Executive Profile

David Andersson

I'm a security leader with 20+ years spanning enterprise architecture, compliance and engineering leadership. I've built and scaled security programs from the ground up, from ISMS design and ISO 27001 certification to leading full security functions at high-growth SaaS companies and government agencies, and I'm equally comfortable shaping strategy at the executive table or in a hands-on technical review.
My work spans the full security function: governance that satisfies auditors without becoming theatre, application security and detection engineering close enough to the code that I can still read it, and the leadership judgement to build a team around all of it.

Security as a service function, not a gatekeeper. The shift from "no, you can't do that" to "yes, let's find a better way" is the work, and the best results come from bringing security into the design phase and treating engineering teams as partners.

David Andersson

Technical Competencies

architecture

Security Program Leadership

Building security functions from a single hire to full teams, leading through acquisition integration, with staff, budget, and executive reporting responsibility.

Program Building M&A Integration Staff & Budget Executive Reporting
verified_user

Governance, Risk & Compliance

ISO 27001/27002 and SOC 2 Type 2 implementation, ISMS design built from scratch, protective security legislation, and audit ownership across regulated and commercial environments.

ISO 27001 SOC 2 ISMS Protective Security
encrypted

Application & Technical Security

Application security across the SDLC, threat modeling, vulnerability management, and detection engineering, keeping technical judgement close to the work rather than delegated away.

Application Security Threat Modeling Vulnerability Management Detection Engineering

Professional Experience

2025 - Present

Remote

SaaS observability, open source

Grafana Labs AB

Director of Security Engineering

Grafana Labs AB

Promoted from Senior Manager, Engineering in Security (Oct 2024). Team of 10 across two sub-teams. Staff and budget responsibility.

Leading a team of 10 across two sub-teams: one building VulnO11y, an internal observability tool for vulnerability management across the Grafana ecosystem, and one serving as internal security consultants providing architecture reviews, vulnerability remediation support, and hands-on AppSec advisory across engineering teams.

  • Built and operate VulnO11y, an observability tool that models the full vulnerability lifecycle as a state machine, from detection through CVE publication, embargo handling, and SLO-driven remediation. Ingests from Trivy, Grype, and OSV across first-party and third-party scope, and tracks the point a vulnerability entered a repository, image, or artefact against the agreed time-to-fix.
  • Co-presented at GrafanaCON 2026 on the April 2025 CI/CD incident response. Full attack reconstruction, canary-token detection, and open-source forensics (Loki, Trufflehog, Zizmor, Gato-X) that confirmed no customer or user data was affected.
  • Evolving threat modeling practice. STRIDE remains the default, with the team building a custom model inspired by STRIDE and PASTA to cover AI-introduced threat surfaces where classic frameworks fall short.
  • Own the AppSec testing toolchain across the organisation: SAST, SCA, external penetration testing, and the bug bounty and VDP programme.
  • Internal advisory function providing architecture reviews and remediation support to product teams.
  • Staff and budget ownership, operational and strategic improvements across incident management, secure SDLC, and vendor governance.
Vulnerability Management VulnO11y Vulnerability Lifecycle CVE Coordination Embargo Handling Coordinated Disclosure Open Source Security Trivy Grype OSV SAST SCA Penetration Testing Bug Bounty VDP STRIDE PASTA Threat Modeling Incident Response CI/CD Security Detection Engineering AppSec Architecture Review Secure SDLC Vendor Governance Public Speaker

2024 - 2025

Remote

SaaS observability, open source

Grafana Labs AB

Senior Manager, Engineering in Security

Grafana Labs AB

Built the security engineering function from the ground up. Promoted to Director.

Built the security engineering function supporting product development and application security advisory. Established the internal advisory model, scaled the AppSec toolchain, and set the vulnerability management practice that later became VulnO11y. Promoted to Director of Security Engineering.

Software Development Security Cloud Security DevSecOps Engineering Management People Management AppSec Vulnerability Management

2024 - 2024

Remote

SaaS, software asset management

Flexera

Director of Security Engineering

Flexera

Title aligned to Flexera's levelling structure following the acquisition of Snow Software (closed February 2024). Scaled to a team of 15 including a reporting manager.

