Profile: Raj Sharma, Head of Information Security, Northern Bank
Published On: September 15, 2026

Raj Sharma began his career in cybersecurity more than 20 years ago, when the field was still commonly referred to as data security. Fresh out of college and working as a management trainee at a bank, Raj was approached by the CTO about an opening for a data security administrator.
“At the time, I had not known anything about data security. It was very new, but I decided to give it a shot,” Raj recalls.
That opportunity introduced him to what he describes as the other side of technology and set the direction for his career. Over the years, Raj has watched cybersecurity evolve through the shift from on prem environments to the cloud, the rise of ransomware, and now the opportunities and risks created by AI.
Raj spent 16 years at Eastern Bank, progressing from Data Security Administrator to pivotal leadership positions within the cybersecurity program. Along the way, he played a key role in developing and maturing the organization’s information security function.
Maturing Security Through Partnership
In 2018, Raj joined Northern Bank with an opportunity to continue to mature its information security program. Today, his responsibilities span all aspects of cybersecurity, giving him visibility into each program area. However, some of the most important work he has done has been around relationships.
Coming from a much larger organization, Raj recognized the importance of working closely with Northern Bank’s IT team and business leaders. Rather than positioning security as a separate function, he wanted the organization to see him as a partner who could support innovation and growth while ensuring the appropriate guardrails were in place.
That philosophy has become central to how Raj views the role of a security leader. “A CISO really must have a good understanding of the business, a good understanding of the business objective, and a good understanding of the business strategy,” he explains.
Getting involved early is critical. When security understands where business leaders are heading and what technologies they want to use, it helps build security into the process rather than evaluating risk after decisions have already been made.
Learning to Speak the Language of Business
Raj learned the importance of business communication through experience. Earlier in his career, he remembers presenting a technology solution to senior leadership and walking away believing he had done a great job. Afterward, one of the executives approached him with candid feedback that despite the work Raj had put into the presentation, he had not explained what leadership really needed to know.
“What’s going to be the value to the business? What’s going to be the cost? And if there’s risk, put those risks in business terms so that it’s easy to understand,” Raj recalls being told.
It was an awakening moment. Technical expertise might help a security leader identify risk, but communicating that risk requires understanding what matters to the audience.
Today, Raj thinks about security conversations in terms of areas such as business objectives, cost, potential loss, and organizational impact. He encourages other security leaders to do the same, particularly when communicating with executives and boards.
Preparing for What Comes Next
Raj’s priorities reflect how quickly the security landscape continues to evolve. Resilience and governance remain foundational, but he is also focused on AI governance, phishing resistant multifactor authentication, post quantum preparation, and security awareness.
Some of those risks may still be years away, but Raj believes organizations should begin preparing before they become immediate problems. With post quantum security, for example, that means understanding where certificates and encryption are used today and considering how those technologies may eventually need to change.
At the same time, employees remain a critical part of the equation. “Our employees are our biggest control when it comes to security,” Raj explains.
AI is making that responsibility more complicated as fraudulent emails become increasingly difficult to distinguish from legitimate communications. For Raj, continuing to strengthen security awareness is therefore just as important as investing in emerging technologies.
Creating Structure Around AI
AI governance has become one of Raj’s most immediate priorities as Northern Bank navigates adoption from multiple directions.
Existing vendors are increasingly adding AI capabilities to their products, while employees and business teams are interested in platforms such as Copilot and other large language models. Raj believes both require oversight.
The organization needs to understand how vendors have secured their AI capabilities and whether new functionality meets Northern Bank’s standards. Internally, it also warrants visibility into which AI tools are being used and how employees interact with them.
“There must be good governance around AI,” Raj says. “Making sure that this process is vetted and making sure that we have good control over what AI tools are being used.”
Northern Bank has established a governance committee where these questions may be evaluated as the technology continues to evolve. For Raj, the goal is not to prevent adoption, but to create a process that allows the business to take advantage of AI within appropriate boundaries.
Doing More with a Lean Team
Like many security leaders, Raj faces the challenge of managing increasingly complex risks with finite resources. “How can we sustain these big challenges while remaining a lean shop?” he asks. “I have a small team, but we have these big challenges.”
That reality makes prioritization especially important. It also reinforces why Raj wants security integrated into business decisions. When leaders understand risk before making a decision, the organization can make more informed choices about where resources will have the greatest impact.
Raj brings a collaborative approach to leading his own team. He wants employees to take ownership with their own ideas and have the support they need to succeed. “I consider myself to be more of a transparent, collaborative leader,” he shares. “I allow my team members to feel empowered to take ownership and for me to be by their side in case there are any issues.”
With a field that changes as quickly as cybersecurity, he also places significant emphasis on continued learning. For Raj, training matters more than simply accumulating certifications. He looks for people who are curious and willing to continually develop their skills.
Making Yourself Visible
Raj holds himself to that same expectation for growth. He attends and speaks at conferences, participates in panels, maintains relationships with peers, and regularly seeks feedback from colleagues and other leaders about his own strengths and weaknesses.
Building those relationships did not always come naturally. “At the beginning of my career, I was more of an introvert,” Raj recalls. Over time, he realized that approach meant people often came to him only when there was a security problem. To become a stronger leader and business partner, he needed to make himself more visible.
Today, Raj encourages other cybersecurity professionals to do the same, even if they start small. An email or LinkedIn message can be the first step toward developing a relationship with someone they respect.
He also gives back through the Massachusetts Cyber Exchange, where he mentors college students preparing to enter the field. For Raj, mentorship reflects a broader evolution within cybersecurity itself.
“Security is no longer this person who’s sitting in the corner by themselves,” he says. “A security professional needs to be in alignment with the business lines, with their peers.”
It is a lesson that mirrors Raj’s own career. As cybersecurity has evolved from data security into a strategic business discipline, he has evolved with it, continually learning, strengthening relationships, and ensuring security remains connected to where the business is going next.
Subscribe
Stay up to date with cyber security trends and more
