Cybersecurity Jobs in USA with Visa Sponsorship
Cybersecurity professionals are in exceptionally high demand in the US, with hundreds of thousands of unfilled positions nationwide creating strong employer willingness to sponsor international talent. Most sponsored roles are in the private sector at tech companies, financial institutions, and healthcare organizations, since government and defense positions typically require security clearances limited to US citizens. Industry certifications such as CISSP, CompTIA Security+, and CEH carry significant weight in both hiring and visa petition support. For detailed occupation requirements, see the O*NET profile.
Find Cybersecurity JobsOverview
Showing 5 of 1,882+ Cybersecurity jobs










See all 1,882+ Cybersecurity Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Cybersecurity roles.
Get Access To All Jobs
Position Summary:
Work Arrangement:
This position is available as a hybrid position in our Sioux Falls, SD or Wilmington, DE office.
At The Bancorp, we’ve spent more than 25 years driving innovation in the financial services industry. As one of the first banks to embrace fintech, we combine technology, expertise and a forward-looking approach to deliver creative, real-world solutions. We work side by side with our partners to help them grow and innovate with confidence. Across Fintech Solutions, Institutional Banking, Commercial Lending and Real Estate Bridge Lending, we provide the people, processes, technology and banking capabilities that turn bold ideas into outcomes.
Join a team that brings urgency and rigor to every challenge and plays a direct role in driving growth for our clients and the communities we serve.
The Cybersecurity Threat Analyst I role is responsible for monitoring security alerts, logs, and threat intelligence under general supervision to identify suspicious activity. Performs initial triage using established procedures, documents findings, creates or updates tickets, and escalates events requiring deeper investigation or response.
Supports routine vulnerability management, asset review, investigation, reporting, and security awareness activities. Uses approved artificial intelligence (AI) tools for research, query development, evidence summarization, and documentation while validating outputs, following data-handling requirements, and protecting confidential information.
Key Responsibilities:
- Monitors security alerts from approved tools and performs initial triage using documented procedures and playbooks.
- Reviews relevant firewall, email, web, domain name system (DNS), endpoint, and other logs to gather evidence and identify indicators of suspicious activity.
- Creates and updates tickets, documents actions taken, and escalates incidents based on defined severity and escalation criteria.
- Supports incident response activities under guidance, including evidence collection, basic scoping, containment tracking, and follow-up documentation.
- Reviews threat intelligence alerts and indicators of compromise for relevance to the environment and escalates significant findings.
- Runs approved vulnerability scans and reviews results to identify potential issues, duplicates, and items requiring validation.
- Collects and reviews asset information, including configurations and running processes, to support investigations and vulnerability management.
- Operates security monitoring tools and performs routine configuration or tuning tasks under guidance.
- Participates in change management activities and follows established security operations procedures.
- Communicates technical findings clearly to cybersecurity team members, internal partners, and vendors.
- Assists with security product evaluations and recommends improvements based on documented requirements.
- Supports security metrics, trend reporting, and assigned security awareness activities.
- Uses approved AI-assisted capabilities to enrich alerts, correlate indicators, summarize evidence, and support basic investigation tasks.
- Uses approved AI assistance to draft basic queries, investigation notes, reports, scripts, and stakeholder communications.
- Validates AI-generated content against authoritative sources and follows approved-use, data-handling, human-review, documentation, and auditability requirements.
- Maintains awareness of emerging threats, including AI-enabled phishing, social engineering, and enterprise AI misuse, and escalates relevant findings.
- Performs other duties as assigned.
Qualification Requirements:
- Associate or bachelor’s degree in cybersecurity, information technology, computer science, or a related field, or an equivalent combination of education, training, and experience.
- Internships, academic labs, help desk, system administration, network support, or security operations experience may qualify as relevant experience.
- Foundational understanding of cybersecurity principles, common threats, Transmission Control Protocol/Internet Protocol (TCP/IP) networking, and Windows, Linux, or macOS operating systems.
- Basic familiarity with security logs, monitoring tools, vulnerability management concepts, and ticketing workflows.
- Ability to follow documented procedures, maintain accurate records, recognize when additional assistance is needed, and escalate promptly.
