STEM OPT Security Researcher Jobs
Security Researcher roles in vulnerability research, threat intelligence, and penetration testing qualify for STEM OPT's 24-month extension when your degree is in computer science, cybersecurity, or a related STEM field. Your employer must be enrolled in E-Verify, and you'll need a signed I-983 training plan before your start date.
Find STEM OPT Security Researcher JobsOverview
Showing 5 of 13+ Security Researcher jobs










See all Security Researcher Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Security Researcher roles.
Get Access To All Jobs
INTRODUCTION
At the University of California, Berkeley, we are dedicated to fostering a community where everyone feels welcome and can thrive. Our culture of openness, freedom, and belonging makes it a special place for students, faculty, and staff, who are among the most talented and accomplished anywhere, including Nobel laureates, Pulitzer Prize winners, and MacArthur Fellows. Since our founding in 1868, we have been an engine for innovation - driving intellectual, economic, and social progress that benefits California, the U.S., and beyond. Together, we change the world.
At Berkeley, the best careers are built on a foundation of continuous learning and growth. We actively support professional development by providing all full-time staff employees with at least 80 hours of paid time per year and provide space for supportive colleague communities via numerous employee resource groups.
We invite applicants who are inspired by our Principles of Community and who are eager to be part of our exciting Strategic Plan, which charts Berkeley's next era of excellence.
DEPARTMENTAL OVERVIEW
The Office of Research Administration & Compliance (RAC) works with faculty, staff, and students across UC Berkeley to catalyze, support, and safeguard research and innovation. Ensuring research compliance, safety, and security across the university is a key priority because the overall success of the research enterprise depends on the highest standards of ethics, compliance, and integrity.
Position Summary
The Research Security Cybersecurity Specialist is a newly created role within the Research Security program that supports UC Berkeley's compliance with federal cybersecurity and data security requirements applicable to sponsored research. Reporting to the Executive Director of Research Security, this position serves as the research security team's subject matter expert on cybersecurity standards, frameworks, and data protection regulations ensuring that principal investigators' research computing environments meet the cybersecurity requirements of their federal awards.
This is a research security compliance function, not an operational IT security engineering role. The Research Security Cybersecurity Specialist evaluates diverse research computing environments to determine whether centralized services, departmental IT, or other situations meet applicable federal standards, and guides researchers toward compliance through clear, patient, expert consultation. This role implements the cybersecurity components of UC Berkeley's NSPM-33 Research Security Program and plays a central part in building the compliance processes, procedures, and workflows that the campus will rely on as federal research cybersecurity requirements continue to evolve.
APPLICATION REVIEW DATE
The First Review Date for this job is: September 9, 2026. For full consideration, please apply on or before the first review date.
Responsibilities
-
Assesses the cybersecurity posture of individual research labs and PI computing environments, including centralized, departmental, and self-managed/bespoke setups against applicable federal standards (NIST 800-171, NIST 800-53, CMMC, FISMA, and evolving NSPM-33 requirements). Conducts gap analyses, identifies areas of potential non-compliance, and collaborates with PIs and IT service providers to develop clear, actionable remediation plans.
-
Provides expert guidance on data security requirements associated with federally sponsored research, including HIPAA, FERPA, and controlled technical information requirements. Advises on data storage, handling, and protection requirements in coordination with the export control team when Technology Control Plans or export-controlled data are involved. Develops and implements standard operating procedures and controls for data security compliance across diverse research contexts.
-
Helps build the compliance processes, procedures, and workflows needed to support research cybersecurity compliance as federal requirements continue to evolve. Monitors regulatory developments across federal agencies (NSF, DoD, DOE, NIH, and others) and assesses their implications for sponsored research. Contributes to the development of System Security Plans, compliance documentation, and certification processes.
-
Collaborates with campus IT organizations, including the Information Security Office, Research IT, and departmental IT groups to coordinate on compliance-related technical questions. Works within a complex, highly decentralized IT landscape with diplomacy and collaborative skill. Coordinates with relevant campus units during cybersecurity incident response efforts to assess compliance implications and ensure affected research environments are brought back into alignment with federal requirements. Functions as an independent compliance assessor of research computing environments while navigating a multi-stakeholder environment with professionalism and tact. May interface with federal sponsors regarding cybersecurity compliance inquiries or audit support.
-
Develops and delivers targeted training and educational materials on cybersecurity compliance requirements for PIs, research staff, and graduate students. Creates accessible resources (guides, FAQs, checklists, web-based materials) and provides one-on-one consultation to help researchers understand and meet cybersecurity obligations associated with their federally sponsored projects.
REQUIRED QUALIFICATIONS
-
Strong working knowledge of NIST cybersecurity frameworks, particularly NIST 800-171 and NIST 800-53, with the ability to interpret, apply, and assess compliance against these standards.
-
Ability to rapidly learn and apply new and evolving regulatory frameworks, federal requirements, and cybersecurity standards (e.g., CMMC, DFARS 252.204-7012, FISMA, NSPM-33, NIST 800-172, and agency-specific research security requirements).
-
Exceptional written and verbal communication skills with a demonstrated ability to explain complex technical cybersecurity concepts clearly and patiently to non-technical audiences, including faculty, graduate students, and administrative staff.
-
Strong interpersonal and consultative skills with the ability to build trust and credibility with researchers, guide them through compliance processes with patience and clarity, and maintain productive relationships even when delivering difficult or unwelcome requirements.
