Infrastructure Security Engineer Jobs in USA with Visa Sponsorship
Infrastructure Security Engineers are strong H-1B visa and O-1 visa candidates. Employers actively sponsor this role because qualified applicants are scarce, and a bachelor's degree in computer science, information systems, or a related field satisfies specialty occupation requirements. For detailed occupation requirements, see the O*NET profile.
Find Infrastructure Security Engineer JobsOverview
Showing 5 of 1,059+ Infrastructure Security Engineer jobs










See all 1,059+ Infrastructure Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Infrastructure Security Engineer roles.
Get Access To All Jobs
About WorkOS
WorkOS builds modern developer tools and APIs that make it easy for companies to become Enterprise Ready. Our platform powers authentication, identity, authorization, and other critical infrastructure that developers need to securely scale their products to large organizations.
We recently raised a $100M Series C, valuing the company at $2B, led by Meritech and Sapphire with participation from Greenoaks, Craft, Abstract, and Audacious. WorkOS powers enterprise features for many of the fastest-growing AI companies, including OpenAI, Cursor, and Perplexity, Sierra, and Plaid.
As AI reshapes software, WorkOS is at the frontier of Human and Agent Authentication, Identity, and Access Control helping companies answer a new critical question: who are your agents, and what are they allowed to do? Our fast-growing customer base includes hundreds of modern software companies building the next generation of enterprise-ready products.
About the Security Platform team
The Infrastructure Security team provides and supports the primitives that enable engineering to securely build applications and meet compliance obligations, while abstracting away the underlying complexity for the best possible developer experience.
Our work centers on workload identity and authorization: how internal applications authenticate to each other and to the services they depend on, and how that access is granted and enforced. We're replacing static secrets with short-lived identity credentials, bringing identity-based authentication to the services engineers use every day, and unifying how authorization is managed across the company.
We're a platform engineering team with a security mission. We measure success by the security outcomes we enable and by how much engineers enjoy building on what we ship — the secure path should be the easiest path.
Who we're looking for
- A platform builder. You love building infrastructure that other engineers rely on every day, and you sweat the developer experience details that make adoption effortless.
- Fluent in service-to-service auth. You know authentication and authorization deeply: JWTs, X.509 certificates, and when to reach for each.
- A systems thinker. You reason carefully about bootstrapping, circular dependencies, availability, and failure modes, especially for infrastructure that everything else depends on.
- A pragmatic migrator. You know that shipping the primitive is half the job. You can drive adoption across many teams, meet them where they are, and retire the legacy path.
- A strong partner to engineering. You build trust with engineers by understanding their priorities and making security frictionless.
- Excited about AI. You're embracing AI and automation to scale platform work and reduce toil.
- Curious and humble. You ask the basic questions, enjoy untangling complex systems, and bring others along with you.
Responsibilities
- Build workload identity infrastructure. Make short-lived identity credentials a default part of every application's runtime environment, in partnership with application platform owners.
- Bring identity-based authentication to internal services. Work with the owners of major internal dependencies to support identity certificates, make them the golden path for newly onboarding applications, and drive migration of existing ones.
- Eliminate static secrets. Replace all static passwords and service tokens with short-lived identity credentials, and build identity-authenticated egress proxies and API abstractions that inject and automatically rotate managed secrets for the external dependencies that still require them.
- Unify authorization. Build a single interface and framework through which authorization policies are centrally managed and enforced.
Qualifications
- 5+ years of experience in software engineering, with a focus on security-related platform, infrastructure, or distributed systems.
- Strong working knowledge of secrets management, fine-grained authorization, and workload identity systems.
- Familiarity with the Kubernetes ecosystem and authentication/authorization technologies such as JWTs, X.509 certificates, PKI, cert-manager, SPIFFE/SPIRE, and OPA.
- Experience building and operating production infrastructure that other teams depend on, with attention to availability and failure modes.
- Proven ability to drive cross-team adoption of platform capabilities or lead large-scale migrations.
Benefits and Perks (US Only)
At WorkOS, we offer resources that emphasize personal and familial well-being. We offer healthcare coverage for you and your family, including medical, dental, and vision. We offer parental leave, paid-time off and fully remote working arrangements.
- 401k matching
- Competitive Equity
- Healthcare, dental and vision coverage
- FSA, ST/LT Disability, Voluntary Life
- Carrot fertility benefits
- 20 days paid vacation + 10 holidays + unlimited sick leave
- 12 weeks fully paid parental leave
- Fitness: Monthly stipend for gyms, yoga classes, race registrations or whatever keeps you active
- Wellness: Monthly stipend for a massage, meditations class, therapy, or activities that enhance your well-being
- Commuter benefits for hybrid employees in SF/NYC
- Unlimited token usage!
