Incident Response Engineer Jobs in USA with Visa Sponsorship
Incident Response Engineers are strong candidates for H-1B visa and O-1 visa sponsorship. The role qualifies as a specialty occupation requiring a computer science or cybersecurity degree, and demand from tech, finance, and defense contractors means sponsorship is realistic for qualified candidates. For detailed occupation requirements, see the O*NET profile.
Find Incident Response Engineer JobsOverview
Showing 5 of 17,612+ Incident Response Engineer jobs










See all 17,612+ Incident Response Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Incident Response Engineer roles.
Get Access To All Jobs
INTRODUCTION
We are currently seeking a Senior Cyber Incident Response Engineer as part of our Enterprise Information Security department. Enterprise Information Security (EIS) is integrated with the Enterprise Technology and Operations division (1100+ technical people) at Zions Bancorporation. EIS is responsible for enabling secure innovation and business growth for 10,000+ employees across 11 states. EIS is undergoing rapid growth and we are focused on creating a relevant program that will enable our organization’s long-term success. What’s great about our department is that we laugh with each other, have Executive and Board level visibility and support for our work, and are driving highly visible, enterprise-wide initiatives. We are focused on creating business value and are seeking like-minded professionals to join our team!
ROLE AND RESPONSIBILITIES
The Senior Cyber Incident Response Engineer will join our CSOC Team. The Cybersecurity Operations Center (CSOC) team is the cyber front line at Zions Bancorporation. If you want to work on a team where your input matters, you get to collaborate with sharp colleagues with whom you will grow, where your work is truly valued and you make a real difference, then you will be in good company.
As a Senior Cyber Incident Response Engineer you will play a key role in defending the enterprise from malicious actors. The work you do has real impact customer-wide and enterprise-wide and it is truly valued by both.
The Senior Cyber Incident Response Engineer will:
- Act as key contributor in the CSOC’s growth and evolution, actively improving our cyber incident response capabilities
- Respond to cybersecurity incidents, especially as an escalation point for high-priority or highly complex incidents
- Function as subject matter expert in multiple cybersecurity tools and processes such as SIEM, IDS, EDR, DLP, WAF and similar
- Develop and implement monitoring use cases, cyber incident response procedures, playbooks and other technical documentation
- Collaborate with Enterprise Cybersecurity Architecture and technology teams in monitoring and alerting infrastructure, processes, and tools
- Train, mentor and guide other team members (across both the CSOC and other EIS teams) on cyber incident response practices, tooling, and capabilities
- Participate in the on-call rotation so we can maintain 24/7 coverage in responding to alerts and possible threats
- Other duties as assigned
BASIC QUALIFICATIONS
- Hands-on technical experience with one or more commercial SIEM products such as Splunk (preferred), IBM QRadar, LogRhythm, ArcSight, NetWitness, etc., which should include familiarity with defining and writing alert conditions/use cases in addition to daily use for investigating incidents
- Experience producing technical documentation, standard operating procedures, and incident response playbooks
- Expert technical knowledge in networking, Windows administration, Linux administration, common attack techniques and preventions
- Advanced working knowledge of common attack vectors, different classes of attacks (e.g., passive, active, insider, close-in, distributed, etc.) and general attack stages (e.g., foot printing and scanning, enumeration, gaining access, escalation or privileges, maintaining access, network exploitation, covering tracks, etc.)
- Advanced knowledge of system administration concepts for UNIX/Linux and Windows operating systems
- Development experience with scripting languages such as R, HIVE, Python, JavaScript, etc., is a plus
- Experience with any Endpoint Detection and Response platform is a plus
- Relevant advanced technical certifications are a plus (ex: SANS, ISC2) with 5+ years of relevant experience in one or more technical cybersecurity domains (combination of education and experience, such as 6-8 years of relevant experience or equivalent education may meet qualifications)
LOCATION
This position has a hybrid work from home schedule with a minimum of three days per week in the office at the new Zions Technology Center in Midvale, UT
The Zions Technology Center is a 400,000-square-foot technology campus in Midvale, Utah. Located on the former Sharon Steel Mill superfund site, the sustainably built campus is the company’s primary technology and operations center. This modern and environmentally friendly technology center enables Zions to compete for the best technology talent in the state while providing team members with an exceptional work environment with features such as:
- Electric vehicle charging stations and close proximity to Historic Gardner Village UTA TRAX station.
- At least 75% of the building is powered by on-site renewable solar energy.
- Access to outdoor recreation, parks, trails, shareable bikes and locker rooms.
- Large modern cafe with a healthy and diverse menu.
- Healthy indoor environment with ample natural light and fresh air.
- LEED-certified sustainable building that features include the use of low VOC-emitting construction materials.
BENEFITS
- Medical, Dental and Vision Insurance - START DAY ONE!
