The threat surface is the city itself. San Francisco's city and county government runs more than 60 departments, each a node in a sprawling network that handles everything from healthcare records to critical infrastructure controls. Over 800,000 residents depend on these systems daily, with services delivered in more than 160 languages. The attack vectors aren't hypothetical - they're the same ones that hit every large public-sector organization: ransomware targeting operational technology, credential stuffing against citizen-facing portals, supply chain compromises in legacy vendor stacks.
The digital front door is SF.gov, a centralized platform built to consolidate access to city services. That consolidation improves UX, but it also concentrates risk - one compromised authentication flow could expose multiple departmental data silos. The cybersecurity challenge here is less about novel zero-days and more about hardening a massive, heterogeneous environment where SCADA systems coexist with web apps, and where municipal budgets rarely move at the speed of the threat landscape.
This is government work. The culture emphasizes public service, equity, transparency, and community partnership. The mission isn't to protect shareholder value - it's to keep city services running for people who may have no alternative. That changes the calculus: availability and accessibility matter as much as confidentiality. If you're drawn to environments where the stakes are civic and the attack surface is a real city, this is that gig.




