The State of Arizona operates as the administrative backbone for over 7 million residents, with a sprawling attack surface that spans public health data, tax administration, transportation infrastructure, and economic security systems serving more than 3 million people through the Department of Economic Security alone. The cybersecurity challenge here isn't a single product or platform - it's defending a heterogeneous estate of agencies, each with its own legacy systems, data classifications, and threat models, all while maintaining continuity of essential public services. Arizona became the 48th state on February 14, 1912, and the government now employs more than 10,000 people across verticals including wildlife conservation (managing over 800 species), public administration, and tax systems.
Security teams operating within Arizona's state government work across multiple domains simultaneously - securing citizen PII in social services, hardening critical infrastructure in transportation, and maintaining the integrity of financial and tax platforms. The organization runs on the Arizona Management System (AMS), which emphasizes continuous improvement and results-driven governance, meaning security initiatives are expected to demonstrate measurable outcomes, not just compliance checkboxes. The threat model includes nation-state actors targeting government data, ransomware against public-facing services, and insider risk across a large, distributed workforce.
The state prioritizes flexible work arrangements, including remote options within Arizona, which means the security posture has to account for distributed endpoints and remote access at scale. With no single product or tech stack to anchor to, the work demands adaptability - building security architecture that can federate across dozens of agencies while maintaining centralized visibility and incident response. The mission is straightforward: protect the systems that fund Arizona's priorities and keep communities functioning.




