STEM OPT SOC Analyst Jobs
SOC Analyst roles in cybersecurity qualify for STEM OPT because they map to CIP codes in computer science and information technology. Your STEM degree gives you up to 24 months of extended work authorization beyond initial OPT, but every employer must be enrolled in E-Verify before your extension is approved.
Find STEM OPT SOC Analyst JobsOverview
Showing 5 of 63+ SOC Analyst jobs










See all 63+ SOC Analyst Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new SOC Analyst roles.
Get Access To All Jobs
COMPANY OVERVIEW
HealthStream is the leader in healthcare workforce solutions. We help organizations work better by helping their people work smarter.
HealthStream provides the leading learning, clinical development, credentialing, and scheduling applications delivered on healthcare’s #1 platform. We streamline everyday tasks while improving performance, engagement, and safety – fostering a workplace where people flourish, and care thrives.
WHY JOIN US
At HealthStream, you’ll have the opportunity to make a meaningful impact on the future of healthcare by collaborating with a team of talented professionals dedicated to innovation and excellence. We offer competitive compensation, comprehensive benefits, and a supportive work environment where creativity and collaboration thrive.
Our shared vision is to enhance the quality of healthcare by empowering the people who deliver care – a commitment we have upheld for over 30 years through providing innovative solutions and driving constant growth. Join us in revolutionizing the healthcare industry and shaping the future of patient care. As a HealthStreamer, you will be at the forefront of healthcare technology innovation, making a recurring impact on the industry.
We’re proud of our values-forward culture that offers our people:
- Mission-oriented work
- Diverse and inclusive culture
- Competitive Compensation & Bonuses
- Comprehensive Insurance Plans
- Mental and Physical Health Support
- Work-from-home flexibility
- Fitness Center Reimbursements
- Streaming Good time off for volunteering
- Wellness workshops
- Buddy Program for new HealthStreamers
- Collaborative work environment
- Career growth opportunities
- Continuous learning opportunities
- Inspiring workspaces to collaborate and connect with other HealthStreamers
- Free employee parking at our Resource Centers in Nashville and San Diego
At HealthStream, our thriving culture encourages collaboration and values contributions, allowing our team members to continuously solve big problems and grow. We offer flexibility and paid time off to support work-life integration for all employees, including a hybrid work environment and Streaming Good volunteer day. For team members in commutable distance, HealthStream has Resource Centers in Nashville, TN and San Diego, CA. Our resource centers provide an inspiring workspace to collaborate and recharge as well as company-sponsored onsite social events for development, connection, and celebration.
We are committed to driving innovation in healthcare and ensuring that patients receive competent care from qualified professionals. As a HealthStream team member, you will help bring this vision to life. If you want to work for a company committed to its values and vision, HealthStream is the place for you!
HealthStream is an equal opportunity employer. HealthStream prohibits employment practices that discriminate against individual employees or groups of employees on the basis of age, color, disability, national origin, race, religion, sex, sexual orientation, pregnancy, veteran or military status, genetic information or any other category deemed protected by state and/or federal law.
POSITION INFORMATION
POSITION OVERVIEW
The Application Security Analyst plays a hands-on role in supporting and executing the application security program at HealthStream. Working closely with and under the guidance of the Sr. Application Security Architect, this role focuses on identifying, assessing, and helping remediate security vulnerabilities across our software products and cloud environments. The Analyst will partner with Engineering, DevOps, and Product teams to embed security practices into the software development lifecycle (SDLC), operate security tooling, and contribute to a culture of security awareness. This is an excellent opportunity for a motivated security professional looking to grow within a collaborative, mission-driven healthcare technology organization.
KEY RESPONSIBILITIES
You will be responsible for adhering to all HealthStream security policies, procedures, and assigned training.
Application Security Testing & Vulnerability Management
- Operate and manage automated application security testing tools, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Interactive Application Security Testing (IAST).
- Triage, validate, and prioritize vulnerability findings from security scans, penetration tests, and bug reports, working with development teams to track remediation to closure.
- Conduct or support manual security assessments and penetration testing of web applications, APIs, and mobile applications.
- Produce clear, actionable vulnerability reports with risk ratings and remediation guidance for development teams.
- Manage and maintain vulnerability findings within the Snyk, Invicti and SonarQube or equivalent vulnerability management platform.
