Sveriges mest populära poddar
Razorwire Cyber Security & InfoSec Insights

A New Voice in InfoSec. What Nobody Tells You About Breaking Into the Industry

37 min12 augusti 2026

What does it actually look like to break into InfoSec from the outside, with no technical background, no industry contacts and no idea what half the acronyms mean?

Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this interview episode, I'm joined by Irina Sordiya, a GRC and compliance professional based in Montreal who came into information security from a finance background.

Not everyone who works in information security started out in IT. Irina's route in began at a career fair where she stumbled into a fintech startup looking for someone who could translate financial regulation into language a dev team could understand. From there she moved into auditing at KPMG and eventually crossed to the other side, leading security posture and compliance in-house.

This is a conversation for anyone considering a career in InfoSec or in the early stages of one. Irina talks openly about feeling like an outsider, not understanding the acronyms and slowly realising that GRC isn't about technical knowledge, it's about understanding risk, building trust and communicating with people. She and Jim also get into the growing problem of grifters in GRC, where Canadian regulation is heading and why the InfoSec community is one of the most welcoming places to build a career.

Three key talking points:

  • You don't need a technical background
  • Irina came from a finance degree with no IT experience and a job interview where she was asked if she knew what an auditor does. She got the job. This episode is proof that soft skills, empathy and a risk mindset can take you further than most people expect.
  • G is for grifter in GRC
  • As regulatory pressure has increased, so has the number of people selling shortcuts. Overpriced courses, AI-generated templates, agents claiming to replace the CISO. Irina and Jim discuss why this preys on people trying to break in and why there's no substitute for doing the work.
  • The risk mindset as a North Star
  • The best advice Irina received early on was to develop a risk mindset. It's what helps you step back from hundred-page policies and ask what you're actually trying to protect, and why it matters more than technical knowledge for anyone in GRC.

If you're thinking about getting into InfoSec or wondering whether you belong, this conversation is for you.

On what she'd tell herself on day one:

"I would have told myself not to be scared going into this and that there will be always helpers along the way who care about what they do and put ego on the side."

Irina Sordiya

Listen to this episode on your favourite podcasting platform: https://razorwire.captivate.fm/listen

In this episode, we covered the following topics:

  • From Finance to InfoSec
  • Irina's journey started at a career fair with no IT knowledge. Find out how a finance background opened the door to a career in information security.
  • Auditor to In-House
  • As an auditor, an exception means "see you next year." In-house, it means "see you next week." We discuss what changes when you cross to the other side.
  • Building Trust as a GRC Professional
  • Discover why empathy and relationship building matter more than policy enforcement.
  • AI Governance Is Still Anyone's Guess
  • No country has got AI governance right yet. We discuss why most organisations are working it out as they go, why ISO 42001 is becoming a starting point and what that means for anyone working in GRC.
  • AI as a Tool for InfoSec Professionals
  • We discuss where AI can genuinely help with the grunt work of GRC without replacing the thinking that makes the role valuable.
  • G Is for Grifter in GRC
  • With overpriced courses, AI-generated templates and agents claiming to replace the CISO, we get into why the noise is making it harder for genuine newcomers.
  • The Risk Mindset
  • The best advice Irina received: develop a risk mindset. We discuss why it matters more than technical knowledge.
  • Why the InfoSec Community Is Worth Joining
  • Irina's experience has been overwhelmingly positive. We talk about why InfoSec professionals tend to share and support rather than gatekeep.
  • The Future of Entry-Level Roles
  • If AI takes over the grunt work that junior professionals learn from, how does the next generation develop?

Resources Mentioned

Irina Sordiya on LinkedIn

KPMG

ISO 27001

ISO 42001 (AI governance)

SOC 1 / SOC 2

EU AI Act

CISM certification

PCI DSS

Connect with your host James Rees

Hello, I am James Rees, the host of the Razorwire podcast. This podcast brings you insights from leading cyber security professionals who dedicate their careers to making a hacker’s life that much more difficult.

Our guests bring you experience and expertise from a range of disciplines and from different career stages. We give you various viewpoints for improving your cyber security – from seasoned professionals with years of experience, triumphs and lessons learned under their belt, to those in relatively early stages of their careers offering fresh eyes and new insights.

With new episodes every other Wednesday, Razorwire is a podcast for cyber security enthusiasts and professionals providing insights, news and fresh ideas on protecting your organisation from hackers.

For more information about us or if you have any questions you would like us to discuss email [email protected].

If you need consultation, visit www.razorthorn.com, We give our clients a personalised, integrated approach to information security, driven by our belief in quality and discretion.

LinkedIn: Razorthorn Security

YouTube: Razorthorn Security

TikTok: Razorwire Podcast

Instagram: Razorwire Podcast

Twitter: @RazorThornLTD

Website: www.razorthorn.com

All rights reserved. © Razorthorn Security LTD 2025

Fler avsnitt av Razorwire Cyber Security & InfoSec Insights

Visa alla avsnitt av Razorwire Cyber Security & InfoSec Insights

Razorwire Cyber Security & InfoSec Insights med Razorthorn Security | Cybersecurity & InfoSec finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.