Chestnut Hill College is a private Catholic institution founded in 1924 in the Chestnut Hill neighborhood of Philadelphia, Pennsylvania. With approximately 1,500 students and a 75-acre campus, it operates at a scale where IT security isn't abstracted away by massive teams - you're close to the infrastructure, close to the decisions, close to the blast radius. The college offers more than 60 undergraduate majors and minors alongside graduate programs, which means the attack surface spans academic systems, student data, financial records, and the usual sprawl of endpoints that come with a campus population that size.
No cybersecurity-specific technical domains, product lines, or dedicated security engineering teams are listed in available information. That's not unusual for an institution this size - securing a college like this likely means you're threading compliance obligations (think FERPA, PCI for campus transactions) through systems that weren't always built with zero-trust in mind. The mission, rooted in the tradition of the Sisters of Saint Joseph, emphasizes holistic development across intellectual, spiritual, emotional, and social dimensions - context that shapes how the institution thinks about risk and the people behind the data it holds.
If you're looking at this one, the question is whether you want to own the full security stack in an environment where you can actually see the impact of your work. With more than 19,000 graduates produced over a century, the alumni and donor data alone is a target worth thinking about. The threat model here is less nation-state, more opportunistic - ransomware, phishing campaigns hitting email infrastructure, credential stuffing against legacy portals. The role is probably about building guardrails where few existed, not tuning a SOC that's already humming.






