Infrastructure Security Engineer Jobs in USA with Visa Sponsorship
Infrastructure Security Engineers are strong H-1B visa and O-1 visa candidates. Employers actively sponsor this role because qualified applicants are scarce, and a bachelor's degree in computer science, information systems, or a related field satisfies specialty occupation requirements. For detailed occupation requirements, see the O*NET profile.
Find Infrastructure Security Engineer JobsOverview
Showing 5 of 1,036+ Infrastructure Security Engineer jobs










See all 1,036+ Infrastructure Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Infrastructure Security Engineer roles.
Get Access To All Jobs
Google Infrastructure and Security Lead Architect
Join our AI & Engineering team in transforming technology platforms, driving innovation, and helping make a significant impact on our clients' success. You'll work alongside talented professionals reimagining and re-engineering operations and processes that are critical to businesses. Your contributions can help clients improve financial performance, accelerate new digital ventures, and fuel growth through innovation.
AI & Engineering leverages cutting-edge engineering capabilities to build, deploy, and operate integrated/verticalized sector solutions in software, data, AI, network, and hybrid cloud infrastructure. These solutions are powered by engineering for business advantage, transforming mission-critical operations. We enable clients to stay ahead with the latest advancements by transforming engineering teams and modernizing technology & data platforms. Our delivery models are tailored to meet each client's unique requirements.
Engineering as a Service provides complete design, implementation, and technology operations, leveraging our core engineering expertise. We transform engineering teams, modernize technology, and deliver complex programs with a product engineering approach. Our flexible delivery models-traditional teams, pools, or pods-are tailored to each client's needs, offering engineering-led advisory, implementation, and operational capabilities to accelerate innovation.
Recruiting for this role ends on 10-31-2026
Work you'll do:
As a Google Cloud (GCP) Infrastructure & Security Lead Architect, you will serve as a strategic technical leader and trusted advisor for our enterprise clients, guiding them through complex cloud transformation journeys. In this role, you will bridge the gap between high-level business objectives and deep technical execution, focusing on building scalable, highly available, and deeply secure cloud environments.
You will be responsible for the end-to-end design and implementation of foundational cloud architectures, from establishing secure multi-tenant landing zones and robust networking topologies to guiding application migration strategies. A critical component of this role is embedding security by design-leveraging Google Cloud's advanced security portfolio to protect workloads, secure data, and maintain continuous compliance against evolving cyber threats. You will collaborate closely with development, operations, and security teams to foster a culture of automation and DevSecOps excellence.
Responsibilities include:
- Architect and deploy highly scalable, multi-tenant GCP landing zones utilizing structured resource hierarchies (Organizations, Folders, Projects) tailored to client governance and billing requirements.
- Design centralized identity and access strategies leveraging Google Cloud Identity, Single Sign-On (SSO), and role-based access control (RBAC). Implement Context-Aware Access and the Principle of Least Privilege (PoLP) to secure human and machine identities.
- Standardize and automate the deployment of cloud infrastructure using Terraform. Develop modular, reusable infrastructure code to ensure consistent, repeatable, and auditable environment provisioning.
- Design and implement robust network topologies, including Shared VPCs, Hub-and-Spoke models, and isolated subnets to control traffic flow and minimize the blast radius of potential incidents.
- Architect highly available and secure connections between on-premises data centers and Google Cloud using Dedicated/Partner Interconnect or High Availability (HA) Cloud VPN.
- Secure inbound and outbound traffic flows by implementing Cloud Armor for WAF and DDoS protection, hierarchical firewall policies, and VPC Service Controls to prevent data exfiltration.
- Evaluate existing on-premises or multi-cloud legacy workloads to define optimal migration blueprints, utilizing industry-standard patterns.
- Architect and deploy highly scalable, multi-tenant GCP platform utilizing structured resource hierarchies (Organizations, Folders, Projects) tailored to client governance and billing requirements.
- Guide development teams in modernizing applications by adopting GCP managed services, serverless computing (Cloud Run, Cloud Functions), and container orchestration platforms (Google Kubernetes Engine - GKE).
- Collaborate with data architects to ensure real-time streaming and batch ingestion pipelines (e.g., Pub/Sub, Dataflow, BigQuery) are architected with strict security boundaries and encryption standards.
- Integrate and tune Google Cloud Security Command Center (SCC Premium) to provide unified visibility into misconfigurations, vulnerabilities, and active threats.
- Architect strategies for data security at rest and in transit using Cloud KMS (including Customer-Managed Encryption Keys), GCP Secret Manager, and Cloud Data Loss Prevention (DLP).
- Develop and implement organization policies and Google Cloud Policy Library rules to establish automated security guardrails that prevent non-compliant resource deployments.
Required Qualifications
- Bachelor's degree in computer science, Information Technology, Cybersecurity, or a closely related technical field (or equivalent practical experience).
- 7-10+ years of hands-on experience in cloud architecture, infrastructure engineering, or cloud security, with a significant portion of that time dedicated to Google Cloud Platform environments.
- Strong practical experience writing and maintaining Infrastructure as Code (IaC) using Terraform, alongside familiarity with CI/CD tools (e.g., GitHub Actions, GitLab CI, Cloud Build).
