Security Operations Manager Jobs in USA with Visa Sponsorship
Security Operations Manager roles qualify for H-1B visa and O-1 visa sponsorship when the position requires a bachelor's degree in cybersecurity, information systems, or a related field. Employers in finance, defense contracting, healthcare, and tech sponsor these roles regularly, particularly for candidates managing SOC teams or enterprise security programs. For detailed occupation requirements, see the O*NET profile.
Find Security Operations Manager JobsOverview
Showing 5 of 10,075+ Security Operations Manager jobs










See all 10,075+ Security Operations Manager Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Security Operations Manager roles.
Get Access To All Jobs
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
Position Summary
The Lead Director of Third-Party Security Assessment & Risk Operations plays a critical role in protecting the organization by ensuring that third parties (vendors, suppliers, and partners) meet the security standards required to operate in a highly regulated environment. This role leads the end-to-end lifecycle of third-party security assessments, ensuring that risks are identified early, understood clearly, and addressed effectively. By building and advancing a scalable, risk-based assessment program, this position helps safeguard the enterprise while enabling the business to move forward with confidence in its external partnerships.
This leader partners closely with Procurement, Legal, Compliance, and business units to embed security into the full vendor lifecycle and translate complex cyber risks into clear, actionable guidance. The role also shapes enterprise-wide risk and control assurance efforts by bringing visibility, consistency, and accountability to third-party risk management. Through strong program leadership, executive engagement, and continuous improvement, the Lead Director ensures the organization can manage third-party risk at scale while supporting growth, regulatory compliance, and operational resilience.
Key Responsibilities:
Third Party Security Leadership
- Own and continuously mature the enterprise Third Party Security program, including processes, and tooling.
- Direct staff in the identification, development, implementation, and maintenance of security assessment practices for all third parties — including vendors, suppliers, and business partners.
- Establish demand-driven resource models and align team capacity to portfolio volume and organizational priorities.
- Build, coach, and lead a high-performing team of security professionals spanning Individual Contributors, Managers, and Senior Managers.
Risk Assessment & Control Assurance
- Lead the evaluation and assessment of emerging cyber threats, vulnerabilities, and attack vectors relevant to third party ecosystems.
- Direct detailed control testing, regulatory audit scenarios, and compliance validation activities for third party relationships.
- Develop and enforce risk-based remediation strategies derived from assessment findings and lessons learned.
- Implement and enforce security controls within third parties supporting large, complex, and diverse enterprise environments.
Regulatory Compliance & Policy Alignment
- Ensure organizational adherence to applicable local, national, and international regulatory requirements (e.g., HIPAA, PCI-DSS, NIST, ISO 27001/27036, SOC 2) within the scope of third party security.
- Provide authoritative security guidance to project teams, portfolio personnel, and business leaders to ensure alignment with CVS Health control standards.
- Monitor evolving regulatory and industry landscapes and proactively adjust program requirements to maintain compliance.
Executive Stakeholder Engagement
- Serve as a trusted advisor to senior business and technology executives on third party cyber security matters.
- Communicate risk posture, program performance metrics, and remediation status to executive leadership through compelling, data-driven presentations.
- Act as the primary point of enablement for Third Party Security Assessment Operations across the organization.
- Develop and sustain strategic relationships across functional business, IT, and vendor leadership teams.
Operational Excellence & Continuous Improvement
- Establish organizational capabilities to track program progress, surface issues, and remove obstacles in alignment with the CVS Health mission.
- Define and monitor KPIs and KRIs to measure program effectiveness and drive continuous improvement.
- Identify and implement technology solutions and automation opportunities to scale assessment operations.
Required Qualifications
- 10+ years of progressive Information Security experience, with a strong foundation across risk management, architecture, and engineering domains.
- 7+ years of direct leadership experience managing security professionals in both direct and matrixed reporting structures.
- 5+ years of experience building and leading Third Party Security Risk or Vendor Risk Management programs at enterprise scale.
- 5+ years of experience leading detailed control testing, regulatory audits, and compliance assessments.
- 3+ years of experience implementing security controls within third party environments supporting large, complex enterprises.
Preferred Qualifications
- Exceptional communication and executive presentation skills; ability to translate technical risk into business language for non-technical audiences.
- Strong command of risk analysis frameworks and the ability to derive well-defined mitigation strategies from assessment findings.
- Demonstrated ability to lead and influence without direct authority across cross-functional, matrixed organizations.
- Superior organizational and process management skills; experience building and scaling high-performing teams.
- Proficiency with Third Party Risk platforms (e.g., Archer, SecurityScorecard, ServiceNow, BlackKite) and GRC tooling.
