Information Security Manager Jobs in USA with Visa Sponsorship
Information Security Manager roles attract strong H-1B visa sponsorship from financial services, healthcare, and tech employers. Most require a bachelor's degree in computer science or cybersecurity, and relevant certifications like CISSP or CISM significantly strengthen your petition. For detailed occupation requirements, see the O*NET profile.
Find Information Security Manager JobsOverview
Showing 5 of 5,669+ Information Security Manager jobs










See all 5,669+ Information Security Manager Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Information Security Manager roles.
Get Access To All Jobs
About us
Fanatics is building a leading global digital sports platform. We ignite the passions of global sports fans and maximize the presence and reach for our hundreds of sports partners globally by offering products and services across Fanatics Commerce, Fanatics Collectibles, and Fanatics Betting & Gaming, allowing sports fans to Buy, Collect, and Bet. Through the Fanatics platform, sports fans can buy licensed fan gear, jerseys, lifestyle and streetwear products, headwear, and hardgoods; collect physical and digital trading cards, sports memorabilia, and other digital assets; and bet as the company builds its Sportsbook and iGaming platform. Fanatics has an established database of over 100 million global sports fans; a global partner network with approximately 900 sports properties, including major national and international professional sports leagues, players associations, teams, colleges, college conferences and retail partners, 2,500 athletes and celebrities, and 200 exclusive athletes; and over 2,000 retail locations, including its Lids retail stores. Our more than 22,000 employees are committed to relentlessly enhancing the fan experience and delighting sports fans globally.
The Role
The Information Security GRC Analyst III, Controls Assurance (Fanatics Corporate) sits at the center of how Fanatics proves its security controls actually work, testing across PCI DSS, SOX ITGC, SOC reporting, and our internal NIST-aligned control baselines. This is a Corporate-level role with direct exposure across the full Fanatics portfolio: you will work daily with business units, IT teams, Security Operations, and InfoSec GRC counterparts across our subsidiaries and brands, giving you a rare, enterprise-wide view of how a global, multi-brand organization operates and secures itself.
Working in partnership with the designated owner of each control set, you will execute assigned control testing, collect and evaluate evidence, support user access reviews and control exception administration, and contribute to findings tracking and control reporting. Control effectiveness is rarely a clean pass or fail; you will need to read the intent behind a control, work through the grey areas, and take a practical, risk-based approach to compensating controls, tailored to how each subsidiary or brand actually does business. Strong communication is central to the role: you will explain technical and non-technical control requirements clearly and consistently to control owners, and use that clarity to influence timely, positive adoption of controls and remediation.
Control baselines and framework control sets are established and owned within the GRC team, so this is a controls assurance role rather than a program build-out or control design role. A substantial portion of the work is recurring and deadline-driven, including access review cycles, evidence collection, and assessment calendars.
- Execute assigned control tests in partnership with control set owners, including: sample selection, evidence requests, walkthroughs, and documented conclusions on operating effectiveness.
- Communicate control requirements, testing results, and rationale clearly and consistently to control owners across technical and non-technical audiences, and use that clarity to influence timely, positive adoption of controls and remediation.
- Prepare workpapers that withstand assessor review without rework.
- Evaluate evidence critically, identifying artifacts that do not substantiate the control.
- Support QSA, audit, and service auditor engagements, including evidence request lists and walkthrough preparation.
- Support user access review campaigns: population scoping, reviewer assignments, completion monitoring, and verification that revocations were executed.
- Collect and quality-check evidence for framework cycles, resolving gaps before assessor fieldwork.
- Support the control exception process: intake, routing, compensating controls, expiry tracking, and re-review.
- Apply practical, risk-based judgment to grey-area control questions, including whether a compensating control adequately addresses the underlying risk given how a specific subsidiary or brand operates.
- Identify opportunities to reduce manual evidence collection.
- Help maintain the control library: owners, test procedures, evidence requirements, testing frequency, and system mappings.
- Support cross-framework mapping, including mapping internal baseline controls to the external requirements they satisfy.
- Support findings tracking and remediation follow-up, retesting closed items rather than accepting closure on assertion.
- Contribute to control reporting and metrics, and to workflow upkeep in the designated GRC platform.
- Partner day-to-day with business units, IT teams, Security Operations, and InfoSec GRC counterparts across Fanatics' subsidiaries and brands, understanding how each operates in order to apply controls appropriately.
- Build sufficient depth across control sets to provide backup coverage during leave, peak workload, or overlapping cycles.
What We're Looking For
- Four years + in IT audit, IT control testing, information security GRC, or a related discipline; Big Four or regional firm IT audit experience applies directly.
- Demonstrated experience executing control tests to a defined procedure, including sampling, evidence evaluation, and documented conclusions.
- Experience with user access reviews, either administering campaigns or testing them as a control.
- Exposure to at least one of PCI DSS, SOX ITGC, SOC, or an internal security control baseline.
- Experience driving a recurring process across stakeholders outside a direct reporting line, with a record of following items to completion.
- Curiosity and adaptability to understand how Fanatics' different subsidiaries and brands operate, and how that context shapes how a control should be applied and assessed for effectiveness.
