STEM OPT Systems Security Engineer Jobs
Systems Security Engineer roles qualify for the STEM OPT 24-month extension if your degree falls under an eligible CIP code in computer science, information security, or a related STEM field. Your employer must be enrolled in E-Verify, and you'll train under a formal I-983 plan tied to your security engineering work.
Find STEM OPT Systems Security Engineer JobsOverview
Showing 5 of 13+ Systems Security Engineer jobs










See all Systems Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Systems Security Engineer roles.
Get Access To All Jobs
We are seeking a Security Systems Infrastructure Engineer to join our federal team supporting our Electronic Security Systems (ESS) projects. This is a hybrid role with the ability to come in to our Rockville, MD office and other project sites in the Washington D.C. Metro (DMV) area as needed.
At Johnson Controls, we support our nation’s most critical facilities, the people who occupy them, and the missions they enable. Johnson Controls Federal Systems (JCFS) is a specialized team serving as a trusted partner to the federal government. We help modernize U.S. military installations, Department of Defense and other federal agency facilities to be smarter, more resilient, efficient, sustainable, and secure.
Location: Hybrid role with the ability to come in to our Rockville, MD office as needed, as well as visit local project sites as needed. Must be based in the Washington D.C. Metro / Baltimore area (MD/DC/VA)
Benefits: Eligible for benefits on first day of employment
Vacation: 3 weeks of paid vacation, 5 sick days, 3 floating holidays, and 10 standard holidays per calendar year
As a Security System Engineer, you will:
- Be responsible for building, configuring, troubleshooting, and supporting Windows servers and network services required to support enterprise electronic security systems.
- Work with the installation, configuration, and administration of Active Directory Domain Services (AD DS)
- Build and configure domain controllers
- DNS, DHCP, Group Policy, user/service accounts, permissions, and basic domain administration
- Configuration of NTP / network time services and synchronization across servers, workstations, switches, and security appliances
- Install and perform basic administration of Microsoft SQL servers
- Develop and support Windows server roles, services, firewall rules, certificates, and service dependencies
- Basic Hyper-V / virtual machine configuration and administration
- Support Windows security hardening and implementation of secure server configurations
- Work with network troubleshooting involving VLANs, IP addressing, gateways, routing, ports, and firewall requirements
- Configurate and troubleshoot AAA services used to authenticate network switches and other network devices
- Interface with end users, gather requirements, and design and maintain an Active Directory and Network based server environment to manage end-user access and information for a physical security system.
- Provide a physical security network server design and set of requirements that meets user and customer needs
- Participate in technical design reviews and recommend solutions and improvements
- Develop plans for implementation, prototype testing and verification.
- Create detailed networked server documentation, including physical diagrams, logical diagrams, IP address schemes and asset management and database designs
- Design, document and implement processes for network server hardware, software and database support. Identify, implement and configure tools to facilitate support processes and provide audit trails of support activities
- Other duties as assigned
Required Qualifications:
- Strong technical knowledge with Windows Server administration, network integration, and security system infrastructure.
- Ability to take new or partially configured environments and perform the setup, integration, troubleshooting, testing, and documentation necessary to place the system into operation
- Experience working with Windows Server 2022 and Windows Server 2025
- Experience working with the installation, configuration, and administration of Active Directory Domain Services (AD DS)
- Ability to configure and troubleshoot network server, connectivity, and physical security system hardware and software issues, both in person and over the phone
- Ability to work with network engineers to configure and validate authentication, authorization, and accounting for managed switches
- Ability to troubleshoot communications between servers, network switches, controllers, workstations, and other IP-based security devices
Preferred Qualifications:
- Experience with electronic security systems such as Access Control Systems (ACS), Intrusion Detection Systems (IDS), Video Management Systems (VMS), and IP intercom systems is strongly preferred
- Demonstrated knowledge and skills required to configure and manage database systems using SQL Server and Oracle DBMS tools
- Experience with RADIUS and/or TACACS+, including integration of network-device authentication with Active Directory or another centralized authentication service
- Familiarity with Cisco switching environments is preferred
Preferred Education:
- Bachelor’s Degree or Associates Degree in Engineering, Computer Science, Networking, or other relevant discipline, or equivalent work experience
- Certified System Engineer ICAM PACS (CSEIP)
- Security+ and Network+ certifications
Who We Are
At Johnson Controls (NYSE: JCI), we are One Team working collaboratively to create purposeful solutions that make a difference in the world. We are a Fortune 500 company with more than 100,000 employees worldwide offering the world's largest portfolio of building technology products, solutions and services. As a member of our Federal Systems team, your work matters. We value and recognize your contributions and want to help you succeed. We invest in our employees, provide opportunities for growth and advancement, and foster a culture of inclusion and respect.
