Selected work

Cybersecurity · Learning ecosystem · Enterprise change

Unifying cyber expectations across a fragmented, high-security organization

How a global aerospace company built a clearer cyber learning ecosystem while separating from its parent brand.

A close-up view of an aerospace turbine

Case study

3,000digital technology employees, plus contractors
≈350learning and awareness assets
10+languages supported
20 monthsstrategy and production, followed by multi-year maintenance

A major global aerospace company was separating from its parent brand and effectively standing up as a new enterprise. Its digital technology organization needed to establish a stronger, more unified cybersecurity culture of its own.

Employees were adapting to new security expectations while navigating migrations, new systems, evolving policies, and new ways of working. In a highly regulated environment, cybersecurity learning could not function as a simple compliance exercise. People needed to understand what good cyber behavior looked like, where to find support, and how their responsibilities connected to the security of the business.

The organization’s historically siloed operating model created necessary specialization, but it also made shared expectations harder to establish. Engineers, architects, leaders, and technical teams worked with different tools, responsibilities, and constraints. A one-size-fits-all curriculum would have added friction rather than reducing it.

The real challenge was to create consistency across a fragmented environment while the organization was already carrying the demands of separation and migration work.

This was not a course rollout problem. It was an ecosystem-design problem.

I served as training lead for the awareness and education workstream, guiding strategy and execution across stakeholder alignment, curriculum design, team leadership, content development, translation, deployment, and reporting.

  • Partnered with client leaders and subject-matter experts to identify gaps and validate priorities
  • Developed the needs assessment, role-based curriculum, and leadership updates
  • Managed training developers and design resources through development, testing, quality assurance, translation, and delivery
  • Owned testing and deployment in the client learning platform
  • Coordinated with program management and communications leads across the broader cybersecurity initiative
  • Presented the strategy and demonstrated key solutions to client and EY audiences

I treated the work as a learning ecosystem challenge: make expectations easier to understand, resources easier to access, and the overall program easier to sustain.

  • Mapped topics and responsibilities across dozens of digital technology roles
  • Combined digital modules, one-pagers, short videos, presentations, and performance support
  • Created a centralized SharePoint and Teams resource hub for learning, policies, contacts, and reporting pathways
  • Organized required and recommended content into structured role-based journeys
  • Designed for global use, translation, maintenance, and continuous improvement

Leadership requested training for the company’s M365 Government Community Cloud High environment—a more controlled, security-first version of the familiar M365 experience. The request mattered, but it did not fit neatly into the role-based curriculum or behave like conventional cybersecurity training.

Instead of forcing it into a course, I reframed the request through a security and performance-support lens. The solution became an interactive GCC High resource hub focused on real employee friction: sharing files externally, requesting SharePoint sites, and navigating Teams in a more controlled environment. Input from the team monitoring support tickets kept the experience grounded in actual needs.

As the program became more visible, additional stakeholders requested one-off topics—some valuable, some outside scope, and some competing with planned work. I had to protect the strategy and delivery timeline while remaining responsive to changing leadership priorities.

Subject-matter experts were also occupied with separation and migration work. In several cases, I moved forward with minimum viable products that met immediate obligations and created a strong foundation for refinement during the maintenance phase.

The engagement became a potential model for similar cybersecurity learning work. More importantly, it reinforced my belief that high-stakes learning is about reducing ambiguity, supporting real work, and building systems people can actually use.

  • Centralized access to cybersecurity learning, policies, contacts, and support
  • Made role-specific expectations and learning pathways easier to navigate
  • Gave leaders a more consistent way to communicate expected cyber behavior
  • Supported global audiences with translated learning and awareness materials
  • Established a foundation for multi-year maintenance and continuous improvement

Have a complex challenge?

Let's make it clear—and make it matter.