Case study · Employer program
GM Financial — Cybersecurity program and AI/ML governance
IT Cybersecurity Project Manager, April 2021 – April 2026. Arlington, Texas.
Employer program — this was my role as an employee, not a consulting engagement.
At a glance
- Organisation:
- GM Financial, the captive finance arm of General Motors.
- Portfolio:
- cumulative $11M across more than twenty cybersecurity engagements.
- Domains:
- privileged access management, secrets management, Okta identity and access, vulnerability automation.
- AI track:
- security and governance lead for the enterprise AI/ML adoption program.
The situation
A regulated financial-services company was moving from experimenting with AI and machine learning to adopting them across the enterprise. The technical appetite was there. What had to be built alongside it was the part that lets a bank say yes: who can access which data, how models and pipelines are secured, how decisions are auditable, and how the whole thing fits the controls the company already runs. That work sat with the cybersecurity program, and the cybersecurity program sat with me.
What I did
Ran the cybersecurity portfolio.
More than twenty projects over five years, $11M cumulative — privileged access management, secrets management, Okta identity and access, and vulnerability automation — each delivered under the company's change control, with security, risk, and operations stakeholders signing off at every stage.
Led the security and governance track of AI/ML adoption.
I sat between the business sponsors, the data engineering team, and the AI practitioners, and made sure the program's requirements for identity, data handling, and auditability were defined early and built in rather than bolted on.
Kept one view leadership could read.
Scope, schedule, risk, and spend across the portfolio, reported in a form that executives and auditors could both use.
What it taught me
Three things I now build into every engagement:
Governance is a design input, not a gate.
The AI initiatives that moved were the ones where security and risk were in the room at the start.
Identity is where AI programs succeed or stall.
Who and what can reach which data is the first question a regulated company asks, and the last one most pilots answer.
The operating model matters more than the model.
A pipeline nobody owns on a Tuesday morning is a pilot, whatever the demo looked like.