H-1B Visa Incident Response Engineer Jobs
Incident Response Engineer roles sit squarely within H-1B visa specialty occupation territory, requiring at least a bachelor's degree in computer science, cybersecurity, or a related field. Employers in financial services, defense contracting, and enterprise tech are among the most active H-1B sponsors for this title, and the role's STEM classification supports cap-exempt employer pathways at qualifying research institutions.
Find H-1B Visa Incident Response Engineer JobsOverview
Showing 5 of 36+ Incident Response Engineer jobs










See all 36+ Incident Response Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Incident Response Engineer roles.
Get Access To All Jobs
DESCRIPTION
If you are interested in this position, please apply on Twitch's Career site.
About Us:
Twitch is the world’s biggest live streaming service, with global communities built around gaming, entertainment, music, sports, cooking, and more. It is where thousands of communities come together for whatever, every day.
We’re about community, inside and out. You’ll find coworkers who are eager to team up, collaborate, and smash (or elegantly solve) problems together. We’re on a quest to empower live communities, so if this sounds good to you, see what we’re up to on LinkedIn and X, and discover the projects we’re solving on our Blog. Be sure to explore our Interviewing Guide to learn how to ace our interview process.
ABOUT THE ROLE
Twitch is looking for a Security Incident Response Engineer to join our SIRT. Reporting to the SIRT Manager, you'll be at the heart of our mission to find, handle, and learn from security incidents across our global platform. We're looking for engineers who thrive coordinating response to emerging issues in information security who are ready to level up our defense. If you're passionate about protecting the Twitch community and solving complex security puzzles, we want to hear from you!
You can work from San Francisco, CA; Irvine, CA; or Seattle, WA.
YOU WILL
- Participate in an on-call rotation that includes your peers on the Security Incident Response Team
- Qualify reports or alerts of activity as security incidents using clear guidelines that establish what a security incident is
- Evaluate the potential and realized impact of security incidents to Twitch
- Analyze threat actor tactics, techniques, and procedures
- Participate or create information sharing groups; communicate securely and responsibly
- Write and follow clear procedures so that our work can be accountable, repeated, measured, and improved
- Communicate with peers and leadership about timeline of a security related event with what potential and realized impact, how we discovered it, and how we're handling it
- Coordinate security incident response activities with affected teams to do the right thing for our customers and our organization
- Investigate, document, and implement agentic detection, enrichment, triage, response, and communication automations in every day processes
- Lead lessons learned discussions and help teams effect change across the business that reduces incident recurrence
PERKS
- Medical, Dental, Vision & Disability Insurance
- 401(k)
- Maternity & Parental Leave
- Flexible PTO
- Amazon Employee Discount
BASIC QUALIFICATIONS
- 3+ years of information security and compliance experience, or Bachelor's degree in computer science, engineering, analytics, mathematics, statistics, IT or equivalent
- Automation experience using scripting or programming languages (Go, Python, Ruby, Shell, or Perl)
- Ability to securely design and implement AI/ML-driven playbooks to automate common security operations
- Experience coordinating responses to security incidents
- Knowledge of security issues and threat landscape
- Background in cloud, host, network, and application security
- Familiarity with common Incident Response frameworks or lifecycle models like NIST-800-61, ISO/IEC 27035, etc.
PREFERRED QUALIFICATIONS
- B.S. or M.S. in Computer Science, Computer Engineering, Software Security, or a related technical discipline
- Experience and familiarity with streaming and content creation
- Experience handling security incidents in hybrid cloud environment (AWS, GCP) and conducting log dives on cloud telemetry like CloudTrail
- Passion and excitement for Twitch
Twitch is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave.
- USA, CA, IRVINE - 159,300.00 - 202,400.00 USD annually
- USA, CA, SAN FRANCISCO - 166,600.00 - 212,800.00 USD annually
- USA, WA, Seattle - 159,300.00 - 202,400.00 USD annually
See all 36+ H-1B Visa Incident Response Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new H-1B Visa Incident Response Engineer Jobs.
