Strong understanding of major security and regulatory frameworks including NIST CSF, NIST 800 53, SOC 2, ISO 27001, DORA, GDPR, and related risk assessment and internal control methodologies and demonstrated success supporting and leading internal and external audits and certifications. Technical & Regulatory Expertise: Strong understanding of cybersecurity principles, data protection, privacy, and compliance, including hands on familiarity with areas such as access control, encryption, network security, identity and access management, and incident response.