, the scope includes all network infrastructure, operating systems, and web server platforms throughout TECO Energy and its subsidiaries. Assists with the development and enhancing of IAM systems including SSO, authentication, and access controls ensuring confidentiality, integrity, and availability of IAM systems and data. Provides IAM Security support for the TECO environment primarily focusing IT corporate applications and OT/NERC applications. Responsible for adhering to established policies, following best practices, developing and possessing a solid understanding of exploits and vulnerabilities, resolving issues by following the appropriate escalation procedures. Supports the enforcement of corporate, regulatory, and risk management policies and assists in developing, maintaining, and publishing corporate IAM security standards, procedures, and guidelines for enterprise computing platforms. Position will be responsible for collaborating with multiple business units across multiple Emera affiliates.
PRIMARY DUTIES AND RESPONSIBILITIES
-
Assist in Developing and maintaining a roadmap for Identity and Access Management (IAM) including Governance and Administration (IGA), Privileged Access Management (PAM), authentication, SSO, directory services, and access governance. Collaborate closely with teams including Cyber Security, Human Resources, Technology, Architecture and Lines of Business (LoBs) to create efficient and user-friendly IAM solutions.
-
Assist in designing, implementing, and maintaining access governance processes, including Joiner/Mover/Leaver workflows, access requests, RBAC, access certifications/reviews, application onboarding, and least-privilege controls. Support enterprise IGA capabilities, including Saviynt, and integrations with business applications and directories.
-
Support Privileged Access Management (PAM) capabilities, including privileged account onboarding, credential management, access controls, and privileged access remediation with emphasis on platforms such as CyberArk.
-
Assist with the deployment, management and enhancement of SSO and authentication solutions, including integrations with enterprise applications, Microsoft Entra ID/Active Directory, and other identity platforms to provide secure and seamless authentication.
-
Assist with the implementation and management of authentication and access control mechanisms, including multi-factor authentication, conditional access, and identity security controls.
-
Assist with the monitoring, troubleshooting and response to identity and access-related incidents and technical issues. Support remediation of unauthorized access, excessive privileges, identity lifecycle failures, and other IAM control issues.
-
Effectively collaborate with both technical and non-technical business owners, application teams, implementation partners, and managed service providers. Identify opportunities to improve IAM automation, integrations, processes and toolsets, and provide hands-on technical support for activities outside standard managed service scope.
SUPERVISION
Direct Supervision: None
Indirect Supervision: None
RELATIONSHIPS
Key Internal: Engaging multiple technology groups and business units. Interactive engagement may require communication with individual contributors, and middle management.
Key External: Little to no key external relationships.
QUALIFICATIONS
Education
Required: Bachelor’s Degree in Computer Science, Information Systems or other technology-related field from an accredited college or university. An associate’s degree with an additional 2 years of required experience may be considered in lieu of a bachelor’s degree. A high school diploma and an additional 4 years of required experience may be considered in lieu of a bachelor’s degree.
Preferred: None.
Licenses/Certifications
Required: None
Preferred: CISSP, CISM, CIAM, ITIL, Sabiynt, CyberArk, Microsoft Identity/Entra, or other relevant IAM/security certifications
Experience
Required: At least one (1) year of experience in IAM or related security engineering experience.
Preferred: Two (2) or more years of experience in IAM or related security engineering experience
Knowledge/Skills/Abilities (KSA)
Required:
- Understanding of Identity and Access Management concepts, including RBAC, least privilege, entitlement management, and access controls.
- Knowledge of identity lifecycle management, including Joiner/Mover/Leaver processes, onboarding, offboarding, access changes, and automated provisioning/deprovisioning.
- Knowledge of Identity Governance and Administration capabilities, including access requests, certifications/access reviews, role management, application onboarding, and governance processes.
- Understanding of Privileged Access Management concepts, including privileged account onboarding, credential management, access controls, and privileged access governance.
