The Law School Admission Council (LSAC) is a not-for-profit that sits at a unique crossroads: it manages sensitive personal data for millions of aspiring law students while operating in one of the most credential-conscious verticals in education. That means threat models aren't abstract - they involve PII at scale, financial data tied to fee waivers, and systems that directly gate access to a profession built on trust. The attack surface isn't theoretical; LSAC's digital infrastructure supports standardized testing, application processing, and candidate analytics across the legal education pipeline.
For security and engineering teams, the work likely spans identity and access management, data protection for high-stakes admissions workflows, and platform integrity for services like the LSAT and Credential Assembly Service. The organization's mission - promoting equity and fairness in law school admissions - means availability and confidentiality aren't just compliance boxes; they directly affect whether underrepresented candidates can access legal careers. Programs like RISE Alliance and the Plus Program reinforce that the data LSAC holds has real human weight.
Culturally, LSAC signals a collaborative, mission-driven environment with competitive compensation, a 7% 401k match, comprehensive health coverage, and structured time off. It's a purpose-driven shop where security work isn't divorced from the org's core reason for existing - you're protecting the pipeline into a profession that shapes justice itself.