Continued leading security engineering for the Snow Atlas platform when Flexera's acquisition of Snow Software closed in February 2024, with the title aligned to Flexera's levelling structure. Led the security engineering function through acquisition and team integration, scaling to a team of 15 including a reporting manager, and built out detection capability across the combined estate as part of aligning Snow's security operations with Flexera's.

  • Owned cloud and application security engineering across the platform, together with the Security Champions Community of Practice spanning all engineering teams.
  • Daily operational and strategic risk management across development and production.
  • Held monthly CTO updates on security posture and progress.
  • Well versed in the CNCF landscape and OWASP tooling, integrating both process and tooling to mature the cloud-native Snow Atlas platform.
M&A Integration Acquisition Integration Detection Engineering Cross-functional Team Leadership Cloud Security Application Security Security Champions CNCF OWASP

2022 - 2024

Remote

SaaS, software asset management

Snow Software

Head of Security Engineering

Snow Software

Grew from manager of 1 to a full security engineering function through to the Flexera acquisition.

Owned product security, application security, and cloud infrastructure security for the SaaS platform. The platform was an Azure-native, multi-tenant lift-and-shift of Snow Software's historic on-prem product. Started as a single manager with one report and grew the function through to Flexera's acquisition of Snow Software, which closed in February 2024.

  • Owned the full AppSec and cloud security toolchain on Azure: SAST, DAST, SCA, and CSPM, plus external penetration testing and the bug bounty programme.
  • Platform security owner for ISO 27001 certification and SOC 2 Type 2 accreditation (Security Trust Service Criterion). Sat in audit interviews, collected evidence, and improved policies and SDLC controls across the platform.
  • Established the Security Champions Community of Practice with representation from every engineering team.
  • Aligned security into all phases of the SDLC through shift-left principles, threat modelling, team autonomy, and automated tooling.
Azure Multi-tenant SaaS Lift-and-Shift Product Security Cloud Security SAST DAST SCA CSPM Penetration Testing Bug Bounty ISO 27001 SOC 2 Type 2 SOC 2 Security TSC Audit Evidence Security Champions DevSecOps Application Security

2019 - 2022

Karlstad, Sweden

Swedish government agency, defence and protective security

Swedish Defence Conscription and Assessment Agency

Chief Information Security Officer

Swedish Defence Conscription and Assessment Agency

Promoted from IT Security Manager. Functional CISO, working closely with the Protective Security Organisation and the IT team (CIO and IT enterprise architect).

Acted as the functional CISO at the agency. Rebuilt the ISMS largely from scratch, establishing a clear separation between information governed by the Swedish Protective Security Act and standard information, two domains with fundamentally different handling requirements. Worked closely with the protective security organisation and the IT team, including the CIO and the IT enterprise architect, and with development teams to embed security requirements into internal systems. Much of the work supported systems to be accredited according to KSF (Requirements on Security Functions) and uphold communications security.

  • Designed and implemented controls for both ISO 27001/27002 and protective security legislation.
  • Served as acting unit manager and member of department leadership team.
  • Established security requirements processes for in-house software development. Based the ISMS on ISO 27001 and 27002, and authored a requirements catalogue aligned with the information classification levels of systems.
CISO Functional CISO ISMS ISO 27001 ISO 27002 Protective Security Protective Security Act KSF Requirements on Security Functions Communications Security Information Classification Security Requirements Engineering Requirements Catalogue Government Security Defence Sector

2017 - 2019

Karlstad, Sweden

Swedish government agency, defence and protective security

Swedish Defence Conscription and Assessment Agency

IT Security Manager

Swedish Defence Conscription and Assessment Agency

Technical security architecture for both COTS and in-house development. Promoted to CISO.

Responsible for technical security architecture with regard to the design and implementation of both COTS and in-house development. Promoted to Chief Information Security Officer.

Security Architecture Requirements Analysis Identity and Access Management Network Security Public Sector

2021 - 2021

Karlstad, Sweden

Swedish government agency

MSB (Swedish Civil Contingencies Agency)

Information Security Specialist

MSB (Swedish Civil Contingencies Agency)

Six-month secondment from the Swedish Defence Conscription and Assessment Agency.

Six-month secondment from the Swedish Defence Conscription and Assessment Agency to MSB's information security function. Worked on defining the national nomenclature for information security, establishing Swedish-language terminology for concepts that had until then been used inconsistently across agencies. The work was later published as Termbanken, the reference terminology bank for information security in Swedish public administration. Also contributed to the security work on Ena, Sweden's national digital infrastructure programme developed jointly by Digg, MSB, and other agencies to standardise secure data exchange, identity management, and cross-agency collaboration across the public sector.

