Columbia University operates a security-relevant surface area that most private-sector orgs can't match: sixteen schools, twenty-five libraries, and over a hundred research centers spread across New York City, all handling sensitive data - from medical records at Columbia University Irving Medical Center to federally funded research datasets. The attack model isn't theoretical; it's endpoint sprawl across a 250-year-old institution where legacy infrastructure meets cutting-edge computational research.
Security roles here deal in the kinds of problems you get when a university doubles as a medical center, a research enterprise, and a campus network simultaneously. The threat landscape includes nation-state actors targeting academic research, ransomware aimed at healthcare systems, and the perpetual challenge of securing a diverse, transient user base of students, faculty, and international collaborators. Tooling and policy have to scale across disciplines that range from genomics labs to social science survey data.
Columbia's institutional culture emphasizes international academic relationships and a diverse, global faculty and student body - which means identity and access management isn't a simple directory problem. Security teams operate in an environment where openness is a core institutional value and the perimeter is, functionally, nonexistent. The work is less about building walls and more about protecting data integrity and research continuity across a genuinely complex ecosystem.






