Incident Manager Jobs in USA with Visa Sponsorship
Incident Manager roles attract H-1B, TN, and L-1 visa sponsorship from large tech and financial services employers. Most positions require a bachelor's degree in information technology, computer science, or a related field, qualifying as a specialty occupation under USCIS guidelines. For detailed occupation requirements, see the O*NET profile.
See All Incident Manager JobsOverview
Showing 5 of 45+ Incident Manager jobs


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?
See all 45+ Incident Manager jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Incident Manager roles.
Get Access To All Jobs
INTRODUCTION
Wintrust provides community and commercial banking, specialty finance and wealth management services through its 16 bank charters and nine non-bank businesses. Wintrust delivers the sophisticated solutions of a large bank while staying true to the relationship-focused, personalized service of our community banking roots. We serve clients in all 50 states with more than 200 branch banking locations in Illinois, southwestern Florida, northwestern Indiana, west Michigan and southern Wisconsin and commercial banking offices in Chicago, Denver, Milwaukee, Grand Rapids, Mich., and in key branch banking locations throughout Illinois. Our people are the heart of our business and we are proud to rank consistently as a top place to work. Wintrust is a $66 billion financial institution based in Rosemont, Illinois, and listed on the NASDAQ Global Select Market under the symbol “WTFC.”
Why join us?
- An award-winning culture! We are rated a Top Workplace by the Chicago Tribune (past 12 years) and Employee Recommended award by the Globe & Mail (past 6 years)
- Competitive pay and discretionary or incentive bonus eligible
- Comprehensive benefit package including medical, dental, vision, life, a 401k plan with a generous company match and tuition reimbursement to name a few
- Promote from within culture
Why join this team?
- This position has the opportunity to interface with and have a positive impact on multiple areas of Wintrust's business
- We hold ourselves accountable to high standards, share wins, operate ethically, and have fun
Position Overview
The Cybersecurity Incident Manager is a senior technical contributor within the Security Operations Center responsible for owning and coordinating escalated cybersecurity incidents from detection through resolution. This role ensures that high-severity threats are investigated, contained, and remediated effectively while minimizing business impact. The Cybersecurity Incident Manager serves as a subject-matter expert for incident response & forensics, provides advanced analysis support to L1/L2 analysts, and drives improvements in incident handling processes and documentation.
What You’ll Do
- Incident Response & Coordination – Lead and manage escalated cybersecurity incidents and major events, coordinating analysis, containment, remediation, and recovery across technical teams. Act as escalation point for complex incidents and serve as subject matter expert during active threat handling
- Forensics – Perform in-depth incident analysis & using SIEM, EDR/XDR, and forensic tools
- Documentation & Reporting – Document incident timelines, technical findings, decisions, and remediation steps. Produce detailed post-incident reports, contribute to post-incident reviews, and communicate actionable insights to stakeholders
- Process & Playbook Development – Maintain and improve incident response playbooks, standard operating procedures (SOPs), and runbooks. Work with SOC leadership to evolve response workflows based on lessons learned and emerging threats
- Knowledge Sharing, Mentorship, and Continuous Improvement – Provide technical guidance and mentoring to L1/L2 analysts, help refine escalation criteria and foster consistent incident handling practices. Identify gaps in detection and response capabilities. Collaborate with team to enhance alerts, automations, and defensive measures. Contribute to SOC initiatives like tabletop exercises and capability evaluations
Qualifications
- Bachelor’s degree or equivalent experience
- 5+ years of forensics and incident response experience
- Experience working with CrowdStrike tools
- Detection engineering experience
- Investigation experience
Benefits
- Medical Insurance
- Dental
- Vision
- Life insurance
- Accidental death and dismemberment
- Short-term and long-term Disability Insurance
- Parental Leave
- Employee Assistance Program (EAP)
- Traditional and Roth 401(k) with company match
- Flexible Spending Account (FSA)
- Employee Stock Purchase Plan at 5% discount
- Critical Illness Insurance
- Accident Insurance
- Transportation and Commuting Benefits
- Banking Benefits
- Pet Insurance
Compensation
The estimated salary range for this role is $130,000.00 - $160,000.00, along with eligibility to earn an annual bonus. Actual salaries may vary based on several factors, such as a candidate’s qualifications, skills and experience.