Get Access To All JobsTips for Finding H-1B Visa Sponsorship as an Incident Response Engineer
Align your credentials to SOC code 15-1212
Incident Response Engineers are typically classified under SOC 15-1212 (Information Security Analysts) for LCA purposes. Confirm your degree field maps to cybersecurity or computer science before applying, since a mismatched specialty can trigger an RFE during adjudication.
Verify prevailing wage before accepting offers
Use the OFLC Wage Search to check the Level I through Level IV wage for SOC 15-1212 in the employer's metro area. Your offered salary must meet or exceed the certified LCA wage, and underpayment is one of the most common DOL audit triggers for this occupation.
Target employers with active clearance programs
Defense contractors and federal system integrators that sponsor security clearances often prefer sponsoring H-1B holders directly rather than using staffing firms, since clearance continuity matters. Filing through a direct employer also reduces the risk of controlled-unclassified-information restrictions complicating your petition.
Use Migrate Mate to find verified H-1B sponsors
Search Incident Response Engineer roles on Migrate Mate to filter specifically for employers with confirmed H-1B LCA filing history in cybersecurity and information security titles, so you're not cold-applying to companies with no sponsorship track record.
Request premium processing before your start date
USCIS premium processing guarantees a 15-business-day adjudication decision. For Incident Response roles, where security incidents don't wait for visa timelines, asking your employer to file with premium processing protects both sides if onboarding needs to align with an active incident program.
Document hands-on tools in your support letter
USCIS officers reviewing cybersecurity petitions increasingly scrutinize whether the role genuinely requires a specialized degree. Your employer's support letter should tie specific incident response platforms, forensic toolsets, and threat-intelligence frameworks directly to the degree requirement to preempt specialty occupation RFEs.
H-1B Visa Incident Response Engineer: Frequently Asked Questions
Does an Incident Response Engineer role qualify as an H-1B specialty occupation?
Yes. Incident Response Engineers typically qualify under the H-1B specialty occupation standard because the role normally requires at least a bachelor's degree in computer science, cybersecurity, information systems, or a closely related field. USCIS evaluates the specific job duties and the employer's actual requirements, so the offer letter and support letter should explicitly state the degree requirement rather than listing it as preferred.
Which industries sponsor H-1B visas most consistently for Incident Response Engineers?
Financial services firms, enterprise technology companies, federal contractors, managed security service providers, and cloud infrastructure companies are among the most consistent H-1B sponsors for this title. These employers file LCAs under DOL regularly for information security roles and tend to have established immigration programs. You can browse employer-specific filing history for Incident Response Engineer roles on Migrate Mate before applying.
Can I work for a cap-exempt employer as an Incident Response Engineer on H-1B?
Yes, if the employer qualifies. Universities, nonprofit research institutions affiliated with universities, and certain government research organizations are cap-exempt, meaning your employer can file an H-1B petition outside the annual lottery. Cybersecurity and incident response functions at these institutions, such as university security operations centers or research lab threat teams, can support a cap-exempt filing if the role is tied to the institution's core mission.
What happens to my H-1B status if I'm laid off from an Incident Response Engineer position?
You have a 60-day grace period after your employment ends to find a new sponsoring employer, file a change of status, or take another action to maintain lawful status. During that window, a new employer can file an H-1B transfer petition using portability rules under AC21, allowing you to start work once the transfer is filed, not just approved. Acting within the first 30 days gives you the most flexibility.
How does the H-1B prevailing wage requirement affect offers for Incident Response Engineers?
Before filing your H-1B petition, your employer must obtain a certified LCA from DOL confirming your offered salary meets the prevailing wage for the Incident Response Engineer or Information Security Analyst role in the specific work location. The wage level (I through IV) reflects your experience, and your actual offer must match or exceed it. You can verify the applicable wage range using the OFLC Wage Search before negotiating your offer.