- Basic scripting, command-line, or query skills, or a demonstrated willingness to learn tools such as Python, PowerShell, or SQL.
- Familiarity with generative AI and machine learning concepts used in cybersecurity, including common capabilities, limitations, privacy risks, and the need for human validation.
- Clear written and verbal communication, sound organization, and the ability to work effectively in a collaborative environment.
- Coursework, an internship, a lab environment, or hands-on experience related to security operations, threat analysis, incident response, or vulnerability management preferred.
- Familiarity with one or more security technologies, such as security information and event management (SIEM), endpoint or extended detection and response (EDR/XDR), security orchestration, automation, and response (SOAR), threat intelligence, vulnerability scanning, or ticketing platforms preferred.
- Basic knowledge of network traffic, firewalls, intrusion detection or prevention, packet analysis, cloud services, databases, or data visualization tools preferred.
- An entry-level certification, such as CompTIA Security+, Network+, CySA+, Microsoft SC-900, or a comparable vendor credential, or a willingness to pursue one preferred.
- Basic experience with scripting, application programming interfaces (APIs), or low-code automation to collect, organize, or validate security data preferred.
- Familiarity with approved AI-assisted workflows for security research, documentation, query development, or analysis preferred.
- Awareness of AI-specific security risks and safeguards, including prompt injection, sensitive-data leakage, malicious automation, and AI-generated social engineering preferred.
What Success Looks Like:
- Within the first 90 days, works the alert queue independently using established playbooks.
- Documents investigations clearly enough that a senior analyst can pick up the case without a conversation.
- Escalates at the right threshold, neither sitting on something urgent nor passing up work the analyst is equipped to handle.
- By the end of the first year, has progressed meaningfully toward a foundational security certification.
- Navigates the SIEM and endpoint tooling without supervision.
- Contributes to tuning suggestions and threat hunting work rather than only consuming assignments.
- Treats AI-assisted output as a draft rather than an answer, and consistently validates results against primary evidence before acting.
Why This Role Matters:
- This position is the program’s intake layer.
- Alerts, threat intelligence feeds, scan output, and asset discovery data all land here first, and anything missed or under-documented at this stage does not get caught somewhere else.
- This position protects senior capacity.
- Detection engineering, forensics, and threat hunting require uninterrupted focus, which is impossible while working a live queue.
- Level 1 ownership of steady-state triage is what lets senior analysts go deep, and it is why routine monitoring and ticket flow keep running when responders pull away to an active incident.
- This position closes the feedback loop.
- No one sees false positives more often than the analyst in the queue daily, and those observations are the raw input for tool tuning.
- The same applies to the vulnerability and asset data reviewed here, which keeps the program’s picture of its own environment accurate.
- This position creates the record.
- Good case documentation makes work transferable across shifts and up to incident response, while thin documentation means the work gets redone.
- This position is where AI governance actually happens.
- Approved-use and human-review requirements are policy on paper until someone applies them at the point of use, and the highest-volume routine AI usage in the department sits in this seat.
- This position is the program’s bench, developing future senior analysts on the Bank’s own tooling and escalation thresholds.
Additional Information:
This job will be open and accepting applications for a minimum of five days from the date it was posted.
Working at The Bancorp Bank, N.A. and Benefits Information:
The Bancorp Bank, N.A. is an EQUAL OPPORTUNITY EMPLOYER and will not discriminate on the basis of race, color, religion, gender, gender identity, sexual orientation, pregnancy, citizenship, national origin, age, disability, genetic information, veteran status or other protected category with respect to recruitment, hiring, training, promotion, and other terms and conditions of employment.
Employment with The Bancorp Bank, N.A. includes successfully passing a background check including credit, criminal, education, employment, OFAC, and social media background history.
LI-PJ1
LI-Hybrid
See all 1,882+ Cybersecurity Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Cybersecurity roles.
Get Access To All JobsTips for Finding Cybersecurity Jobs
Take advantage of the cybersecurity talent shortage
The U.S. has hundreds of thousands of unfilled cybersecurity positions, which works in your favor for sponsorship. Employers facing critical security staffing gaps are more willing to sponsor visas when they can't find qualified domestic candidates.