Standards Development Terminology Technical Writing Public Sector National Infrastructure

2015 - Present

Remote

Independent consulting practice

Versitile Consulting AB

Principal Security Consultant

Versitile Consulting AB

Independent practice running alongside primary engagements. Startup CISO and security advisor work through to hands-on architecture, compliance, and assessment.

Independent consulting practice delivering information security engagements that range from startup CISO and security advisor work to hands-on architecture, compliance, and security assessment.

  • Startup CISO for an AI startup. Took the company through alignment with SOC 2 and ISO 27001, maturing boilerplate ISMS content into tailored, company-specific policies. Built a GRC pipeline on Vanta and GitOps: policies authored as markdown in Git, rendered to PDF, and uploaded to Vanta through a GitHub Actions workflow. Delivered in-house OWASP Top 10 training and acted as IT security architect in feature development.
  • Security advisor in the energy sector (ongoing engagement). Procurement support, policy writing and ISMS work, SIEM tuning, and applying GDPR and NIS2 to the operating context.
  • Security assessment of a mid-sized SaaS product, including review of source control and the CI/CD environment.
  • Senior security advisor for a web-based animal medical records system used by veterinarians to report deviations and violations (for example, sheep diseases) and compile statistics. Supported both data quality and security.
  • Online doctor service. Helped form their first ISMS and aligned operational procedures with legislation across multiple jurisdictions: Sweden, Germany, UK, and USA.
Startup CISO Interim CISO ISMS ISO 27001 SOC 2 GDPR NIS2 Vanta GitOps GitHub Actions Policy as Code OWASP Top 10 Security Architecture SIEM Tuning CI/CD Review Source Control Review Procurement Security Energy Sector Healthcare Security Multi-jurisdiction Compliance

2015 - 2017

Karlstad, Sweden

Cyber security consultancy

Bitsec AB

Senior Consultant & Business Area Manager

Bitsec AB

P&L responsibility for the IT and information security business area. Procurement, staffing, and delivery.

Led the IT and information security business area covering procurement, consultant assignments, and delivery. Key engagements included security architecture for a mainframe migration at the Swedish Transport Agency, developing Secure Development Lifecycle processes, and creating a cyber security strategy for a multinational corporation.

Business Area Management Security Architecture Secure SDLC Cyber Security Strategy Public Sector

2013 - 2015

Karlstad, Sweden

Engineering and technology consultancy

ÅF Technology AB

Senior Information Security Consultant

ÅF Technology AB

Technical security consultant, primarily industrial control systems clients.

Technical information security for industrial control systems (ICS) covering security requirement profiling, SIEM implementation, and security reviews. Represented Sweden in SIS TK 318, the standardization committee for the ISO 27000 family.

ICS Security OT Security SIEM ISO 27000 Standardization SIS TK 318

2011 - 2013

Oslo, Norway

Cyber security consultancy

Avan AS

Senior Information Security Consultant

Avan AS

Enterprise PKI specialist for large organizations.

Enterprise PKI covering design, implementation, and operations for large organizations. Also performed IT security reviews and assessments.

Enterprise PKI Cryptography Identity Management Security Assessment

2007 - 2011

Karlstad, Sweden

Information security consultancy

Veriscan Security AB

Technical Information Security Consultant

Veriscan Security AB

Technical security specialist across enterprises, municipalities, and government agencies.

Technical security specialist across a broad client base including enterprises, municipalities, and government agencies. Led ISO 27001/27002 compliance assessments and served as security advisor for high-security ICS environments.

ISO 27001 Assessment ICS Security Public Sector Compliance

Certifications

CISSP

Certified Information Systems Security Professional

ISC²

Since 2011

CISM

Certified Information Security Manager

ISACA

2018 - 2026

SCF

SABSA Chartered Security Architect, Foundation

SABSA Institute

Since 2021

27001 LI

ISO 27001 Lead Implementer

IT Governance

Since 2021

Education & Courses

school

B. Sc. Computer Science

Karlstad University

Graduated 2012

school

Information Security (30 ECTS)

Luleå University of Technology

2017

group

Understanding Group & Leaders (UGL)

Leadership Course

2020