EB-1A for Cybersecurity Experts
Cybersecurity evidence is often classified, ephemeral, or sensitive. The strongest petitions convert that work into durable public proof — CVEs, published research, standards participation, and independent recognition from the security community.
Built for: Security researchers, incident responders, threat-intelligence leads, and application-security engineers.
Evidence matrix: your work mapped to USCIS criteria
Each row converts routine professional output into a packaged exhibit an adjudicator can score.
Daily work
Discovering and responsibly disclosing vulnerabilities or exploits
USCIS criterion
Original contributions of major significanceEvidence packaging
CVE records, vendor acknowledgments, bug-bounty rankings, and expert letters explaining the technical impact and reach of the findings.
Daily work
Publishing security research, tools, or frameworks the community adopts
USCIS criterion
Authorship of scholarly articles / published materialEvidence packaging
Publication record, tool download or GitHub star metrics, and citations or references from other researchers.
Daily work
Serving as a reviewer for security conferences or journals
USCIS criterion
Judging the work of othersEvidence packaging
Reviewer invitations, OpenReview or conference records, and chair confirmation of reviewer selection standards.
Daily work
Leading security for a high-profile product, platform, or organization
USCIS criterion
Critical role for distinguished organizationsEvidence packaging
Org placement, scope of systems protected, incident outcomes, and evidence the organization is distinguished.
Daily work
Participating in standards bodies like NIST, ISO, or OWASP
USCIS criterion
Membership requiring outstanding achievementEvidence packaging
Membership bylaws, meeting records, and letters documenting your contribution to adopted standards or frameworks.
Daily work
Top-decile compensation for cybersecurity roles in your metro
USCIS criterion
High remunerationEvidence packaging
Total-comp statements benchmarked against BLS/OES 90th percentile data for information security analysts or related occupations.
High remuneration benchmarks
Indicative BLS/OES-style 90th percentile total compensation for this occupation by metro. Your petition must compare your compensation against the correct occupation code and location.
$255,000
Bay Area — 90th percentile
$228,000
New York City — 90th percentile
$241,000
Seattle — 90th percentile
RFE mitigation for this profile
Where USCIS pushes back
Cybersecurity experts often get the 'operational defender, not field leader' objection. USCIS accepts you protected systems but questions whether you advanced the field. Mitigate by foregrounding public research, community-adopted tools, standards participation, and independent expert testimony that your methods are used beyond your employer.
Frequently asked questions
Related visa guides
See where your profile stands today
Run the free profile audit and get a criterion-by-criterion read on your EB-1A eligibility, tuned to your role.