The attack surface here is massive: 22 universities, 450,000-plus students, and 56,000 faculty and staff spread across California. California State University isn't just a single network - it's a distributed system of interconnected campuses, each with its own infrastructure, endpoints, and data flows. The threat model spans student data protection, research integrity, and operational continuity across a public institution that handles everything from financial aid records to healthcare information.
Founded in 1960, Cal State operates as the nation's largest four-year public university system. The security challenge scales accordingly: identity and access management across hundreds of thousands of users, endpoint hardening on a budget that isn't venture-backed, and defending against phishing campaigns that target a constantly rotating population of students and staff. The system emphasizes collaboration across campuses, which means security teams aren't siloed - they're coordinating policy, tooling, and incident response across institutional boundaries.
The work runs deep into domains like network segmentation for campus environments, cloud security posture management for increasingly SaaS-dependent operations, and compliance frameworks tied to FERPA, HIPAA (where applicable), and state-level data protection mandates. There's no product to sell - this is about protecting infrastructure that enables teaching, research, and administrative operations at scale. The culture emphasizes inclusive excellence and hands-on learning, which for security teams translates into securing environments that are inherently more open and collaborative than a typical enterprise perimeter.





