STEM OPT Incident Response Engineer Jobs
Incident Response Engineer roles in threat detection, forensic analysis, and security operations qualify for the STEM OPT 24-month extension when your degree maps to an eligible CIP code. Your employer must be enrolled in E-Verify and sign a Form I-983 training plan before your extension begins.
Find STEM OPT Incident Response Engineer JobsOverview
Showing 4 of 6+ Incident Response Engineer jobs








See all Incident Response Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Incident Response Engineer roles.
Get Access To All Jobs
Shape the Future with Dun & Bradstreet
At Dun & Bradstreet, we believe data has the power to create a better tomorrow. As a global leader in business decisioning data and analytics, we help companies worldwide grow, manage risk, and innovate. For over 180 years, businesses have trusted us to turn uncertainty into opportunity. We’re a diverse, global team that values creativity, collaboration, and bold ideas. Are you ready to make an impact and help shape what’s next? Join us! Explore opportunities at dnb.com/careers.
We are seeking a highly skilled Senior Incident Response Analyst to lead advanced threat detection, investigation, and remediation efforts within our Security Operations program. This role is responsible for handling complex security incidents, guiding junior analysts, improving detection capabilities, and strengthening our overall security posture.
The Senior Incident Response Analyst brings deep technical expertise, strong analytical thinking, and a proactive mindset toward defending the enterprise.
Key Responsibilities:
- Lead high‑fidelity alert investigations, performing deep technical analysis to rapidly identify, contain, and remediate threats.
- Own complex incident investigations, driving technically precise conclusions and elevating the organization’s detection and response maturity.
- Champion process development, identifying gaps, designing scalable workflows, and implementing improvements that strengthen the Incident Response program.
- Create and refine technical playbooks, documentation, and response guides, ensuring clarity, consistency, and operational excellence.
- Mentor and uplift junior analysts, providing guidance, coaching, and training to build a high‑performing team.
- Serve as the escalation point for critical and ambiguous cases, applying advanced threat analysis and sound judgment under pressure.
- Collaborate with engineering, IT, Legal, HR, and business partners to resolve incidents holistically and drive enterprise‑wide security improvements.
- Apply strong analytical and technical expertise to continuously enhance SOC processes, workflows, and response capabilities.
- Contribute to the evolution of our detection landscape, partnering with detection engineering to improve log ingestion, alert logic, and signal quality.
- Assess and mitigate AI‑related security risks, including model misuse, prompt injection, data leakage, and emerging automation attack vectors.
- Participate in an on‑call rotation, serving as a trusted responder for high‑severity incidents.
Skills Needed:
- At least 1 SANS/GIAC Certification (GCIH, GREM, GCFA preferred)
- Strong Hands-on experience with
- SIEM Platforms (Splunk, Microsoft sentinel, etc)
- EDR Tools (CrowdStrike, Carbon Black)
- Cloud environments (Azure, AWS, GCP, AliCloud)
- Network log analysis (Netflows and PCAP files)
- Deep understanding of:
- Mitre ATT&CK framework
- Malware behavior and exploitation techniques
- Windows, Linux, and macOS internals
- Script analysis (Javascript, VBscript, powershell, python)
- Malicious binary analysis (Windows, MacOS, Linux)
- Clear communication rooted in technical competence
- Confidence discussing findings with peers and senior management
Education:
Bachelors Degree - Required
Benefits We Offer:
- Generous paid time off in your first year, increasing with tenure.
- Up to 16 weeks 100% paid parental leave after one year of employment.
- Paid sick time to care for yourself or family members.
- Education assistance and extensive training resources.
- Do Good Program: Paid volunteer days & donation matching.
- Competitive 401k with company matching.
- Health & wellness benefits, including discounted Wellhub membership rates.
- Medical, dental & vision insurance for you, spouse/partner & dependents.
All Dun & Bradstreet job postings can be found at https://jobs.lever.co/dnb. Official communication from Dun & Bradstreet will come from an email address ending in @dnb.com.
Notice to Applicants: Please be advised that this job posting page is hosted and powered by Lever, a subsidiary of Employ Inc. Your use of this page is subject to Employ's Privacy Notice and Cookie Policy, which governs the processing of visitor data on this platform.
Equal Employment Opportunity (EEO): Dun & Bradstreet provides equal employment opportunities to applicants and employees without regard to race, color, religion, creed, sex, age, national origin, citizenship status, disability status, sexual orientation, gender identity or expression, pregnancy, genetic information, protected military and veteran status, ancestry, marital status, medical condition (cancer and genetic characteristics) or any other characteristic protected by law. Know Your Rights: Workplace Discrimination is Illegal - The current poster can be found here. We participate in E-Verify - The current poster can be found here.