- Proven track record of participating in/or leading enterprise-scale cloud migrations and modernizing legacy infrastructure.
- Ability to travel up to 50% based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred Qualifications:
- 12+ years of comprehensive experience in cloud migration and security architecture, particularly in consulting, professional services, or client-facing advisory roles.
- Active status as a Google Cloud Professional Cloud Architect or Google Cloud Professional Cloud Security Engineer.
- Recognized cybersecurity certifications such as CISSP, CCSP, or CISM.
- Deep expertise in securing containerized workloads, Kubernetes (GKE) clusters, and microservice meshes (e.g., Anthos/Google Cloud Service Mesh).
- Strong ability to align technical designs with compliance frameworks such as NIST SP 800-53, CIS Benchmarks, SOC 2, HIPAA, or GDPR.
Wages + Salary
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $141,200 to $278,300.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
See all 1,036+ Infrastructure Security Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Infrastructure Security Engineer roles.
Get Access To All JobsTips for Finding Visa Sponsorship as an Infrastructure Security Engineer
Target employers with established H-1B filing history
Large technology companies, financial institutions, and defense contractors file H-1B petitions for security engineers consistently. Filtering by employers with prior sponsorship history narrows your search to realistic opportunities rather than companies new to the process.
Frame your resume around infrastructure-specific security skills
Employers and USCIS both scrutinize whether your background matches the role. Highlight specific platforms and protocols: firewall architecture, zero-trust network design, SIEM tools, and cloud security frameworks like AWS Security Hub or Azure Sentinel.
A relevant degree strengthens your specialty occupation case
USCIS evaluates whether the position normally requires a specialized degree. Computer science, cybersecurity, information assurance, or electrical engineering all support the specialty occupation argument. Unrelated degrees create friction that employers and attorneys must address.
Certifications support your petition but do not replace a degree
CISSP, CISM, CompTIA Security+, and cloud security certifications demonstrate competency and help with visa interviews. They strengthen the overall petition package, but USCIS still requires a qualifying degree or its equivalent in years of experience.
Start the sponsorship conversation early in the hiring process
Raising visa needs after an offer creates friction. Mentioning it during initial screening lets recruiters confirm employer policy before both sides invest time. Most large tech and finance employers have immigration counsel on retainer and expect this question.
Browse Infrastructure Security Engineer roles on Migrate Mate
Migrate Mate filters jobs by visa sponsorship availability, so every listing you see reflects an employer willing to sponsor. This removes the guesswork of cold-applying and discovering sponsorship limitations after multiple interview rounds.
Frequently Asked Questions
Do Infrastructure Security Engineer roles qualify for H-1B sponsorship?
Yes. Infrastructure Security Engineer is a specialty occupation under H-1B visa criteria because the role normally requires at least a bachelor's degree in computer science, cybersecurity, information systems, or a closely related technical field. USCIS consistently approves H-1B petitions for security engineering roles at companies that document the degree requirement clearly in the job description and Labor Condition Application.
What degree do I need for an employer to sponsor my visa as an Infrastructure Security Engineer?
A bachelor's degree in computer science, cybersecurity, information assurance, electrical engineering, or information systems satisfies the specialty occupation requirement for most petitions. Degrees in unrelated fields can still qualify if you have substantial coursework in a technical discipline and the employer's attorney builds a supporting argument. Three years of relevant work experience can substitute for one year of formal education if you lack a four-year degree.
Are Infrastructure Security Engineers likely to get selected in the H-1B lottery?
Selection depends on the annual lottery, not the job title. In FY2025, USCIS received roughly 442,000 registrations for 85,000 available slots, producing a selection rate near 25%. Applicants with a U.S. master's degree or higher enter a separate advanced-degree pool, which historically improves selection odds. Some employers pursue cap-exempt petitions through qualifying nonprofit or university affiliations, which bypasses the lottery entirely.
Can I work as an Infrastructure Security Engineer on OPT while waiting for H-1B sponsorship?
Yes. If you graduated from a U.S. university with a STEM-eligible degree, you qualify for a 24-month STEM OPT extension beyond the initial 12-month OPT period, giving you up to three years of work authorization. This window covers at least two H-1B lottery cycles. Your employer must be enrolled in E-Verify to support the STEM extension, which most established tech and finance employers already satisfy.
Where can I find Infrastructure Security Engineer jobs that offer visa sponsorship?
Migrate Mate lists Infrastructure Security Engineer roles specifically filtered for visa sponsorship availability. Every job on the platform reflects an employer willing to sponsor, so you can apply with confidence rather than discovering immigration limitations late in the hiring process. Browse current openings on Migrate Mate to find roles matched to your visa situation.
What is the prevailing wage requirement for sponsored Infrastructure Security Engineer jobs?
U.S. employers sponsoring a visa must pay at least the prevailing wage, which is what workers in the same role, area, and experience level typically earn. The Department of Labor sets this rate to make sure companies aren't hiring foreign workers simply because they'd accept lower pay than a U.S. worker. It varies by job title, location, and experience. You can look up current prevailing wage rates for any occupation and location using the OFLC Wage Search page.