Executive Profile

David Andersson

Information security leader with more than two decades of experience spanning enterprise architecture, compliance, and engineering leadership. Track record of building security programs from the ground up — from ISMS design and ISO 27001 certification to scaling product security teams at high-growth software companies. Equally comfortable shaping strategy at the executive table and diving into technical security reviews.

David Andersson

Technical Competencies

encrypted

Application Security

Security architecture, secure SDLC, threat modeling, security requirements engineering, and building security champion networks across development organizations.

Secure SDLC Threat Modeling PKI
verified_user

Security & Compliance

ISMS implementation and review, ISO 27001/27002, risk management, incident and continuity management, vendor governance, and security legislation.

ISO 27001 SOC 2 Risk Mgmt
architecture

Engineering Leadership

Coaching and situational leadership, staff and budget responsibility, building and scaling security teams, and driving strategic improvement programs.

People Mgmt DevSecOps Strategy

Professional Experience

2024 — Present

Remote

Grafana Labs

Director of Security Engineering

Grafana Labs AB

Leading a team of 10 across two sub-teams: one building security tooling as a plugin within the Grafana open source ecosystem, and one serving as internal security consultants — architecture reviews, vulnerability remediation support, and hands-on AppSec advisory across engineering teams.

  • Elevated first-party vulnerability management into an end-to-end process — intake, triage, remediation, coordinated disclosure, and embargo handling — in an open source environment
  • Internal advisory function providing architecture reviews and remediation support to product teams
  • Staff and budget ownership, operational and strategic improvements across incident management, secure SDLC, and vendor governance

2022 — 2024

Remote

Snow Software/Flexera

Director of Security Engineering

Snow Software/Flexera

Owned product security, application security, and cloud infrastructure security for the SaaS platform. Started as a single manager with one report, grew the function, and through the Flexera acquisition scaled to leading a team of 15 including a reporting manager.

  • Drove key parts of successful ISO 27001 certification and SOC 2 Type 2 accreditation
  • Led security engineering through the Flexera acquisition and team integration
  • Daily operational and strategic risk management across development and production

2017 — 2022

Karlstad, Sweden

Swedish Defence Recruitment Agency

Chief Information Security Officer

Swedish Defence Recruitment Agency

Rebuilt the agency's ISMS largely from scratch, establishing a clear separation between information governed by the Swedish Protective Security Act and standard information — two domains with fundamentally different handling requirements. Worked closely with development teams to embed security requirements into internal systems.

  • Designed and implemented controls for both ISO 27001/27002 and protective security legislation
  • Served as acting unit manager and member of department leadership team
  • Established security requirements processes for in-house software development

2015 — Present

Remote

Versitile Consulting

Senior Consultant, Information Security

Versitile Consulting AB

Independent consulting practice delivering information security engagements that range from interim leadership to hands-on architecture and compliance work.

  • Interim CISO for an AI startup — building security governance from the ground up
  • Senior security advisor for a web-based medical records system
  • Security accreditation assessments and compliance follow-up

2015 — 2017

Karlstad, Sweden

Bitsec

Senior Consultant & Business Area Manager

Bitsec AB

Led the IT and information security business area — procurement, consultant assignments, and delivery. Key engagements included security architecture for a mainframe migration at the Swedish Transport Agency, developing Secure Development Lifecycle processes, and creating a cyber security strategy for a multinational corporation.


2013 — 2015

Karlstad, Sweden

ÅF Technology

Senior Information Security Consultant

ÅF Technology AB

Technical information security for industrial control systems (ICS) — security requirement profiling, SIEM implementation, and security reviews. Represented Sweden in SIS TK 318, the standardization committee for the ISO 27000 family.


2011 — 2013

Oslo, Norway

Avan

Senior Information Security Consultant

Avan AS

Enterprise PKI — design, implementation, and operations for large organizations. Also performed IT security reviews and assessments.


2007 — 2011

Karlstad, Sweden

Veriscan Security

Information Security Consultant

Veriscan Security AB

Technical security specialist across a broad client base — enterprises, municipalities, and government agencies. Led ISO 27001/27002 compliance assessments and served as security advisor for high-security ICS environments.

Certifications

CISSP

Certified Information Systems Security Professional

ISC²

Since 2011

CISM

Certified Information Security Manager

ISACA

2018 — 2026

SCF

SABSA Chartered Security Architect — Foundation

SABSA Institute

Since 2021

27001 LI

ISO 27001 Lead Implementer

IT Governance

Since 2021

Education & Courses

school

B. Sc. Computer Science

Karlstad University

Graduated 2012

school

Information Security (30 ECTS)

Luleå University of Technology

2017

group

Understanding Group & Leaders (UGL)

Leadership Course

2020