Education: Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, Business Administration, or a related field.
Experience: 5+ years of experience in IT Risk Management, Information Security, Compliance, or IT Audit.
Technical Skills:
Strong understanding of risk assessment methodologies and frameworks (e.g., NIST CSF, ISO 27001, PCI DSS).
Experience maintaining risk registers and tracking remediation lifecycles.
Solid knowledge of IT infrastructure (networks, databases, cloud architecture) and secure system development practices (e.g., DevSecOps, CI/CD pipelines, secure architecture) to accurately identify and evaluate technical vulnerabilities.
Familiarity with privacy regulations and emerging AI governance standards.
Soft Skills: Exceptional communication skills with the ability to translate complex technical risks into business terms for management and stakeholders.
Certifications (Preferred): CRISC, CISA, CISM, ISO 27001 Lead Auditor or similar industry-recognized risk and audit certifications.