Episode Details
Back to Episodes
A New Voice in InfoSec. What Nobody Tells You About Breaking Into the Industry
Description
What does it actually look like to break into InfoSec from the outside, with no technical background, no industry contacts and no idea what half the acronyms mean?
Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this interview episode, I'm joined by Irina Sordiya, a GRC and compliance professional based in Montreal who came into information security from a finance background.
Not everyone who works in information security started out in IT. Irina's route in began at a career fair where she stumbled into a fintech startup looking for someone who could translate financial regulation into language a dev team could understand. From there she moved into auditing at KPMG and eventually crossed to the other side, leading security posture and compliance in-house.
This is a conversation for anyone considering a career in InfoSec or in the early stages of one. Irina talks openly about feeling like an outsider, not understanding the acronyms and slowly realising that GRC isn't about technical knowledge, it's about understanding risk, building trust and communicating with people. She and Jim also get into the growing problem of grifters in GRC, where Canadian regulation is heading and why the InfoSec community is one of the most welcoming places to build a career.
Three key talking points:
- You don't need a technical background
- Irina came from a finance degree with no IT experience and a job interview where she was asked if she knew what an auditor does. She got the job. This episode is proof that soft skills, empathy and a risk mindset can take you further than most people expect.
- G is for grifter in GRC
- As regulatory pressure has increased, so has the number of people selling shortcuts. Overpriced courses, AI-generated templates, agents claiming to replace the CISO. Irina and Jim discuss why this preys on people trying to break in and why there's no substitute for doing the work.
- The risk mindset as a North Star
- The best advice Irina received early on was to develop a risk mindset. It's what helps you step back from hundred-page policies and ask what you're actually trying to protect, and why it matters more than technical knowledge for anyone in GRC.
If you're thinking about getting into InfoSec or wondering whether you belong, this conversation is for you.
On what she'd tell herself on day one:
"I would have told myself not to be scared going into this and that there will be always helpers along the way who care about what they do and put ego on the side."
Irina Sordiya
Listen to this episode on your favourite podcasting platform: https://razorwire.captivate.fm/listen
In this episode, we covered the following topics:
- From Finance to InfoSec
- Irina's journey started at a career fair with no IT knowledge. Find out how a finance background opened the door to a career in information security.
- Auditor to In-House
- As an auditor, an exception means "see you next year." In-house, it means "see you next week." We discuss what changes when you cross to the other side.
- Building Trust as a GRC Professional
- Discover why empathy and relationship building matter more than policy enforcement.
- AI Governance Is Still Anyone's Guess
- No country has got AI governance right yet. We discuss why most organisations are working it out as th