Accommodations information for applicants with disabilities: Dun & Bradstreet is committed to providing reasonable accommodation to, among others, individuals with disabilities and disabled veterans. If you need an accommodation because of a disability to search and apply for a career opportunity with Dun & Bradstreet, please send an e-mail to AcquisitionT@dnb.com to let us know the nature of your accommodation request and your contact information.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please visit https://bit.ly/3LMn4CQ.
See all STEM OPT Incident Response Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new STEM OPT Incident Response Engineer Jobs.
Get Access To All JobsTips for Finding STEM OPT Authorization as an Incident Response Engineer
Verify your CIP code before applying
Confirm your degree's Classification of Instructional Programs code maps to a STEM-designated field like Computer Science or Information Security. Your DSO can check your I-20 against the official STEM CIP list, a mismatch disqualifies you from the 24-month extension regardless of your job duties.
Screen employers for E-Verify enrollment early
Incident Response Engineer roles often sit inside security or IT operations teams at companies that don't always advertise their E-Verify status. Ask the recruiter directly during a first call, STEM OPT is void if your employer isn't enrolled in E-Verify before your extension start date.
Negotiate your I-983 training plan before accepting
Your employer must complete Form I-983 detailing how your Incident Response duties connect to your STEM degree. Raise this before signing an offer, some hiring managers in security operations have never filed one, and delays getting it signed can push your extension start date.
Use Migrate Mate to target verified sponsors
Search Incident Response Engineer roles on Migrate Mate, which filters for employers with confirmed E-Verify enrollment and active STEM OPT hiring history. This cuts out the manual verification step and surfaces companies already familiar with the I-983 and 24-month extension process.
Map your resume to O*NET's IR Engineer tasks
Pull the Incident Response Engineer occupation profile from O*NET and align your resume skills to its listed tasks: threat containment, forensic investigation, and post-incident reporting. Employers filing STEM OPT extensions reference SOC codes, so matching your experience to standard task language strengthens your I-983 training plan.
Time your H-1B registration around your OPT end date
If your STEM OPT extension runs through an H-1B lottery cycle, cap-gap protection automatically extends your work authorization if you're selected. Submit your registration in March during your final OPT year so any cap-gap gap between October 1 and your extension's expiry is covered by USCIS rules.
Frequently Asked Questions
Does an Incident Response Engineer role qualify for the STEM OPT extension?
Yes, if your underlying degree carries an eligible STEM CIP code and your job duties in threat detection, digital forensics, or security operations directly relate to that field. The role itself doesn't confer eligibility, your degree does. Confirm the CIP code on your I-20 with your DSO before your employer files the I-983 training plan, since USCIS evaluates the degree-to-job connection during any request for evidence.
What does my employer need to do before my STEM OPT extension starts?
Your employer must be enrolled in E-Verify and must sign Form I-983, the Training Plan for STEM OPT Students, before your extension begins. The I-983 requires them to document how your Incident Response duties relate to your STEM degree, set learning objectives, and attest that the position is paid and meets labor standards. You then submit the signed I-983 to your DSO, who issues a new I-20 for the USCIS extension filing.
How do I confirm a company is enrolled in E-Verify before accepting an offer?
Ask the recruiter or HR contact directly whether the company is enrolled in E-Verify. Employers can also be searched through the E-Verify employer search tool maintained by DHS. For security-sector companies that may have government contracts, E-Verify enrollment is often mandatory by federal regulation, but enrollment still needs confirmation, don't assume based on company size or contract status alone.
Which STEM degrees typically support an Incident Response Engineer STEM OPT extension?
Degrees in Computer Science, Information Security, Cybersecurity, Computer Engineering, and Electrical Engineering commonly carry eligible STEM CIP codes. Some programs in Management Information Systems or Applied Mathematics also qualify depending on the specific CIP code your school assigned. A degree titled broadly, like Information Technology, may or may not qualify, so verify the exact CIP code on your I-20 against the DHS STEM Designated Degree Program List before counting on the extension.
Where can I find Incident Response Engineer jobs where employers are already set up to hire STEM OPT students?
Migrate Mate lists Incident Response Engineer positions filtered for employers with E-Verify enrollment and documented STEM OPT hiring activity. That saves you from discovering mid-offer that a company has never processed an I-983 or isn't enrolled in E-Verify. Targeting employers who have already navigated the training plan process significantly reduces the risk of delays between your OPT expiry and extension approval.