Jobs / United States / Ebay INC
Detection & Response Engineer
Ebay INC · 🇺🇸 Austin
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordThe US Department of Labor certified 478 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 314 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- What Ebay INC paid sponsored hires in similar roles58 certified filings for “MTS 1, Software Engineer” (Software Developers) in TX: $142k–$188k, median $169k. Most were filed at wage level IV (58%) — 4 lottery entries, ≈61% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — Ebay INC
The US Department of Labor certified 478 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 314 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Ebay INC →
About the role
At eBay, we're more than a global ecommerce leader — we’re changing the way the world shops and sells. Our platform empowers millions of buyers and sellers in more than 190 markets around the world. We’re committed to pushing boundaries and leaving our mark as we reinvent the future of ecommerce for enthusiasts. Our customers are our compass, authenticity thrives, bold ideas are welcome, and everyone can bring their unique selves to work — every day. We're in this together, sustaining the future of our customers, our company, and our planet. Join a team of passionate thinkers, innovators, and dreamers — and help us connect people and build communities to create economic opportunity for all. About the team and the role: The Detection & Response team helps protect eBay’s global marketplace by identifying, investigating, and responding to cyber threats across a sophisticated technology environment. This role sits at the center of high-impact security work, partnering closely with the SOC, Global Technology engineering, People Team, Legal, and other security teams to reduce risk and strengthen resilience across the company. As a senior individual contributor, you will work across endpoint, identity, cloud, Kubernetes/container, and network environments to investigate advanced threats, improve detections, and help compose scalable response capabilities. This is an opportunity to influence how eBay detects and responds to modern adversaries, while contributing to automation, threat-informed defense, and continuous improvement across the security program. This role participates in an on-call rotation. What you will accomplish: • Lead high-impact incident response across a wide range of scenarios, including external intrusions, insider threats, and misuse, helping contain risk and restore business operations quickly and optimally. Improve eBay’s ability to detect and respond to threats by building, tuning, and maintaining SIEM detections and alert logic that increase coverage while reducing false positives. • Investigate complex security events end-to-end by reconstructing activity from telemetry, identifying root cause, and driving containment, eradication, and recovery with multi-functional partners. • Apply threat modeling to new systems, infrastructure, and features, translating security risks into practical telemetry, detection, and response requirements for engineering teams. • Proactively hunt for attacker behavior, surface visibility gaps, and turn adversary research into actionable countermeasures, playbooks, and detective controls that strengthen long-term defense. • Develop automation and tooling, including AI- or agent-assisted workflows, to streamline enrichment, triage, evidence collection, and response actions in ways that are safe, auditable, and scalable. What you will bring: • 5+ years of experience in incident response, detection engineering, threat hunting, or a closely related security field, with a track record of leading investigations and improving response operations. • Strong understanding of modern adversary tactics, techniques, and procedures, capable of translating them into practical detections, mitigations, and response strategies. • Hands-on experience across cloud and SaaS environments, with the ability to develop detection approaches that can scale across platforms such as AWS, Azure, and GCP. • Experience working in Kubernetes or containerized environments, including using cluster telemetry to investigate activity and identify common attack paths or failure patterns. • Proven network and digital forensics fundamentals, including analyzing network traffic and applying forensically sound practices during active investigations. • Scripting or automation experience in Python or a similar la