Michael York, Technology & Infrastructure Executive · CIO / CISOAI Governance, Cloud & Platform · Board Advisor

Strategic Focus
Bridging legacy stability and future intelligence. Leading organizations through the transition from digital-first to AI-native.
I lead information security and DevOps for a fintech platform serving 1,500+ financial institutions as they deliver credit and financial-wellness products to the people they serve. My work sits at the intersection of three things that don't always get along: moving fast, staying secure, and proving it to auditors, regulators, and demanding partners. I came up through security and risk (holding the CISSP, CISA, CISM, and CRISC), but I also own DevOps, so I don't treat security as something that happens to other people's systems. I'm responsible for the pipelines, the cloud architecture, and the uptime as well as the controls that protect all of it. That dual mandate shapes how I think: the best security makes the business faster and more credible, not slower and more annoyed. Lately I spend a lot of time on AI (as a threat and as a tool) and on the controls layer underneath it: audit trails, scoped tool authority, and the boundary between an output a system can act on and one that needs a human first.
30+
Years in Technology
CISSP · CISA
CISM · CRISC
Industry Certifications
About
I lead information security and DevOps for a fintech platform serving 1,500+ financial institutions as they deliver credit and financial-wellness products to the people they serve. My work sits at the intersection of three things that don't always get along: moving fast, staying secure, and proving it to auditors, regulators, and demanding partners.
Explore
Latest on AI governance & security
All AI writing- Sep 1, 2026 · 10 min
Your Plugin Directory Is Now Procurement
Two clicks in a plugin menu install a vendor. That connector holds a workspace credential and never cleared the third-party gate any other dependency would.
- Aug 26, 2026 · 10 min
Your AI Contract Covers a Third of the Traffic
Every enterprise AI control binds to an account. Two thirds of AI users on corporate devices use personal logins, so your contract governs a minority of use.
Latest field notes
All writing- Sep 14, 2026 · 8 min
Your Service Catalog Is Where Employee Experience Dies.
The service catalog is the product surface most employees touch, run as a queue. Measure it as a funnel. Its abandonment is your shadow-IT forecast.
- Sep 10, 2026 · 7 min
Shadow IT Is Unmet Demand With a Corporate Card.
An expense report for unsanctioned SaaS is revealed willingness-to-pay. Read the demand and buy it back with a paved road worth choosing over the card.
Fintech security & DevOps case studies
All work- SavvyMoney
Making Security a Sales Asset in Fintech
External attestations, documented controls, and a recurring threat-intelligence offering turned security from a deal-blocker into part of the pitch.
- SavvyMoney
Automating Security Operations at a Fintech
Automated the repetitive core of security operations with scheduled, structured briefings: humans review the exceptions, machines handle the recurring work.
Let's work together
Advisory engagements, fractional security leadership, or just an intro call.