- Integration and adoption of AI-based tooling to facilitate time to market and defensible results.
Education
- Bachelor’s degree or equivalent experience (High School Diploma and 4 years relevant experience).
Pay Range
The typical pay range for this role is:
$144,200.00 - $288,400.00
This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.
Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
Great benefits for great people
We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.
This full-time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well-being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.
Additional details about available benefits are provided during the application process and on Benefits Moments.
We anticipate the application window for this opening will close on: 07/06/2026
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.
See all 10,075+ Security Operations Manager Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Security Operations Manager roles.
Get Access To All JobsTips for Finding Visa Sponsorship as a Security Operations Manager
Target industries with established sponsorship track records
Finance, defense contracting, healthcare systems, and enterprise tech companies sponsor Security Operations Manager roles most consistently. These sectors face persistent talent shortages in security leadership and have legal and compliance infrastructure already in place to process visa petitions.
Frame your degree field carefully on applications
H-1B eligibility requires the role to be a specialty occupation. A degree in computer science, cybersecurity, information systems, or electrical engineering maps cleanly. Unrelated degrees raise questions, so lead with certifications like CISSP or CISM alongside your academic background.
Emphasize SOC leadership over technical execution
Sponsors aren't hiring for hands-on analysis alone. Applications that highlight team management, incident response program ownership, and cross-functional stakeholder coordination position you for manager-level roles that justify sponsorship more clearly than individual contributor framing does.
Engage employers early about their sponsorship history
Before investing weeks in an application, ask whether the company has sponsored H-1B or O-1 visas for security roles before. Employers with no prior sponsorship experience often underestimate the process and back out late, wasting your time and theirs.
Build evidence for an O-1A if you have notable achievements
Security Operations Managers with published research, conference presentations, or recognized incident response leadership may qualify for the O-1A visa. This bypasses the H-1B lottery entirely and suits candidates with a demonstrable record of distinction in the security field.
Use Migrate Mate to filter for verified sponsoring employers
Most job boards don't surface sponsorship status reliably. Migrate Mate lists security roles from employers with confirmed sponsorship histories, letting you spend your search time on companies already willing to sponsor rather than guessing from generic postings.
Frequently Asked Questions
Does a Security Operations Manager role qualify as an H-1B specialty occupation?
Yes, when the job description requires a bachelor's degree or higher in a specific field like cybersecurity, computer science, or information systems. The key is that the degree requirement must be specific, not general. If the posting says 'any bachelor's degree,' that weakens the specialty occupation argument. Roles tied to a defined technical discipline pass USCIS scrutiny more reliably.
Which employers most commonly sponsor Security Operations Managers?
Financial institutions, defense contractors, large healthcare systems, and enterprise technology companies sponsor these roles most frequently. These sectors face regulatory pressure around security compliance, creating persistent demand for experienced security leadership that domestic hiring alone can't fill. Browse verified sponsoring employers on Migrate Mate to focus your search on companies with a demonstrated track record.
Can I get H-1B sponsorship as a Security Operations Manager without a computer science degree?
Possibly, but it requires more documentation. USCIS allows three years of specialized work experience to substitute for one year of formal education. Relevant certifications like CISSP, CISM, or CISA also strengthen your case. However, the employer's petition must still demonstrate the role normally requires a degree-equivalent level of specialized knowledge, which your experience record needs to support.
How does the H-1B lottery affect Security Operations Manager candidates?
All cap-subject H-1B visa petitions enter the annual lottery, where selection rates have hovered around 25% in recent years. If you're not selected, cap-exempt alternatives include employers like universities, nonprofit research organizations, and certain government entities. The O-1A visa is another path that bypasses the lottery entirely for candidates with demonstrable recognition in the security field.
What visa options exist for Security Operations Managers who don't win the H-1B lottery?
Several alternatives apply. The O-1A works for candidates with significant achievements, such as published research, conference speaking, or recognized leadership on major incident response efforts. L-1 visas apply if you're being transferred from an overseas office. TN visas cover Canadian and Mexican nationals in qualifying roles. Some managers extend OPT or pursue employer-sponsored green cards through the EB-2 or EB-3 categories.
What is the prevailing wage requirement for sponsored Security Operations Manager jobs?
U.S. employers sponsoring a visa must pay at least the prevailing wage, which is what workers in the same role, area, and experience level typically earn. The Department of Labor sets this rate to make sure companies aren't hiring foreign workers simply because they'd accept lower pay than a U.S. worker. It varies by job title, location, and experience. You can look up current prevailing wage rates for any occupation and location using the OFLC Wage Search page.