- Experience or working knowledge of enterprise IAM technologies such as Saviynt, CyberArk, Microsoft Entra ID, Active Directory, SSO, and MFA.
- Understanding of connectors, REST APIs, scripts, and automation used to integrate IAM platforms with applications, directories, HR systems, and other enterprise technologies.
- Ability to troubleshoot identity, authentication, provisioning, access, and integration-related issues.
- Knowledge of designing and implementing IAM solutions aligned with business requirements, security standards, and enterprise architecture.
- Understanding of access reviews, segregation of duties, excessive access, privileged access, and least-privilege principles.
- Ability to analyze IAM security issues and support remediation of access-related risks and control deficiencies.
- Working knowledge of security and regulatory requirements including NERC CIP, SOX, NIST, and other applicable security frameworks.
- Ability to collaborate effectively with application owners, business teams, Cyber Security, Infrastructure, Architecture, Compliance, implementation partners, and managed service providers.
Preferred:
- None
IAM Security Technologist
POSITION CONCEPT
The IAM Security Technologist is responsible for operating the company’s information security systems, ensuring that all procedures are followed on a daily, weekly, and monthly basis. Provides support, within a team environment, for all systems used to secure the enterprise information technology assets, the scope includes all network infrastructure, operating systems, and web server platforms throughout TECO Energy and its subsidiaries. Direct assistance with the development and enhancing of IAM systems including SSO, authentication, and access controls ensuring confidentiality, integrity, and availability of IAM systems and data. Provides IAM Security support for the TECO environment primarily focusing on IT corporate applications and OT/NERC applications. Responsible for adhering to established policies, following best practices, developing, and possessing an in-depth understanding of exploits and vulnerabilities, resolving issues by taking the appropriate corrective action, or following the appropriate escalation procedures. Supports the enforcement of corporate, regulatory, and risk management policies and assists in developing, maintaining, and publishing corporate IAM security standards, procedures, and guidelines for enterprise computing platforms. Position will be responsible for collaborating with multiple business units across Emera affiliates.
PRIMARY DUTIES AND RESPONSIBILITIES
-
Support the development and maintenance of a strategic roadmap for Identity and Access Management (IAM) including Governance and Administration (IGA), Privileged Access Management (PAM), authentication, SSO, directory services, and access governance. Collaborate closely with teams including Cyber Security, Human Resources, Technology, Architecture and Lines of Business (LoBs) to create efficient and user-friendly IAM solutions.
-
Support the design, implementation and maintenance of access governance processes, including Joiner/Mover/Leaver workflows, access requests, RBAC, access certifications/reviews, application onboarding, and least-privilege controls. Support enterprise IGA capabilities, including Saviynt, and integrations with business applications and directories.
-
Support Privileged Access Management (PAM) capabilities, including privileged account onboarding, credential management, access controls, and privileged access remediation with emphasis on platforms such as CyberArk.
-
Deploy, manage, and enhance SSO and authentication solutions, including integrations with enterprise applications, Microsoft Entra ID/Active Directory, and other identity platforms to provide secure and seamless authentication.
-
Support the implementation and management of authentication and access control mechanisms, including multi-factor authentication, conditional access, and identity security controls.
-
Monitor, troubleshoot, and respond to identity and access-related incidents and technical issues. Support remediation of unauthorized access, excessive privileges, identity lifecycle failures, and other IAM control issues.
-
Effectively collaborate with both technical and non-technical business owners, application teams, implementation partners, and managed service providers. Identify opportunities to improve IAM automation, integrations, processes and toolsets, and provide hands-on technical support for activities outside standard managed service scope.
SUPERVISION
Direct Supervision: None
Indirect Supervision: May provide guidance and mentorship to associate-level technologists, contractors or co-ops assigned to the team.
RELATIONSHIPS
Key Internal: Engaging multiple technology groups and business units, including Finance and HR. Interactive engagement will require communication with individual contributors, middle management.