- Working knowledge of core control domains: access management and access reviews, privileged access, change management, SDLC, logging and monitoring, encryption, vulnerability and patch management, backup and recovery, and cloud platform fundamentals.
- Excellent written and verbal communication, with the ability to explain technical and non-technical control concepts clearly and consistently to control owners, and to influence stakeholders toward timely, positive adoption of controls and remediation, even without direct authority over them.
- Effective use of approved AI tools in day-to-day work, with sound judgment about where AI output can and cannot be relied upon in an audit context.
- Organizational discipline, persistence, and judgment about when to escalate.
- Detail-oriented, with sound judgment for navigating grey areas in control descriptions and a practical, risk-based approach to evaluating compensating controls rather than a strict pass/fail mindset.
- Bachelor's degree in information security, cybersecurity, information systems, accounting, or a related field, or equivalent practical experience.
- Preferred: CISA certification.
- Preferred: exposure to two or more of PCI DSS, SOX ITGC, and SOC, including familiarity with PCI DSS v4.0.1, and testing against NIST 800-53 or the NIST Cybersecurity Framework.
- Preferred: familiarity with an enterprise GRC or IRM platform.
By submitting your application, you agree to our terms of service and acknowledge you have read our Candidate Privacy Policy.
See all 5,669+ Information Security Manager Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Information Security Manager roles.
Get Access To All JobsTips for Finding Visa Sponsorship as an Information Security Manager
Lead with certifications on your resume
CISSP, CISM, and CISA certifications signal specialty occupation eligibility to both employers and USCIS. Petitions supported by industry credentials alongside a qualifying degree face fewer RFEs during adjudication.
Target regulated industries first
Banks, hospitals, and federal contractors face mandatory compliance frameworks like SOX, HIPAA, and FedRAMP. These organizations sponsor H-1B visas more consistently because security leadership is legally required, not discretionary.
Frame your degree field precisely
USCIS scrutinizes specialty occupation claims for management-adjacent roles. A degree in computer science, information systems, or cybersecurity maps more cleanly to this title than a general business or IT degree.
Document your technical scope, not just team size
Sponsorship petitions succeed when job duties demonstrate technical complexity. Highlight architecture decisions, incident response ownership, and security tool implementation rather than headcount or budget managed.
Ask about sponsorship before the final interview round
Many employers sponsor but don't advertise it. Raising sponsorship after an offer creates friction. Asking during a second-round conversation, once mutual interest is established, gives both sides time to align on process.
Use Migrate Mate to filter for verified sponsors
Not every posting that says 'visa sponsorship available' follows through. Migrate Mate surfaces employers with confirmed H-1B filing history for security roles, saving you from applying to companies that won't actually sponsor.
Frequently Asked Questions
Does Information Security Manager qualify as a specialty occupation for H-1B purposes?
Yes, but the petition needs to be drafted carefully. USCIS may question whether a management role requires a specific bachelor's degree. The strongest petitions document that the position demands theoretical and practical application of computer science, information security, or a directly related field, not just general business acumen. Roles with hands-on technical duties and a degree requirement written into the job description are approved more consistently.
Which visa categories are commonly used to sponsor Information Security Managers?
H-1B visa is the most common path for employer-sponsored security managers. Candidates with extraordinary achievement in cybersecurity, such as published research, national awards, or a record of leading high-profile breach responses, may qualify for O-1A. L-1A is an option for managers transferring from a foreign affiliate. Australian citizens can pursue the E-3 visa, which has no lottery and renews indefinitely.
How do I find employers that actually sponsor H-1B visas for security manager roles?
Migrate Mate filters job listings by confirmed sponsorship history, so you're not guessing based on vague job description language. Look for employers in financial services, healthcare systems, defense contractors, and large technology companies. These sectors hire security managers at scale and have established immigration programs, meaning fewer delays and more experienced HR teams handling the petition process.
Does experience substitute for a degree when applying for H-1B sponsorship as a security manager?
USCIS allows three years of specialized experience to substitute for one year of a bachelor's degree, meaning 12 years of directly relevant experience can stand in for a four-year degree. In practice, approvals on experience-only petitions for management roles face higher RFE rates. Pairing substantial experience with an associate's degree or professional certifications like CISSP creates a stronger combined record than experience alone.
What is the H-1B approval rate for Information Security Manager roles?
USCIS doesn't publish approval rates by job title, but cybersecurity and IT management roles generally see approval rates above 85% when the petition clearly establishes specialty occupation. Denial risk increases when the job description includes duties that don't require a specific technical degree, or when the employer is classified as a staffing or consulting firm. Direct employer petitions with well-documented technical job duties perform significantly better.
What is the prevailing wage requirement for sponsored Information Security Manager jobs?
U.S. employers sponsoring a visa must pay at least the prevailing wage, which is what workers in the same role, area, and experience level typically earn. The Department of Labor sets this rate to make sure companies aren't hiring foreign workers simply because they'd accept lower pay than a U.S. worker. It varies by job title, location, and experience. You can look up current prevailing wage rates for any occupation and location using the OFLC Wage Search page.