All articles

Work Authorization

Formulating H-1B Specialty Occupation Cases for Okta and Ping IAM Specialists

An H-1B specialty occupation case succeeds or fails on a single question: does this position normally require the theoretical and practical application of a body of highly specialised knowledge, evidenced by at least a bachelor's degree in a specific field? For an Okta or PingFederate engineer, the honest answer is yes. The difficulty is that petitions are often written in generic IT vocabulary that conceals exactly the specialisation the standard is asking about.

Describe the role in protocol terms, not tool terms

A description that reads 'administers identity software and resets user accounts' invites a denial, because it describes administrative work. A description that reads 'designs SAML 2.0 and OpenID Connect federation topologies, defines token lifetimes and claim transformation logic, models authorisation policy against regulatory control frameworks, and engineers SCIM-based provisioning between authoritative HR sources and downstream applications' describes applied computer science.

Both sentences can describe the same person. Only one shows the body of specialised knowledge involved. The petition should read like the architecture document the engineer would actually write.

Establish the degree nexus explicitly

The connection between the degree field and the duties should be drawn duty by duty. Cryptographic trust relationships, certificate lifecycle handling and signature validation map to coursework in cryptography and network security. Directory schema design, replication topology and query optimisation map to database systems. Policy modelling and least-privilege design map to formal access-control theory.

Where the role genuinely accepts several closely related fields — computer science, cybersecurity, information systems — say so and explain why each is directly related to the specific duties, rather than presenting a broad list that implies no particular field is required.

Evidence beyond the job description

Supporting evidence carries real weight: industry job postings for comparable identity engineering roles that require a specific degree, organisational charts showing where the role sits within a security function, and expert opinion letters from academics who can speak to the required knowledge base. Platform certifications support the practical side of the argument but do not replace the degree nexus — they reinforce it.

Internal documentation helps too. Architecture diagrams, change records and design reviews demonstrate that the role performs the work described rather than a simplified version of it.

Where cases commonly go wrong

Three weaknesses recur. First, boilerplate duties copied between petitions, which read as generic and are easy to challenge. Second, level-one wage designations attached to duties describing independent architecture ownership — an internal contradiction that draws attention. Third, third-party placement arrangements without clear documentation of who directs and controls the work.

None of these are unfixable, but all of them are far cheaper to address before filing than after a request for evidence lands.

Key takeaways

  • Write duties in protocol and architecture language, not administrative language.
  • Connect specific coursework to specific duties rather than asserting a general degree requirement.
  • Corroborate with industry postings, org charts and design artefacts; certifications reinforce but do not substitute.
  • Align the wage level with the seniority the duties describe.

Hiring or being hired in IAM?

TagWin Recruiting places Okta, Ping, SailPoint and CyberArk specialists with enterprises that cannot afford an identity gap.

Start an intake

Related articles