Key External: Engaging external contacts including vendors, contractors, regulatory agencies, industry associations, and other utility partners.
QUALIFICATIONS
Education
Required: Bachelor’s Degree in Computer Science, Information Systems or other technology-related field from an accredited college or university. An associate’s degree with an additional 2 years of required experience may be considered in lieu of a bachelor’s degree. A high school diploma and an additional 4 years of required experience may be considered in lieu of a bachelor’s degree.
Preferred: Master’s Degree in Computer Science, Information Systems, or other technology-related field from an accredited college or university.
Licenses/Certifications
Required: Will require at least one certification in one of the following: CISSP, CISM, CIAM, ITIL, Sabiynt, CyberArk, Microsoft Identity/Entra, or other relevant IAM/security certifications
Preferred: None
Experience
Required: 3 years of experience in IAM or related security engineering experience
Preferred: 4 or more years of experience in IAM or related security engineering experience.
Knowledge/Skills/Abilities (KSA)
Required:
- Understanding and demonstration of Identity and Access Management concepts, including RBAC, least privilege, entitlement management, and access controls.
- Knowledge of identity lifecycle management, including Joiner/Mover/Leaver processes, onboarding, offboarding, access changes, and automated provisioning/deprovisioning.
- Knowledge of Identity Governance and Administration capabilities, including access requests, certifications/access reviews, role management, application onboarding, and governance processes.
- Understanding of Privileged Access Management concepts, including privileged account onboarding, credential management, access controls, and privileged access governance.
- Experience or working knowledge of enterprise IAM technologies such as Saviynt, CyberArk, Microsoft Entra ID, Active Directory, SSO, and MFA.
- Understanding of connectors, REST APIs, scripts, and automation used to integrate IAM platforms with applications, directories, HR systems, and other enterprise technologies.
- Demonstrated ability to troubleshoot identity, authentication, provisioning, access, and integration-related issues.
- Knowledge of designing and implementing IAM solutions aligned with business requirements, security standards, and enterprise architecture.
- Understanding of access reviews, segregation of duties, excessive access, privileged access, and least-privilege principles.
- Ability to analyze IAM security issues and support remediation of access-related risks and control deficiencies.
- Working knowledge of security and regulatory requirements including NERC CIP, SOX, NIST, and other applicable security frameworks.
- Ability to collaborate effectively with application owners, business teams, Cyber Security, Infrastructure, Architecture, Compliance, implementation partners, and managed service providers.
Preferred:
- Knowledge of Saviynt IGA, including application onboarding, access requests, certifications, lifecycle workflows, and integrations.
- Experience with CyberArk PAM administration, privileged account onboarding, and credential management.
- Experience with Microsoft Entra ID and Active Directory, including authentication, SSO, MFA, and access management.
- Experience with REST APIs, PowerShell, connectors, or other IAM automation technologies.
- Experience supporting IAM solutions in a regulated enterprise or utility environment.
- Ability to work hands-on, supporting IAM implementations, operational improvements, and activities beyond standard managed service scope.
IAM Security Technologist Sr.
POSITION CONCEPT:
The IAM Security Technologist Sr is responsible for operating the company’s information security systems, ensuring that all procedures are followed on a daily, weekly, and monthly basis. Provides expert level support, within a team environment, for all systems used to secure the enterprise information technology assets, the scope includes all network infrastructure, operating systems, and web server platforms throughout TECO Energy and its subsidiaries. Direct assistance with the development and enhancing of IAM systems including SSO, authentication, and access controls ensuring confidentiality, integrity, and availability of IAM systems and data. Provides IAM Security support for the TECO environment primarily focusing on IT corporate applications and OT/NERC applications. Responsible for adhering to established policies, following best practices, developing, and possessing an in-depth understanding of exploits and vulnerabilities, resolving issues by taking the appropriate corrective action, or following the appropriate escalation procedures. Supports the enforcement of corporate, regulatory, and risk management policies and assists in developing, maintaining, and publishing corporate IAM security standards, procedures, and guidelines for enterprise computing platforms. Position will be responsible for collaborating with multiple business units across all Emera affiliates.