Please inquire directly with our recruiting team for benefits available to those working outside the US.
Equal Opportunity Employer
WorkOS is an equal opportunity employer, committed to diversity and inclusiveness. We will consider all qualified applicants without regard to race, color, nationality, gender, gender identity or expression, sexual orientation, religion, disability or age.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Compensation Range: $175K - $275K
See all 1,059+ Infrastructure Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Infrastructure Security Engineer roles.
Get Access To All JobsTips for Finding Visa Sponsorship as an Infrastructure Security Engineer
Target employers with established H-1B filing history
Large technology companies, financial institutions, and defense contractors file H-1B petitions for security engineers consistently. Filtering by employers with prior sponsorship history narrows your search to realistic opportunities rather than companies new to the process.
Frame your resume around infrastructure-specific security skills
Employers and USCIS both scrutinize whether your background matches the role. Highlight specific platforms and protocols: firewall architecture, zero-trust network design, SIEM tools, and cloud security frameworks like AWS Security Hub or Azure Sentinel.
A relevant degree strengthens your specialty occupation case
USCIS evaluates whether the position normally requires a specialized degree. Computer science, cybersecurity, information assurance, or electrical engineering all support the specialty occupation argument. Unrelated degrees create friction that employers and attorneys must address.
Certifications support your petition but do not replace a degree
CISSP, CISM, CompTIA Security+, and cloud security certifications demonstrate competency and help with visa interviews. They strengthen the overall petition package, but USCIS still requires a qualifying degree or its equivalent in years of experience.
Start the sponsorship conversation early in the hiring process
Raising visa needs after an offer creates friction. Mentioning it during initial screening lets recruiters confirm employer policy before both sides invest time. Most large tech and finance employers have immigration counsel on retainer and expect this question.
Browse Infrastructure Security Engineer roles on Migrate Mate
Migrate Mate filters jobs by visa sponsorship availability, so every listing you see reflects an employer willing to sponsor. This removes the guesswork of cold-applying and discovering sponsorship limitations after multiple interview rounds.
Frequently Asked Questions
Do Infrastructure Security Engineer roles qualify for H-1B sponsorship?
Yes. Infrastructure Security Engineer is a specialty occupation under H-1B visa criteria because the role normally requires at least a bachelor's degree in computer science, cybersecurity, information systems, or a closely related technical field. USCIS consistently approves H-1B petitions for security engineering roles at companies that document the degree requirement clearly in the job description and Labor Condition Application.
What degree do I need for an employer to sponsor my visa as an Infrastructure Security Engineer?
A bachelor's degree in computer science, cybersecurity, information assurance, electrical engineering, or information systems satisfies the specialty occupation requirement for most petitions. Degrees in unrelated fields can still qualify if you have substantial coursework in a technical discipline and the employer's attorney builds a supporting argument. Three years of relevant work experience can substitute for one year of formal education if you lack a four-year degree.
Are Infrastructure Security Engineers likely to get selected in the H-1B lottery?
Selection depends on the annual lottery, not the job title. In FY2025, USCIS received roughly 442,000 registrations for 85,000 available slots, producing a selection rate near 25%. Applicants with a U.S. master's degree or higher enter a separate advanced-degree pool, which historically improves selection odds. Some employers pursue cap-exempt petitions through qualifying nonprofit or university affiliations, which bypasses the lottery entirely.
Can I work as an Infrastructure Security Engineer on OPT while waiting for H-1B sponsorship?
Yes. If you graduated from a U.S. university with a STEM-eligible degree, you qualify for a 24-month STEM OPT extension beyond the initial 12-month OPT period, giving you up to three years of work authorization. This window covers at least two H-1B lottery cycles. Your employer must be enrolled in E-Verify to support the STEM extension, which most established tech and finance employers already satisfy.
Where can I find Infrastructure Security Engineer jobs that offer visa sponsorship?
Migrate Mate lists Infrastructure Security Engineer roles specifically filtered for visa sponsorship availability. Every job on the platform reflects an employer willing to sponsor, so you can apply with confidence rather than discovering immigration limitations late in the hiring process. Browse current openings on Migrate Mate to find roles matched to your visa situation.
What is the prevailing wage requirement for sponsored Infrastructure Security Engineer jobs?
U.S. employers sponsoring a visa must pay at least the prevailing wage, which is what workers in the same role, area, and experience level typically earn. The Department of Labor sets this rate to make sure companies aren't hiring foreign workers simply because they'd accept lower pay than a U.S. worker. It varies by job title, location, and experience. You can look up current prevailing wage rates for any occupation and location using the OFLC Wage Search page.