To learn more about who we are and what we do, please check out our Take a Journey video.
Recently, Johnson Controls has been recognized by several organizations for leadership in Environment, Sustainability and Governance, as well as innovations in smart building platforms:
- Named to FORTUNE’s “Most Admired Companies” List
- Corporate Knights Global 100 Most Sustainable Corporations in the World
- Named to Forbes Net Zero Leaders list
- CDP 2023 Climate Change 'A List'
- Ranked 67 on the Drucker Institute’s list of best-managed companies in America
- Forbes Best Employers for Diversity list.
- Newsweek America’s Greatest Workplaces for Diversity
- Ethisphere 2024 World's Most Ethical Companies list for the 17th time
- Newsweek America’s Greatest Workplaces for Women in 2024
- Named to Newsweek America’s Greatest Workplaces for Veterans 2024 / 2025 listing
- Named to Forbes America’s Best Employers for Veterans 2024
- Named one of the top military friendly employers by military.com
Johnson Controls is an equal employment opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, protected veteran status, genetic information, sexual orientation, gender identity, status as a qualified individual with a disability, or any other characteristic protected by law. For more information, please view EEO is the Law. If you are an individual with a disability and you require an accommodation during the application process, please visit www.johnsoncontrols.com/careers
Division: JCFS (Johnson Controls Federal Systems)
See all STEM OPT Systems Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT Systems Security Engineer Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization as a Systems Security Engineer
Verify your CIP code matches security engineering
Not every computer science or IT degree CIP code qualifies for STEM OPT. Check your degree's CIP code against the DHS STEM Designated Degree Program List before applying, and confirm with your DSO that your specific credential covers information assurance or security engineering.
Build an I-983 training plan around real deliverables
Systems security roles involve concrete, measurable work: threat modeling, penetration testing cycles, incident response protocols. Draft your I-983 learning objectives around specific security functions before your offer is signed so your DSO and employer can finalize it without delays.
Filter job postings by E-Verify enrollment status
Many security engineering postings don't state E-Verify enrollment upfront. Use Migrate Mate to identify employers already verified for STEM OPT hiring, so you're not discovering enrollment gaps late in the interview process when offer timelines are tight.
Target federal contractors with cleared security roles
Federal contractors staffing cleared or compliance-focused security roles are required to use E-Verify as a condition of their contracts. Searching DOL LCA disclosure data for security engineering filings at defense and government contractors helps you find structurally compliant employers before you apply.
Negotiate your start date around OPT card processing
USCIS processes STEM OPT extension applications while your initial OPT remains valid, but EAD card production adds weeks. Confirm your current EAD expiration with your DSO and give yourself at least 90 days of buffer when accepting a start date for a systems security role.
Use SOC codes to find accurate prevailing wage benchmarks
Systems Security Engineer roles often file under SOC 15-1212. Run the OFLC Wage Search using that code and your work location to understand the wage level your employer must certify before the LCA is filed, so you can spot offers that fall short of compliance thresholds.
Frequently Asked Questions
Does my degree qualify me for the STEM OPT extension as a Systems Security Engineer?
Your degree qualifies if its CIP code appears on the DHS STEM Designated Degree Program List. Degrees in computer science, information assurance, cybersecurity, electrical engineering, and related fields typically qualify. Your DSO confirms eligibility based on the CIP code attached to your specific credential, not the degree title alone.
Does a Systems Security Engineer employer need to be enrolled in E-Verify?
Yes. E-Verify enrollment is a hard requirement for STEM OPT employment. Your employer must be enrolled before your STEM OPT extension is approved. If your employer is not yet enrolled, they can register through E-Verify directly, but that process takes time and should happen before you submit your STEM OPT application to USCIS.
What goes into an I-983 training plan for a Systems Security Engineer role?
Your I-983 must document specific learning objectives tied to your security engineering work, the supervision structure, and how the training connects to your STEM degree. For this role, that typically means detailing responsibilities like vulnerability assessments, security architecture reviews, or incident response workflows. Your employer's direct supervisor signs off on the plan.
How does cap-gap protection apply if my employer files for H-1B while I'm on STEM OPT?
If your STEM OPT expires before October 1 of the H-1B visa fiscal year and your employer filed a timely H-1B petition that was selected in the lottery, cap-gap protection automatically extends your work authorization. You can continue working as a Systems Security Engineer without interruption during this gap period. USCIS confirms this status through your updated I-20.
Where can I find Systems Security Engineer jobs at E-Verify enrolled employers?
Migrate Mate filters Systems Security Engineer roles by employers already enrolled in E-Verify and with documented STEM OPT hiring history, so you're not manually cross-referencing enrollment status during your search. This saves significant time compared to contacting HR teams individually to verify compliance before applying.