PRIMARY DUTIES AND RESPONSIBILITIES
-
Oversight of the development and implementation of a strategic roadmap for Identity and Access Management (IAM) including Governance and Administration (IGA), Privileged Access Management (PAM), authentication, SSO, directory services, and access governance. Collaborate closely with teams including Cyber Security, Human Resources, Technology, Architecture and Lines of Business (LoBs) to create efficient and user-friendly IAM solutions.
-
Leading efforts in designing, implementing, and maintaining access governance processes, including Joiner/Mover/Leaver workflows, access requests, RBAC, access certifications/reviews, application onboarding, and least-privilege controls. Support enterprise IGA capabilities, including Saviynt, and integrations with business applications and directories.
-
Leading Privileged Access Management (PAM) capabilities, including privileged account onboarding, credential management, access controls, and privileged access remediation with emphasis on platforms such as CyberArk.
-
Deploy, manage, and enhance SSO and authentication solutions, including integrations with enterprise applications, Microsoft Entra ID/Active Directory, and other identity platforms to provide secure and seamless authentication.
-
Lead and support the implementation and management of authentication and access control mechanisms, including multi-factor authentication, conditional access, and identity security controls.
-
Monitor, troubleshoot, and respond to identity and access-related incidents and technical issues. Support remediation of unauthorized access, excessive privileges, identity lifecycle failures, and other IAM control issues.
-
Effectively collaborate with both technical and non-technical business owners, application teams, implementation partners, and managed service providers. Identify opportunities to improve IAM automation, integrations, processes and toolsets, and provide hands-on technical support for activities outside standard managed service scope.
-
Serve as the Subject Matter Expert (SME) for audit, compliance, and regulatory efforts related to IAM, SOX and PII through investigating, documenting, and reporting findings to management.
SUPERVISION
Direct Supervision: None
Indirect Supervision: May provide guidance and mentorship to associate-level technologists and security technologists, contractors or co-ops assigned to the team.
RELATIONSHIPS
Key Internal: Engaging multiple I.T. groups and business units, including Finance and HR. Interactive engagement will require communication with individual contributors, middle management.
Key External: Engaging external contacts including vendors, contractors, regulatory agencies, industry associations, and other utility partners.
QUALIFICATIONS
Education
Required: Bachelor’s Degree in Computer Science, Information Systems or other technology-related field from an accredited college or university. An associate’s degree with an additional 2 years of required experience may be considered in lieu of a bachelor’s degree. A high school diploma and an additional 4 years of required experience may be considered in lieu of a bachelor’s degree.
Preferred: Master’s Degree in Computer Science, Information Systems or other technology-related field from an accredited college or university.
Licenses/Certifications
Required: One or more of the following: CISSP, CISM, CIAM, ITIL, Sabiynt, CyberArk, Microsoft Identity/Entra, or other relevant IAM/security certifications
Preferred: Two or more of the above required certifications.
Experience
Required: 5 years of experience in IAM or related security engineering experience
Preferred: 6 or more years of experience in IAM or related security engineering experience.
Knowledge/Skills/Abilities (KSA)
- Advanced knowledge and deployment of Identity and Access Management concepts, including RBAC, least privilege, entitlement management, and access controls.
- Advanced knowledge of identity lifecycle management, including Joiner/Mover/Leaver processes, onboarding, offboarding, access changes, and automated provisioning/deprovisioning.
- Advanced knowledge of Identity Governance and Administration capabilities, including access requests, certifications/access reviews, role management, application onboarding, and governance processes.
- Understanding of Privileged Access Management concepts, including privileged account onboarding, credential management, access controls, and privileged access governance.