Secure Development Lifecycle (SDLC) Support
- Support the integration of security into CI/CD pipelines and DevSecOps workflows, including automated security gate checks.
- Participate in design and architecture reviews with a security lens, helping identify potential risks early in the development process.
- Assist in threat modeling exercises for new features and systems under the guidance of the AppSec Architect.
- Perform security-focused code reviews and provide developers with clear, constructive feedback and guidance.
- Contribute to the maintenance of a secure code library and reusable security patterns for development teams.
Security Tooling & Cloud Security
- Support the management and configuration of application security tools such as Synk, Invicti, SonarQube and DefectDojo.
- Assist in implementing and monitoring security controls for cloud-based environments, including AWS and Azure.
- Evaluate and test emerging security tools and contribute recommendations to the AppSec team.
- Support API security testing and assist in securing third-party and open-source integrations.
Security Awareness & Collaboration
- Collaborate with cross-functional teams including Engineering, DevOps, and Product to promote security best practices and a shift-left mindset.
- Deliver security awareness content and assist in conducting security training sessions for development staff.
- Stay current on emerging security threats, vulnerabilities (CVEs), and attack techniques, sharing relevant intelligence with the team.
- Assist in maintaining security documentation, standards, runbooks, and internal knowledge base articles.
- Support compliance-related activities, including evidence gathering for audits related to HIPAA, SOC 2, HITRUST or other applicable frameworks. FedRAMP experience is a plus.
- Other Duties as assigned.
REQUIREMENTS
- Bachelor’s degree in information security, Computer Science, Software Engineering, or a related field. Equivalent practical experience will be considered.
- 2 to 4 years of experience in application security, information security, or software development with a security focus.
- Working knowledge of the OWASP Top 10, common web application vulnerabilities, and secure coding principles.
- Hands-on experience with application security testing tools such as SAST, DAST, or IAST (e.g., Synk, Invicti, Checkmarx, SonarQube, Burp Suite, or similar).
- Familiarity with cloud security concepts and hands-on exposure to AWS or Azure environments.
- Understanding of CI/CD pipelines and experience integrating security checks into DevOps workflows.
- Experience with API security testing and a solid understanding of RESTful service security.
- Proficiency in at least one scripting or programming language such as Python, JavaScript, Java, or Go for automation and security tooling purposes.
- Strong analytical and problem-solving skills with attention to detail.
- Excellent written and verbal communication skills, with the ability to explain security concepts to both technical and non-technical audiences.
- Ability to manage multiple tasks and vulnerabilities simultaneously, prioritizing effectively in a fast-paced environment.
QUALIFICATIONS
- Relevant security certifications such as CompTIA Security+, CEH (Certified Ethical Hacker), GWAPT, eWPT, or equivalent.
- Experience using vulnerability management platforms such as Snyk, Invicti, or similar.
- Familiarity with security frameworks and standards including OWASP SAMM, NIST, or CIS Controls.
- Exposure to healthcare industry security and privacy regulations, including HIPAA.
- Experience with secure methods of integration with third-party platforms and open-source components.
- Participation in bug bounty programs, Capture the Flag (CTF) competitions, or open-source security research.
- Awareness of AI/ML security trends and their implications for application security.
- Experience with Identity and Access Management (IAM) security concepts and OAuth/OpenID Connect.
CORE COMPETENCIES
- Collaborative team player with the ability to work effectively across engineering and security teams.
- Proactive learner committed to continuously developing security knowledge and skills.
- Strong work ethic with a commitment to quality and thoroughness in all security activities.
- Solutions-oriented mindset identifies problems and drives them toward resolution.
- Adaptable and comfortable working in an evolving, high-growth technology environment.
COMPENSATION
- The salary range for this position is $78,628 - $85,000. Salary will be determined on the candidate’s level of experience and qualifications. Compensation will be commensurate with skills, relevant experience, and performance in similar roles.
BENEFITS
HealthStream offers a comprehensive benefits package to eligible employees, including:
- Medical, Dental and Vision insurance
- Paid Time Off
- Parental Leave
- 401k and Roth
- Flexible Spending Account
- Health Savings Account
- Life Insurance
- Short- and Long-Term Disability
- Medical Bridge Insurance
- Critical Illness Insurance
- Accident Insurance
- Identity Protection
- Legal Protection
- Pet Insurance
- Employee Assistance Program
- Fitness Reimbursement
Are you passionate about enhancing healthcare outcomes and empowering healthcare professionals? Join the HealthStream team and become a HealthStreamer! Together, we can make a difference in the world of healthcare.