- Life and Disability Insurance, Paid Parental Leave and Adoption Assistance
- Health Savings (HSA), Flexible Spending (FSA), and dependent care accounts
- Paid Training, Paid Time Off (PTO) and 11 Paid Federal Holidays
- 401(k) plan with company match, Profit Sharing, competitive compensation in line with work experience
- Mental health benefits including coaching and therapy sessions
- Tuition Reimbursement for qualifying employees
- Employee Ambassador preferred banking products
See all 17,612+ Incident Response Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Incident Response Engineer roles.
Get Access To All JobsTips for Finding Visa Sponsorship as an Incident Response Engineer
Target sectors with established sponsorship history
Large financial institutions, cloud providers, and defense contractors sponsor Incident Response Engineers regularly. These employers have dedicated immigration teams and file H-1B petitions as a standard part of hiring, making them far more predictable sponsors than mid-market companies.
Document your degree-to-role alignment carefully
USCIS scrutinizes specialty occupation claims for security roles. A degree in computer science, cybersecurity, or information systems maps cleanly. If your degree is in a related field, prepare a credentials evaluation letter that connects your coursework directly to incident response work.
Certifications strengthen your petition significantly
CISSP, GCIH, CEH, and GCFE certifications signal industry-recognized competency and support the specialty occupation argument. Employers filing your H-1B petition benefit from petitions that include evidence beyond your degree, particularly if your role involves forensics or threat hunting.
Clarify scope before accepting an offer
Incident response roles vary widely. Some are purely reactive; others involve proactive threat hunting or red team collaboration. The job description submitted to USCIS must reflect a consistent, specialized scope. Vague or generalist descriptions raise RFE risk, so clarify duties early in the process.
Consider O-1A if you have a strong public profile
Published research, CVE disclosures, conference presentations at DEF CON or Black Hat, or peer-reviewed work in threat intelligence can support an O-1A petition. This path bypasses the H-1B lottery entirely and is worth discussing with an immigration attorney if your profile qualifies.
Clearance eligibility can expand your employer pool
Many federal contractors require security clearance eligibility for incident response roles. As a green card holder or on certain visa statuses, clearance eligibility opens government-adjacent employers that sponsor aggressively and often file cap-exempt H-1B petitions through affiliated research institutions.
Frequently Asked Questions
Does an Incident Response Engineer role qualify as a specialty occupation for H-1B purposes?
Yes, incident response engineering qualifies as a specialty occupation when the position requires at minimum a bachelor's degree in computer science, cybersecurity, information systems, or a closely related field. USCIS has approved H-1B visa petitions for this role consistently, though petitions that describe generalist IT duties rather than specialized security work are more likely to receive a Request for Evidence. The job description must establish that a specific degree is a normal minimum requirement for the position.
Which visa types are most common for Incident Response Engineers seeking sponsorship?
The H-1B is the most common path. The TN visa is available for Canadian and Mexican nationals if the role fits squarely within a qualifying USMCA category such as computer systems analyst. The O-1A is an option for engineers with documented recognition in the cybersecurity field, including published research, CVE credits, or speaking history at major security conferences. L-1B is available for intracompany transfers with specialized knowledge.
What if my degree is in a field other than computer science or cybersecurity?
A directly related degree is not always required, but the connection must be defensible. Degrees in electrical engineering, mathematics, or management information systems have supported specialty occupation arguments when paired with strong work experience and a credentials evaluation. If your degree is in an unrelated field, three years of progressive work experience can substitute for each year of missing education, but the combination must clearly support the specialized nature of the role.
How can I find Incident Response Engineer jobs that offer visa sponsorship?
Migrate Mate filters job listings specifically by visa sponsorship availability, so you can browse incident response roles where employers have already indicated willingness to sponsor. This is more reliable than applying broadly and asking about sponsorship later, which wastes time on companies that won't sponsor or have no immigration infrastructure in place.
Are H-1B approval rates for cybersecurity roles affected by recent policy changes?
USCIS denial and RFE rates for cybersecurity roles increased during periods of heightened scrutiny around specialty occupation definitions, particularly for roles with broad or ambiguous job duties. Petitions that clearly establish a specific degree requirement, define specialized tasks, and include supporting evidence from the employer tend to perform better. Working with an experienced immigration attorney to draft the petition is worth the investment given the scrutiny this category can attract.
What is the prevailing wage requirement for sponsored Incident Response Engineer jobs?
U.S. employers sponsoring a visa must pay at least the prevailing wage, which is what workers in the same role, area, and experience level typically earn. The Department of Labor sets this rate to make sure companies aren't hiring foreign workers simply because they'd accept lower pay than a U.S. worker. It varies by job title, location, and experience. You can look up current prevailing wage rates for any occupation and location using the OFLC Wage Search page.