From our first day in business, Wintrust has been proud to serve a variety of unique communities and people from all walks of life. To build a company that reflects the communities we serve, we believe that fostering a unique and inclusive workplace where everyone feels valued and empowered to succeed will support our ongoing success.
Wintrust Financial Corporation, including community banking and financial services subsidiaries, is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information, and other legally protected categories.

INTRODUCTION
Wintrust provides community and commercial banking, specialty finance and wealth management services through its 16 bank charters and nine non-bank businesses. Wintrust delivers the sophisticated solutions of a large bank while staying true to the relationship-focused, personalized service of our community banking roots. We serve clients in all 50 states with more than 200 branch banking locations in Illinois, southwestern Florida, northwestern Indiana, west Michigan and southern Wisconsin and commercial banking offices in Chicago, Denver, Milwaukee, Grand Rapids, Mich., and in key branch banking locations throughout Illinois. Our people are the heart of our business and we are proud to rank consistently as a top place to work. Wintrust is a $66 billion financial institution based in Rosemont, Illinois, and listed on the NASDAQ Global Select Market under the symbol “WTFC.”
Why join us?
- An award-winning culture! We are rated a Top Workplace by the Chicago Tribune (past 12 years) and Employee Recommended award by the Globe & Mail (past 6 years)
- Competitive pay and discretionary or incentive bonus eligible
- Comprehensive benefit package including medical, dental, vision, life, a 401k plan with a generous company match and tuition reimbursement to name a few
- Promote from within culture
Why join this team?
- This position has the opportunity to interface with and have a positive impact on multiple areas of Wintrust's business
- We hold ourselves accountable to high standards, share wins, operate ethically, and have fun
Position Overview
The Cybersecurity Incident Manager is a senior technical contributor within the Security Operations Center responsible for owning and coordinating escalated cybersecurity incidents from detection through resolution. This role ensures that high-severity threats are investigated, contained, and remediated effectively while minimizing business impact. The Cybersecurity Incident Manager serves as a subject-matter expert for incident response & forensics, provides advanced analysis support to L1/L2 analysts, and drives improvements in incident handling processes and documentation.
What You’ll Do
- Incident Response & Coordination – Lead and manage escalated cybersecurity incidents and major events, coordinating analysis, containment, remediation, and recovery across technical teams. Act as escalation point for complex incidents and serve as subject matter expert during active threat handling
- Forensics – Perform in-depth incident analysis & using SIEM, EDR/XDR, and forensic tools
- Documentation & Reporting – Document incident timelines, technical findings, decisions, and remediation steps. Produce detailed post-incident reports, contribute to post-incident reviews, and communicate actionable insights to stakeholders
- Process & Playbook Development – Maintain and improve incident response playbooks, standard operating procedures (SOPs), and runbooks. Work with SOC leadership to evolve response workflows based on lessons learned and emerging threats
- Knowledge Sharing, Mentorship, and Continuous Improvement – Provide technical guidance and mentoring to L1/L2 analysts, help refine escalation criteria and foster consistent incident handling practices. Identify gaps in detection and response capabilities. Collaborate with team to enhance alerts, automations, and defensive measures. Contribute to SOC initiatives like tabletop exercises and capability evaluations
Qualifications
- Bachelor’s degree or equivalent experience
- 5+ years of forensics and incident response experience
- Experience working with CrowdStrike tools
- Detection engineering experience
- Investigation experience
Benefits
- Medical Insurance
- Dental
- Vision
- Life insurance
- Accidental death and dismemberment
- Short-term and long-term Disability Insurance
- Parental Leave
- Employee Assistance Program (EAP)
- Traditional and Roth 401(k) with company match
- Flexible Spending Account (FSA)
- Employee Stock Purchase Plan at 5% discount
- Critical Illness Insurance
- Accident Insurance
- Transportation and Commuting Benefits
- Banking Benefits
- Pet Insurance
Compensation
The estimated salary range for this role is $130,000.00 - $160,000.00, along with eligibility to earn an annual bonus. Actual salaries may vary based on several factors, such as a candidate’s qualifications, skills and experience.
From our first day in business, Wintrust has been proud to serve a variety of unique communities and people from all walks of life. To build a company that reflects the communities we serve, we believe that fostering a unique and inclusive workplace where everyone feels valued and empowered to succeed will support our ongoing success.
Wintrust Financial Corporation, including community banking and financial services subsidiaries, is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information, and other legally protected categories.
