Michael York, Technology & Infrastructure Executive · CIO / CISOAI Governance, Cloud & Platform · Board Advisor

Strategic Focus
Bridging legacy stability and future intelligence. Leading organizations through the transition from digital-first to AI-native.
I lead information security and DevOps for a fintech platform serving 1,500+ financial institutions as they deliver credit and financial-wellness products to the people they serve. My work sits at the intersection of three things that don't always get along: moving fast, staying secure, and proving it to auditors, regulators, and demanding partners. I came up through security and risk (holding the CISSP, CISA, CISM, and CRISC), but I also own DevOps, so I don't treat security as something that happens to other people's systems. I'm responsible for the pipelines, the cloud architecture, and the uptime as well as the controls that protect all of it. That dual mandate shapes how I think: the best security makes the business faster and more credible, not slower and more annoyed. Lately I spend a lot of time on AI (as a threat and as a tool) and on the controls layer underneath it: audit trails, scoped tool authority, and the boundary between an output a system can act on and one that needs a human first.
30+
Years in Technology
CISSP · CISA
CISM · CRISC
Industry Certifications
About
I lead information security and DevOps for a fintech platform serving 1,500+ financial institutions as they deliver credit and financial-wellness products to the people they serve. My work sits at the intersection of three things that don't always get along: moving fast, staying secure, and proving it to auditors, regulators, and demanding partners.
Explore
Latest on AI governance & security
All AI writing- Sep 1, 2026 · 10 min
Your Plugin Directory Is Now Procurement
Two clicks in a plugin menu install a vendor. That connector holds a workspace credential and never cleared the third-party gate any other dependency would.
- Aug 26, 2026 · 10 min
Your AI Contract Covers a Third of the Traffic
Every enterprise AI control binds to an account. Two thirds of AI users on corporate devices use personal logins, so your contract governs a minority of use.
Latest field notes
All writing- Sep 21, 2026 · 8 min
Enterprise Architecture Works as Guardrails, Not Diagrams.
The laminated reference-architecture diagram enforces nothing. The version that governs ships paved roads and a short list of constraints a pipeline checks.
- Sep 17, 2026 · 8 min
Outsource the Commodity, Never the Judgment.
Lean IT answers every capability question with buy or build, and both reflexes skip the real cut: rent the heavy lifting, keep decisions and accountability.
Fintech security & DevOps case studies
All work- SavvyMoney
Making Security a Sales Asset in Fintech
External attestations, documented controls, and a recurring threat-intelligence offering turned security from a deal-blocker into part of the pitch.
- SavvyMoney
Automating Security Operations at a Fintech
Automated the repetitive core of security operations with scheduled, structured briefings: humans review the exceptions, machines handle the recurring work.
Let's work together
Advisory engagements, fractional security leadership, or just an intro call.