STEM OPT Security Software Engineer Jobs
Security Software Engineer roles qualify for the 24-month STEM OPT extension if your degree falls under an eligible CIP code in computer science, cybersecurity, or a related engineering field. Employers must be enrolled in E-Verify, and you'll need a signed I-983 training plan before your extension starts.
Find STEM OPT Security Software Engineer JobsOverview
Showing 5 of 11+ Security Software Engineer jobs










See all Security Software Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Security Software Engineer roles.
Get Access To All Jobs
Hybrid Work:
- 3-4 days per week
We are seeking an application/software engineer with a strong security focus to evaluate, prioritize, and remediate vulnerabilities and compliance findings across custom applications and infrastructure as code (IaC). The engineer will work primarily in VB.NET, SQL, and Python, with IaC authored using AWS Cloud Development Kit (CDK), and operate within AWS GovCloud. Core responsibilities include addressing Known Exploited Vulnerabilities (KEVs), CVE driven issues, internal assessment items, and Security Assessment & Authorization (SA&A) findings to meet regulatory and organizational requirements. This role sits at the intersection of secure application development, cloud security engineering, and risk/compliance, driving both code level fixes and cloud configuration hardening to maintain a strong security posture.
Primary Responsibilities:
- Conduct security assessments using scanning tools and implement recommended remediations
- Evaluate and remediate Known Exploited Vulnerabilities (KEVs) and Common Vulnerabilities and Exposures (CVEs) in custom applications and infrastructure
- Support Security Assessment and Authorization (SA&A) processes, including documentation and evidence collection
- Analyze Software Bill of Materials (SBOM) findings to identify vulnerable dependencies and recommend updates or alternatives
- Review and remediate security vulnerabilities in custom VB.NET, SQL, and Python code
- Perform security analysis and hardening of AWS Cloud Development Kit (CDK) infrastructure as code
- Collaborate with development teams to implement secure coding practices and address identified vulnerabilities
- Maintain security documentation and track remediation efforts through completion
- Ensure compliance with federal security standards and frameworks (NIST, FISMA, FedRAMP, etc.) within AWS GovCloud environment
- Participate in security scanning automation and continuous monitoring initiatives
Required Qualifications:
- Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or related field; or equivalent work experience
- Minimum 3-5 years of experience in application security or software development with security focus
- Proven experience with vulnerability assessment and remediation methodologies
- Working proficiency with Python, SQL, and VB.NET or legacy .NET frameworks
- Experience with AWS Cloud Development Kit (CDK) or similar IaC tools (Terraform, CloudFormation)
- Hands-on experience working in AWS environments, preferably AWS GovCloud
- Experience with AWS security services (GuardDuty, Security Hub, Inspector, Config)
- Understanding of CVE/KEV identification and remediation processes
- Knowledge of SBOM generation and analysis
- Experience with static application security testing (SAST), dynamic application security testing (DAST) and penetration testing
- Strong analytical and problem-solving skills
- Excellent written and verbal communication skills
Preferred Qualifications:
- Professional security certifications (CISSP, CEH, GIAC GSEC, AWS Security Specialty, or equivalent)
- Knowledge of container security (Docker, ECS, EKS)
- Experience with CI/CD pipeline security integration (Jenkins, GitLab CI, AWS CodePipeline)
- Familiarity with DevSecOps practices and tooling
- Knowledge of secure software development lifecycle (SSDLC) practices
- Understanding of zero trust architecture principles
- Background in both application development and security operations
See all STEM OPT Security Software Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT Security Software Engineer Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization as a Security Software Engineer
Verify your CIP code before applying
Check that your degree's CIP code appears on the DHS STEM Designated Degree Program List. Cybersecurity and computer science programs typically qualify, but information systems degrees sometimes don't, so confirm with your DSO before accepting an offer.
Filter employers by E-Verify enrollment status
Before sending applications, confirm each employer is enrolled in E-Verify using the E-Verify employer search. Security software roles often appear at defense contractors and regulated financial firms, which are enrolled by compliance requirements, making them reliable targets.
Align your I-983 training plan to the role
Work with your hiring manager to map the Security Software Engineer job duties to specific learning objectives in the I-983. USCIS requires a demonstrable connection between your degree field and the role's technical scope, so vague job descriptions create extension risk.
Target employers with cleared or regulated environments
Use Migrate Mate to find Security Software Engineer openings filtered for STEM OPT-eligible employers. Defense, fintech, and healthcare IT employers often have structured onboarding for work-authorization candidates and existing E-Verify infrastructure already in place.
Address security clearance timing during offer negotiation
Many Security Software Engineer roles list clearance eligibility as preferred rather than required at hire. Clarify during the offer stage whether the role requires an active clearance on day one, since sponsoring your STEM OPT extension and initiating a clearance process run in parallel.
Submit your STEM OPT extension application 90 days early
File your STEM OPT extension application with USCIS up to 90 days before your initial OPT expires. If your I-765 is pending on your OPT end date, your cap-gap protection keeps your work authorization continuous while USCIS adjudicates the extension.
Frequently Asked Questions
Does a cybersecurity degree qualify for the STEM OPT extension for Security Software Engineer roles?
Cybersecurity degrees typically qualify if the program's CIP code appears on the DHS STEM Designated Degree Program List. Common qualifying codes include 11.1003 (Computer and Information Systems Security) and related computer engineering fields. Confirm your specific CIP code with your DSO before filing, since the degree program determines eligibility, not the job title itself.
What E-Verify requirement applies to employers hiring Security Software Engineer STEM OPT students?
Any employer hiring you on a STEM OPT extension must be enrolled in E-Verify at the worksite level where you'll work, not just at the company's headquarters. You can verify enrollment through the E-Verify employer search before accepting an offer. Without active E-Verify enrollment, the employer cannot legally employ you on the 24-month extension.
How should the I-983 training plan reflect Security Software Engineer job duties?
The I-983 must connect your specific engineering or computer science degree to the role's technical responsibilities. For Security Software Engineer positions, this means documenting learning objectives around secure code development, vulnerability assessment, or systems architecture that directly relate to your degree field. USCIS reviews this connection during adjudication, so generic job descriptions weaken the filing.
How does cap-gap protection work if my initial OPT expires while my STEM OPT extension is pending?
If you file your STEM OPT extension application before your initial OPT EAD expires, cap-gap protection automatically extends your work authorization while USCIS processes the I-765. You can continue working as a Security Software Engineer during this period without interruption. Carry both your expired EAD and your I-20 with the STEM OPT extension recommendation as proof of authorized status.
Where can I find Security Software Engineer jobs from employers already set up to hire STEM OPT students?
Migrate Mate lists Security Software Engineer roles filtered for employers with E-Verify enrollment and a history of hiring F-1 students on OPT. Searching there saves you from applying to companies that will stall or withdraw offers once they learn the E-Verify and I-983 requirements apply. You can also cross-reference the O*NET occupation profile to identify which degree fields align with the role's defined skill set.