-
Ability to work collaboratively within a complex, multi-stakeholder environment, navigating a decentralized organizational landscape with diplomacy and professionalism.
-
Demonstrated ability to work independently with minimal technical supervision, exercise sound judgement, and manage a dynamic workload including urgent, time-sensitive requests alongside longer-term compliance projects.
-
General familiarity with data security regulations (e.g., HIPAA, FERPA, controlled technical information) and the ability to quickly understand and advise on data protection requirements.
-
Sufficient technical depth to credibly evaluate real-world computing environments and earn the trust of both researchers and campus IT professionals.
PREFERRED QUALIFICATIONS
-
5 or more years of professional cybersecurity experience.
-
Experience in higher education, research institutions, government, or defense contracting environments.
EDUCATION / TRAINING
Bachelor's degree in cybersecurity, information technology, computer science, information systems, or a related field, and/or equivalent experience and training.
A minimum of 3 years of full-time professional experience in cybersecurity, information security, or IT security, including experience with compliance, auditing, or assessment against established frameworks.
LICENSES / CERTIFICATIONS
Relevant professional certifications (e.g., CISSP, CISM, CISA, CompTIA Security+, CMMC RP/CP) (Preferred).
SALARY & BENEFITS
For information on the comprehensive benefits package offered by the University, please visit the University of California's Compensation & Benefits website.
Under California law, the University of California, Berkeley is required to provide a reasonable estimate of the compensation range for this role and should not offer a salary outside of the range posted in this job announcement. This range takes into account the wide range of factors that are considered in making compensation decisions, including but not limited to experience, skills, knowledge, abilities, education, licensure and certifications, analysis of internal equity, and other business and organizational needs. It is not typical for an individual to be offered a salary at or near the top of the range for a position. Salary offers are determined based on final candidate qualifications and experience.
The budgeted annual range that the University reasonably expects to pay for this position is $112,400 to $163,200.
This is an exempt, monthly-paid position.
This is a full-time (40 hours/week) Career position eligible for UC benefits.
See all STEM OPT Security Researcher Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT Security Researcher Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization in Security Researcher
Verify your CIP code before applying
Check that your degree's Classification of Instructional Programs code maps to an approved STEM field on the ICE STEM-designated degree list. Cybersecurity, computer science, and information assurance CIP codes all qualify, but "general IT" programs sometimes don't.
Confirm E-Verify status before accepting offers
Ask HR directly whether the company is enrolled in E-Verify before you sign anything. Federal contractors are required to participate, but many private-sector security research teams aren't. USCIS won't approve your STEM OPT extension if the employer isn't enrolled at the time of filing.
Build a training plan tied to security research skills
Your I-983 must list concrete learning objectives: reverse engineering, malware analysis, or CVE research are defensible. Vague goals like "gain professional experience" get flagged during DSO review. Align each objective to a deliverable your manager can assess at the 12-month evaluation.
Target employers with cleared research programs
Many Security Researcher roles sit inside cleared facilities or support cleared programs, which can complicate STEM OPT timing. Identify employers that sponsor both the work authorization and any required clearance pathway upfront, since clearance processing rarely aligns with OPT deadlines.
Search Migrate Mate for verified STEM OPT employers
Filter your Security Researcher job search on Migrate Mate to surface employers already verified for STEM OPT hiring. Seeing a company's prior authorization history tells you whether their HR team knows the I-983 and E-Verify process before you spend time on applications.
File your extension at least 90 days before OPT ends
Your DSO must recommend the STEM OPT extension in SEVIS, and USCIS recommends submitting your I-765 at least 90 days before your current EAD expires. If the application is pending on your end date, the cap-gap provision keeps you authorized while USCIS adjudicates.
Frequently Asked Questions
Does my degree qualify me for the STEM OPT extension as a Security Researcher?
Your degree qualifies if its CIP code appears on the ICE STEM-designated degree list. Degrees in computer science, cybersecurity, information assurance, electrical engineering, and mathematics all typically qualify. If your degree is in a field like criminal justice with a cybersecurity concentration, check the CIP code with your DSO before assuming eligibility, since the listed field of study controls, not the job title.
What does the I-983 training plan need to include for a Security Researcher role?
The I-983 must connect your day-to-day Security Researcher work to the STEM field of your degree. List specific learning goals such as vulnerability assessment methodology, exploit development, or threat modeling. Your supervisor signs off on evaluations at 12 months and again at the end of the extension. Generic descriptions won't satisfy DSO review, so tie each objective to a measurable outcome.
How do I confirm my employer is enrolled in E-Verify?
Ask the recruiter or HR contact directly whether the company is an E-Verify participant. You can also search the E-Verify employer search tool on the E-Verify website to look up participating employers by name. Enrollment must be active before your STEM OPT extension is approved, and your I-983 must name the employer's E-Verify company identification number.
Where can I find Security Researcher jobs where employers already understand STEM OPT?
Migrate Mate lists Security Researcher openings filtered for employers who are familiar with STEM OPT authorization and E-Verify enrollment. Searching there lets you focus on roles where the hiring process is already set up for F-1 candidates, rather than educating employers about the extension requirements from scratch.
What happens to my work authorization if my H-1B is selected in the lottery before my STEM OPT ends?
If your H-1B visa petition is filed while your STEM OPT EAD is valid and your status remains in F-1, the cap-gap provision extends your work authorization automatically through September 30 of the fiscal year the H-1B takes effect. You can continue working as a Security Researcher during the gap without a new EAD, as long as your employer filed before your OPT expired.