A New Voice in InfoSec. What Nobody Tells You About Breaking Into the Industry

What does it actually look like to break into InfoSec from the outside, with no technical background, no industry contacts and no idea what half the acronyms mean?

Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this interview episode, I'm joined by Irina Sordiya, a GRC and compliance professional based in Montreal who came into information security from a finance background.

Not everyone who works in information security started out in IT. Irina's route began at a career fair where she stumbled into a fintech startup looking for someone who could translate financial regulation into language a dev team could understand. From there she moved into auditing at KPMG and eventually crossed to the other side, leading security posture and compliance in-house.

This is a conversation for anyone considering a career in InfoSec or still finding their feet in the industry. Irina talks about feeling like an outsider, not understanding the acronyms and slowly realising that GRC isn't about knowing everything technical. It's about understanding risk, building trust and communicating with people. She and Jim also get into the growing problem of grifters in GRC, where regulation is heading and what happens to entry level careers if AI takes over the work people traditionally learn from.

Three key talking points:

  • You don't need a technical background
  • G is for grifter in GRC
  • The risk mindset as a North Star

If you're thinking about getting into InfoSec or wondering whether you belong, this conversation is for you.

On what she'd tell herself on day one:
"I would have told myself not to be scared going into this and that there will be always helpers along the way who care about what they do and put ego on the side."
Irina Sordiya

Listen to this episode on your favourite podcasting platform:
https://razorwire.captivate.fm/listen

In this episode, we covered the following topics:

  • From Finance to InfoSec
  • Auditor to In-House
  • Building Trust as a GRC Professional
  • AI Governance Is Still Anyone's Guess
  • AI as a Tool for InfoSec Professionals
  • G Is for Grifter in GRC
  • The Risk Mindset
  • Why the InfoSec Community Is Worth Joining
  • The Future of Entry-Level Roles

For more information about us or if you have any questions you would like us to discuss email podcast@razorthorn.com.
If you need consultation, visit (https://www.razorthorn.com). We give our clients a personalised, integrated approach to information security, driven by our belief in quality and discretion.

Follow us online:
LinkedIn: (https://www.linkedin.com/company/razorthorn-security)
YouTube: (https://www.youtube.com/c/RazorthornSecurity)
TikTok: (https://www.tiktok.com/@razorwire.podcast)
Instagram: (https://www.instagram.com/razorwire.podcast)
X: (https://x.com/RazorThornLTD)
Website: (https://www.razorthorn.com)