RECRUITMENT FRAUD NOTICE: HealthStream is committed to protecting job seekers from recruitment fraud. All legitimate communications from HealthStream’s Talent Acquisition team will come from an official HealthStream email address. HealthStream will never ask candidates to pay fees, purchase equipment, provide banking information, or share sensitive personal information outside of our secure hiring and onboarding process. If you receive a suspicious message claiming to be from HealthStream, please proceed with caution and report it to the appropriate authorities.
Req #46890
See all 63+ STEM OPT SOC Analyst Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT SOC Analyst Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization as a SOC Analyst
Verify your CIP code maps correctly
Check that your degree's CIP code aligns with SOC Analyst roles before applying. Computer science, information assurance, and cybersecurity CIP codes are the most defensible matches. Your DSO confirms the mapping on your I-20 before recommending the STEM extension.
Filter employers by E-Verify enrollment status
Ask recruiting contacts directly whether their company is enrolled in E-Verify before you advance to offer negotiations. STEM OPT authorization is contingent on employer enrollment, and discovering a gap late in the process costs you time on your 12-month initial OPT clock.
Benchmark your offer against OFLC Wage Search data
Pull the prevailing wage for SOC Analyst roles in your target metro using the OFLC Wage Search before you receive an offer. The I-983 training plan must document compensation, so knowing the wage floor lets you flag underpaying positions before you're committed.
Use Migrate Mate to target verified STEM OPT employers
Search SOC Analyst openings on Migrate Mate, which filters for employers with confirmed E-Verify enrollment. This cuts the verification step you'd otherwise handle manually and focuses your applications on companies already set up to file your training plan.
Draft your I-983 training plan before your offer closes
Prepare a draft I-983 with your expected SOC Analyst duties, tools, and learning objectives so you can present it to your employer at the offer stage. Employers unfamiliar with STEM OPT move faster when you arrive with a near-complete form rather than a blank one.
Track your OPT end date against cap-gap eligibility
If your employer files an H-1B visa petition for you before your OPT expires, cap-gap protection extends your work authorization through September 30 of the fiscal year. Confirm with USCIS guidance that your SOC Analyst role qualifies as a specialty occupation before relying on cap-gap coverage.
Frequently Asked Questions
Does a SOC Analyst role qualify for the STEM OPT extension?
Yes, if your degree is in a qualifying STEM field such as computer science, information assurance, or cybersecurity. The CIP code on your I-20 must align with the SOC Analyst occupation code. Your DSO verifies this alignment before recommending the 24-month extension to USCIS, so confirm the match early rather than at the filing stage.
What E-Verify requirement applies to SOC Analyst employers hiring STEM OPT students?
Every employer that hires a STEM OPT student must be actively enrolled in E-Verify. Enrollment is a federal requirement, not a company preference, and your 24-month extension cannot be approved without it. Before accepting a SOC Analyst offer, ask the recruiter or HR contact to confirm E-Verify participation. Migrate Mate surfaces employers that already meet this requirement so you can focus applications there.
What does the I-983 training plan require for a SOC Analyst position?
The I-983 must document your specific SOC Analyst duties, the cybersecurity skills you'll develop, the tools and platforms involved, and how the role relates to your STEM degree. Both you and your employer sign it, and your DSO must also recommend approval. The plan is submitted to your school, not to USCIS, but it must be in place before your STEM extension begins.
Can I switch SOC Analyst employers during my STEM OPT period?
Yes, but the process restarts with each change. Your new employer must be enrolled in E-Verify, you and the new employer must complete a revised I-983, and your DSO must recommend the updated plan. You have up to 10 days between jobs without violating your status. Report the change through SEVIS within the required window to stay in compliance.
How does cap-gap protection work if my SOC Analyst employer files an H-1B petition?
If your employer files a timely H-1B cap-subject petition before your OPT EAD expires, cap-gap automatically extends your work authorization through September 30. The SOC Analyst role must qualify as a specialty occupation for the H-1B to be valid. USCIS issues a cap-gap extension on your I-20, which serves as the work authorization document during that bridging period.