Meet Alexis Lavi, Senior Director in Cybersecurity at BNY. BNY is a global financial services company that helps individuals and organizations manage, move, and protect their money and investments. It provides services such as asset management, investment servicing, and financial technology to clients around the world.

Alexis Lavi is a Senior Director in Cybersecurity at BNY where she is responsible for Security Architecture, AI Security, Data and Strategy. Previously, she was the Chief Security Architect and Merchant Technology Change Executive at Bank of America. Alexis has also spent considerable time with the federal civilian cybersecurity organizations on policy and technical programs.
1. Can you tell us how you first became interested in cybersecurity and how your career evolved from working with federal cybersecurity organizations to becoming Senior Director of Cybersecurity Strategy & Enablement at BNY?
I entered cybersecurity based on my interest in national security. Like many people, 9/11 deeply impacted me, and I pivoted from a career in the medical profession to one in national security. I spent my undergraduate and graduate years studying political science and security studies, expecting to enter a federal civilian role related to protecting our country. I had the opportunity to work with DHS as it was still forming its cybersecurity organization — the predecessor of CISA — alongside the Department of Energy. At the time, concepts like software assurance, information sharing, and intrusion detection tools were just taking hold at a national level, and my very first project was a risk analysis of firewalls and routers for use in classified systems.
After some time supporting the federal civilian space and working at smaller firms, I found the opportunity to join Bank of America. That has been, and will remain, one of the most rewarding chapters of my career. I worked with some of the smartest people I've encountered and learned so much, both professionally and technically. Without that experience, I wouldn't have been ready for this next chapter at BNY.
At BNY, my role is really about connecting the dots — translating security strategy into something teams can actually act on, and making sure the right tools and guidance are in place so security becomes part of how we build, not an afterthought bolted on at the end. It's a natural extension of everything I learned at Bank of America, just applied at a broader, more strategic level.
2. Cybersecurity includes many different career paths. How did you become interested in security architecture, and what does a security architect actually do day to day?
Great question! Only a few people truly know what they're going to be when they grow up — I certainly didn't expect to end up in cybersecurity, let alone architecture, and now AI security on top of that!
What actually pulled me toward architecture was realizing that the most interesting cybersecurity problems weren't about any single control or tool — they were about how everything fit together. I found myself drawn to the "why" behind a design more than the "how" of any one piece of technology, and architecture is where that curiosity gets to live. It's the discipline that forces you to see the whole system, not just your corner of it.
Security architects can take many forms, and the role often depends a lot on the person in it. Some days it's like being a matchmaker, trying to find the right solution or the right person to help advance a project — that's where breadth of knowledge and relationships matter most. Other days you're deep in a technical protocol or tool, making sure it meets the right specifications for a given design — that's where depth of knowledge is critical. And some days it's about creating a clear, visual set of requirements that articulates the current and future state of a solution — that takes both depth and breadth.
Ultimately, security architecture should reduce complexity around the unknown. As a former manager and mentor of mine used to say, "Complexity is the enemy in cyber" — and that's very true. Our job as architects is to give the business options for weighing risk tradeoffs.
3. You've helped organizations build and improve cybersecurity programs of different sizes. If you were advising a student today, what technical skills, projects, or experiences would provide the strongest foundation for that type of work?
First, a strong work ethic never goes out of style. Working hard matters — getting to know your subject matter intimately (especially in the world of AI-generated content) and getting to know the people you work with matters greatly in the early years. That's how you build trust, and from that trust, you earn access to more interesting problems and areas of work.
Second, don't dismiss the basics: authentication versus authorization, symmetric versus asymmetric encryption, and so on. From there, go a level deeper — learn how a protocol actually works, its dependencies, and so on.
When it comes to AI, I'm still learning like everyone else, but the same principles apply: in cyber, understanding how something works — not just how to use it — matters. Take a "skill" as an example: Is it from a trusted author or source? Are there software dependencies? What's the intent behind it? And, of course, is there any malicious code, secrets, or other “bad” material embedded in it? In a world where we're increasingly outsourcing execution to autonomous agents, we need an even deeper understanding of the underlying technology.
4. You hold a patent related to evaluating cloud service vulnerabilities. What problem were you trying to solve, and what can students learn from the process of turning an idea into an innovative security solution?
I have a phrase I live by: work yourself out of a job, because there will always be another one waiting. At the time, SaaS vendors were popping up everywhere, and I was tired of asking and answering the same set of security questions over and over, since most SaaS architectures are fairly similar. So, together with a group of smart, humble people, we put our heads together and built a tool and process to evaluate cloud services more efficiently — freeing us up to focus on more interesting problems.
The biggest lesson for students is that innovation rarely starts with a eureka moment — it starts with annoyance. If you find yourself doing the same manual, repetitive work over and over, that's usually a signal there's a better way to solve it. The other lesson is that you don't have to solve it alone. Surrounding yourself with smart, humble people who are willing to challenge an idea and improve it is what actually turns a frustration into something worth patenting.
5. You've had career moments outside of pure cyber roles, such as running your own consulting firm and working in Payments Technology. How did those roles feed back into your cyber career?
Those experiences rounded out my career and reaffirmed my role within a cyber/technology organization. What I like to call my "sabbaticals" from cyber taught me what it feels like to have security requirements dropped on you at the last minute, how difficult it actually is to ship code in a large organization, the pressure that comes from a business with a real P&L, and just how much user experience matters in consumer technology. My time in Payments shaped how I think about product, architecture, engineering, the business, and the customer — it all came together for me that year.
Running my own business brought its own challenges and lessons. I had the chance to work with small and medium-sized businesses to strengthen their cybersecurity programs, giving them direct, concrete guidance. That work helped me learn to prioritize the controls that truly matter over the "nice to haves." That year was also great because it gave me the time and platform to write again — I had the pleasure of working with Gunnar Peterson on Defensible — and to meet with many startups in the cyber/AI space that are now household names. Taking a year away from a traditional job expanded my professional network, both globally and here in Pittsburgh — which ultimately led me to BNY.