- Advanced knowledge of enterprise IAM technologies such as Saviynt, CyberArk, Microsoft Entra ID, Active Directory, SSO, and MFA.
- In-depth knowledge of connectors, REST APIs, scripts, and automation used to integrate IAM platforms with applications, directories, HR systems, and other enterprise technologies.
- Demonstrated ability to troubleshoot identity, authentication, provisioning, access, and integration-related issues.
- Demonstrated knowledge, design, and implementation of IAM solutions
See all 262+ STEM OPT Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT Security Engineer Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization as a Security Engineer
Verify your CIP code matches the role
Check that your degree's CIP code aligns with the Security Engineer position before applying. O*NET lists the typical education requirements for this occupation, which you can cross-reference against your I-20 to confirm STEM OPT eligibility.
Confirm E-Verify enrollment before accepting offers
Ask recruiters directly whether the company is enrolled in E-Verify before you reach the offer stage. Many smaller security firms or government contractors operate under subcontracting arrangements where the legal employer, not the worksite, must hold the E-Verify enrollment.
Target companies with active LCA filings in cybersecurity
Search Migrate Mate to find employers with verified E-Verify enrollment and LCA filing history for security roles. This filters out companies that verbally claim sponsorship readiness but lack a track record of filing for STEM OPT or H-1B visa workers.
Build your I-983 training plan around security competencies
Work with your DSO and hiring manager to map your Security Engineer duties to concrete STEM learning objectives on Form I-983. USCIS scrutinizes training plans that list generic IT tasks rather than specific security engineering skills tied to your degree field.
Apply 90 days before your OPT end date
Submit your STEM OPT extension application to USCIS no later than 90 days before your current EAD expires. Filing inside that window lets you keep working without a gap even if USCIS processing extends past your end date.
Check prevailing wage before negotiating your offer
Look up the wage level for your Security Engineer role using the OFLC Wage Search before finalizing compensation. Your employer's LCA must certify a wage at or above the applicable prevailing wage, so knowing the floor protects you from offers that would block the filing.
Frequently Asked Questions
Does a computer science or information technology degree qualify for STEM OPT as a Security Engineer?
Yes, degrees in computer science, computer engineering, information security, and closely related STEM fields typically qualify, provided the CIP code on your I-20 maps to the STEM Designated Degree Program List. Your DSO can confirm whether your specific degree program is listed. If your degree is in a borderline field like management information systems, verify the CIP code before applying for the extension.
What E-Verify requirement applies to my Security Engineer employer during STEM OPT?
Your employer must be enrolled in E-Verify at the worksite where you perform your job duties, not just at their headquarters. If you're placed at a client site through a staffing arrangement, E-Verify enrollment must apply to the legal employer named on your I-983, not the client company. Verify enrollment status directly with HR before signing any offer.
What should the I-983 training plan include for a Security Engineer role?
Your I-983 must connect your day-to-day security engineering duties to specific STEM learning goals tied to your degree field. List concrete objectives such as threat modeling, vulnerability assessment, or security architecture design rather than broad IT support tasks. USCIS has rejected training plans that read as standard job descriptions without an educational rationale linking the work to your degree program.
How does cap-gap protection apply if my employer files an H-1B petition while I'm on STEM OPT?
If your STEM OPT EAD expires while an H-1B petition filed on your behalf is pending or approved for October 1, cap-gap automatically extends your work authorization through September 30. You don't need a new EAD for this period. Keep your current EAD, your employer's H-1B receipt notice, and your OPT approval as documentation of your continued authorization during the cap-gap window.
Where can I find Security Engineer jobs where employers are already set up for STEM OPT?
Migrate Mate filters Security Engineer listings by employers with verified E-Verify enrollment and LCA filing history, so you can focus on companies that have already navigated the STEM OPT process. This saves time compared to filtering manually after submitting applications, especially important when your OPT timeline limits how long you can afford to spend in a drawn-out hiring process.