How to Get Visa Sponsorship as an Incident Manager
Target large enterprises and managed service providers
Companies running 24/7 operations, banks, cloud providers, healthcare systems, sponsor Incident Managers most frequently. Smaller firms rarely have the legal infrastructure to support visa petitions, so focus your search on established organizations with dedicated HR and immigration teams.
Frame your degree as directly tied to the role
USCIS requires a specific degree field, not just any bachelor's. Emphasize how your IT, computer science, or engineering degree maps to incident management responsibilities like systems analysis, root cause investigation, and service restoration when speaking with employers or attorneys.
Highlight ITIL or equivalent certifications prominently
ITIL 4, PMP, or AWS certifications signal industry-standard competency and help employers justify the specialty occupation requirement. Petitions supported by recognized credentials alongside your degree face fewer requests for evidence from USCIS adjudicators reviewing IT management roles.
Clarify your work authorization status early in conversations
Employers unfamiliar with sponsorship often exit conversations once costs are raised. Addressing your visa timeline, current status, and the H-1B process concisely and confidently early in screening calls reduces drop-off before interviews reach hiring managers who actually make sponsorship decisions.
Prioritize companies with prior H-1B filing history for this role
Employers who have sponsored Incident Managers before have existing LCA templates, attorney relationships, and internal approval workflows. Their petitions move faster and face fewer administrative hurdles. Public DOL disclosure data confirms which companies have filed for this specific occupation previously.
Understand the LCA prevailing wage tier before negotiating
Your employer must file a Labor Condition Application certifying your offered wage meets the prevailing wage for your location and role level. Knowing which wage tier your experience maps to helps you evaluate offers accurately and confirms the employer is meeting their legal obligations.
Incident Manager jobs are hiring across the US. Find yours.
Find Incident Manager JobsSee all 45+ Incident Manager jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Incident Manager roles.
Get Access To All JobsFrequently Asked Questions
Do Incident Manager roles qualify for H-1B visa sponsorship?
Yes, Incident Manager positions generally qualify as specialty occupations under H-1B requirements when the role requires a bachelor's degree or higher in a specific technical field such as information technology, computer science, or systems engineering. Roles involving process management without a technical degree requirement can face scrutiny, so the job description's degree language matters considerably.
Which visa types are most commonly sponsored for Incident Manager positions?
H-1B is the most common path for Incident Managers from countries without treaty-based visa options. Canadians and Mexicans may qualify for TN status under the Computer Systems Analyst category, which is faster and cap-exempt. Australians can pursue the E-3 visa. L-1B is available for intracompany transferees with specialized knowledge of the sponsoring employer's systems and processes.
What degree do I need for an employer to sponsor my visa as an Incident Manager?
Most successful H-1B petitions for Incident Managers are supported by a bachelor's degree in information technology, computer science, information systems, or engineering. Degrees in business or general management are harder to defend unless the role description explicitly requires technical coursework. If your degree field doesn't match cleanly, three years of relevant specialized work experience can substitute for each year of missing education.
How competitive is H-1B sponsorship for Incident Managers compared to software engineers?
Incident Managers face the same H-1B lottery odds as any other occupation, roughly 25% selection in recent years for cap-subject registrations. However, fewer employers proactively list Incident Manager roles as sponsored positions, so competition for willing sponsors is real. Cap-exempt employers such as universities and nonprofit research organizations are worth targeting if lottery timing is a concern. Browse Migrate Mate to find roles with confirmed sponsorship.
Can I transfer my H-1B to a new employer if I change Incident Manager roles?
Yes. H-1B portability allows you to start working for a new employer as soon as the new petition is filed with USCIS, without waiting for approval, provided you've been maintaining valid H-1B status. The new employer files a fresh I-129 petition. Your job duties, title, and degree requirements need to continue satisfying specialty occupation criteria, which Incident Manager roles generally do when documented correctly.
What is the prevailing wage requirement for sponsored Incident Manager jobs?
U.S. employers sponsoring a visa must pay at least the prevailing wage, which is what workers in the same role, area, and experience level typically earn. The Department of Labor sets this rate to make sure companies aren't hiring foreign workers simply because they'd accept lower pay than a U.S. worker. It varies by job title, location, and experience. You can look up current prevailing wage rates for any occupation and location using the OFLC Wage Search page.
See which Incident Manager employers are hiring and sponsoring visas right now.
Search Incident Manager Jobs