- 10+ years of experience in Cyber Security, IT Risk, or Regulatory Compliance roles, with recent focus on European regulatory frameworks (DORA mandatory; NIS2/GDPR familiarity a plus).
- Demonstrated experience preparing regulatory files/reports for CRO or senior leadership review.
- Direct experience communicating with regulators (drafting responses, attending regulatory calls/meetings, managing submissions) — financial services or fintech regulatory experience strongly preferred.
- Strong understanding of cyber security domains: ICT risk management, incident response, third-party/vendor risk, data security, access controls.
- Working knowledge of data governance and process mapping as it relates to compliance (data flows, classification, retention, controls documentation).
- Excellent written communication skills — able to draft exact, regulator-facing documentation.
- Ability to work directly and independently with C-level stakeholders (CRO) under tight timelines.
Preferred Qualifications
- Certifications: CISSP, CISM, CRISC, CDPSE, or equivalent.
- Prior experience with EU-regulated financial institutions, insurers, or their India-based GCC/support teams.
- Familiarity with GRC tooling (e.g., IBM OpenPages, ServiceNow GRC, Archer) for tracking regulatory obligations and evidence.
- Exposure to ICT third-party risk management and resilience testing (TLPT-adjacent knowledge).