Minimum of 4 years of experience in Information Security / GRC Proven experience in Information Security, Cyber Security, or IT Risk Hands-on experience performing formal risk assessments Managing risk registers Working knowledge of ISO 27001, PCI DSS, SOC2, GDPR Familiarity with secure development lifecycle Familiarity with cloud security principles (AWS/Azure/GCP) Familiarity with identity/access management Exceptional ability to translate technical risks into business language