Adjudication-grade evidence mapping

EB-1A for Cybersecurity Experts

Cybersecurity evidence is often classified, ephemeral, or sensitive. The strongest petitions convert that work into durable public proof — CVEs, published research, standards participation, and independent recognition from the security community.

Built for: Security researchers, incident responders, threat-intelligence leads, and application-security engineers.

Evidence matrix: your work mapped to USCIS criteria

Each row converts routine professional output into a packaged exhibit an adjudicator can score.

  • Daily work

    Discovering and responsibly disclosing vulnerabilities or exploits

    USCIS criterion

    Original contributions of major significance

    Evidence packaging

    CVE records, vendor acknowledgments, bug-bounty rankings, and expert letters explaining the technical impact and reach of the findings.

  • Daily work

    Publishing security research, tools, or frameworks the community adopts

    USCIS criterion

    Authorship of scholarly articles / published material

    Evidence packaging

    Publication record, tool download or GitHub star metrics, and citations or references from other researchers.

  • Daily work

    Serving as a reviewer for security conferences or journals

    USCIS criterion

    Judging the work of others

    Evidence packaging

    Reviewer invitations, OpenReview or conference records, and chair confirmation of reviewer selection standards.

  • Daily work

    Leading security for a high-profile product, platform, or organization

    USCIS criterion

    Critical role for distinguished organizations

    Evidence packaging

    Org placement, scope of systems protected, incident outcomes, and evidence the organization is distinguished.

  • Daily work

    Participating in standards bodies like NIST, ISO, or OWASP

    USCIS criterion

    Membership requiring outstanding achievement

    Evidence packaging

    Membership bylaws, meeting records, and letters documenting your contribution to adopted standards or frameworks.

  • Daily work

    Top-decile compensation for cybersecurity roles in your metro

    USCIS criterion

    High remuneration

    Evidence packaging

    Total-comp statements benchmarked against BLS/OES 90th percentile data for information security analysts or related occupations.

High remuneration benchmarks

Indicative BLS/OES-style 90th percentile total compensation for this occupation by metro. Your petition must compare your compensation against the correct occupation code and location.

$255,000

Bay Area — 90th percentile

$228,000

New York City — 90th percentile

$241,000

Seattle — 90th percentile

Calculate Your Salary vs 90th Percentile OES

RFE mitigation for this profile

Where USCIS pushes back

Cybersecurity experts often get the 'operational defender, not field leader' objection. USCIS accepts you protected systems but questions whether you advanced the field. Mitigate by foregrounding public research, community-adopted tools, standards participation, and independent expert testimony that your methods are used beyond your employer.

Frequently asked questions

Related visa guides

See where your profile stands today

Run the free profile audit and get a criterion-by-criterion read on your EB-1A eligibility, tuned to your role.