Earn industry certifications that employers prioritize
CISSP, CISM, CEH, and CompTIA Security+ are among the most recognized cybersecurity credentials. Holding one or more of these certifications makes your specialty occupation case clearer and signals readiness for senior security roles.
Focus on private-sector roles that don't require security clearance
Many government and defense cybersecurity positions require U.S. security clearance, which is limited to citizens and permanent residents. Target private-sector companies, financial institutions, and healthcare organizations where clearance is not a barrier.
Specialize in cloud security or application security
Cloud security architects, AppSec engineers, and penetration testers are among the hardest cybersecurity roles to fill. Specializing in one of these areas makes you a stronger sponsorship candidate than a generalist security analyst.
Use STEM OPT to build your security track record
Cybersecurity and information security degrees are STEM-eligible, providing 12 months of OPT plus a 24-month STEM extension. Use this time to earn certifications, respond to real incidents, and build the experience that makes you an obvious sponsorship candidate.
Explore cap-exempt cybersecurity roles at universities and research institutions
University IT security teams and federally funded research centers are H-1B cap-exempt. These roles let you bypass the lottery entirely and can serve as a stepping stone to private-sector positions once you have U.S. work experience.
Frequently Asked Questions
Do cybersecurity roles with visa sponsorship require security clearances?
Most sponsored cybersecurity positions do not require security clearances. Clearances are primarily required for government agencies, defense contractors, and intelligence community roles, and are generally limited to U.S. citizens or permanent residents. Private-sector roles at technology companies, financial institutions, healthcare systems, and managed security service providers rarely require clearances and are where the vast majority of sponsorship occurs.
Does the cybersecurity talent shortage actually make it easier to get sponsored?
Yes. With hundreds of thousands of unfilled cybersecurity positions in the U.S., employers face sustained difficulty hiring domestically, which increases their willingness to invest in visa sponsorship. This shortage also strengthens the labor market test for green card processing (PERM labor certification), as employers can more easily demonstrate that qualified U.S. workers are unavailable. Candidates with hands-on experience in penetration testing, incident response, or cloud security are in particularly strong positions.
Which cybersecurity certifications strengthen a visa petition?
CISSP, CompTIA Security+, CEH (Certified Ethical Hacker), and OSCP are the most recognized credentials and carry weight in both hiring and immigration documentation. These certifications provide concrete evidence that the role demands specialized knowledge beyond a general IT background. While certifications alone do not replace the bachelor's degree requirement for H-1B visa, they meaningfully support the specialty occupation argument when included in the petition package.
Can cybersecurity professionals qualify for the O-1 visa?
Yes, if you have notable contributions to the field. Published vulnerability disclosures, conference presentations at events like DEF CON or Black Hat, widely used open-source security tools, or significant bug bounty achievements can all serve as evidence of extraordinary ability. The O-1 visa bypasses the H-1B lottery and has no annual cap, making it a strong alternative for cybersecurity researchers and practitioners with a visible track record.
How to find Cybersecurity jobs with visa sponsorship?
To find cybersecurity jobs with visa sponsorship, use Migrate Mate, which specializes in connecting international talent with sponsoring employers. Focus on tech companies, financial institutions, government contractors, and healthcare organizations that frequently sponsor H-1B, O-1, and TN visas for cybersecurity professionals. Filter searches by roles like Security Analyst, Penetration Tester, and CISO positions.
What cybersecurity specializations are most in demand for visa sponsorship?
Cloud security, application security, and incident response are among the highest-demand specializations because they require deep technical expertise that is genuinely scarce. Security engineering roles at SaaS companies and financial institutions are particularly well-sponsored. GRC (governance, risk, and compliance) roles can also qualify but may face more H-1B scrutiny since USCIS sometimes questions whether these positions require a specific technical degree.
What is the prevailing wage requirement for sponsored Cybersecurity jobs?
When a U.S. employer sponsors a foreign worker for a work visa, they are legally required to pay at least the "prevailing wage", the average wage paid to workers in the same occupation, in the same geographic area, with similar experience. This is set by the Department of Labor to prevent employers from hiring foreign workers at below-market rates. The prevailing wage varies significantly by role, location, and experience level. For example, a cybersecurity in California will have a different prevailing wage than the same role in a smaller state. You can look up current prevailing wage rates for any occupation and location using the OFLC Wage Search Page.