Hands-on experience designing, evaluating, implementing, and maturing technology risk and control environments aligned with the NIST Cybersecurity Framework (NIST-CSF), NYDFS Part 500, GLBA, and other industry and regulatory frameworks, including NIST SP 800-53, FFIEC guidance, CIS Controls, COBIT, ITIL, SOX, SOC 2, PCI DSS, and the ISO/IEC 27000 series. Serve as a First Line of Defense (1LoD) technology risk and controls subject matter expert responsible for identifying, assessing, managing, monitoring, and mitigating technology and cybersecurity risks across infrastructure, applications, cloud services, data platforms, and third-party technology providers.