David Andersson
I'm a security leader with 20+ years spanning enterprise architecture, compliance and engineering leadership. I've built and scaled security programs from the ground up, from ISMS design and ISO 27001 certification to leading full security functions at high-growth SaaS companies and government agencies, and I'm equally comfortable shaping strategy at the executive table or in a hands-on technical review.
My work spans the full security function: governance that satisfies auditors without becoming theatre, application security and detection engineering close enough to the code that I can still read it, and the leadership judgement to build a team around all of it.
Security as a service function, not a gatekeeper. The shift from "no, you can't do that" to "yes, let's find a better way" is the work, and the best results come from bringing security into the design phase and treating engineering teams as partners.
Technical Competencies
Security Program Leadership
Building security functions from a single hire to full teams, leading through acquisition integration, with staff, budget, and executive reporting responsibility.
Governance, Risk & Compliance
ISO 27001/27002 and SOC 2 Type 2 implementation, ISMS design built from scratch, protective security legislation, and audit ownership across regulated and commercial environments.
Application & Technical Security
Application security across the SDLC, threat modeling, vulnerability management, and detection engineering, keeping technical judgement close to the work rather than delegated away.
Professional Experience
Remote
SaaS observability, open source
Director of Security Engineering
Grafana Labs AB
Promoted from Senior Manager, Engineering in Security (Oct 2024). Team of 10 across two sub-teams. Staff and budget responsibility.
Leading a team of 10 across two sub-teams: one building VulnO11y, an internal observability tool for vulnerability management across the Grafana ecosystem, and one serving as internal security consultants providing architecture reviews, vulnerability remediation support, and hands-on AppSec advisory across engineering teams.
- Built and operate VulnO11y, an observability tool that models the full vulnerability lifecycle as a state machine, from detection through CVE publication, embargo handling, and SLO-driven remediation. Ingests from Trivy, Grype, and OSV across first-party and third-party scope, and tracks the point a vulnerability entered a repository, image, or artefact against the agreed time-to-fix.
- Co-presented at GrafanaCON 2026 on the April 2025 CI/CD incident response. Full attack reconstruction, canary-token detection, and open-source forensics (Loki, Trufflehog, Zizmor, Gato-X) that confirmed no customer or user data was affected.
- Evolving threat modeling practice. STRIDE remains the default, with the team building a custom model inspired by STRIDE and PASTA to cover AI-introduced threat surfaces where classic frameworks fall short.
- Own the AppSec testing toolchain across the organisation: SAST, SCA, external penetration testing, and the bug bounty and VDP programme.
- Internal advisory function providing architecture reviews and remediation support to product teams.
- Staff and budget ownership, operational and strategic improvements across incident management, secure SDLC, and vendor governance.
Remote
SaaS observability, open source
Senior Manager, Engineering in Security
Grafana Labs AB
Built the security engineering function from the ground up. Promoted to Director.
Built the security engineering function supporting product development and application security advisory. Established the internal advisory model, scaled the AppSec toolchain, and set the vulnerability management practice that later became VulnO11y. Promoted to Director of Security Engineering.
Remote
SaaS, software asset management
Director of Security Engineering
Flexera
Title aligned to Flexera's levelling structure following the acquisition of Snow Software (closed February 2024). Scaled to a team of 15 including a reporting manager.
Continued leading security engineering for the Snow Atlas platform when Flexera's acquisition of Snow Software closed in February 2024, with the title aligned to Flexera's levelling structure. Led the security engineering function through acquisition and team integration, scaling to a team of 15 including a reporting manager, and built out detection capability across the combined estate as part of aligning Snow's security operations with Flexera's.
- Owned cloud and application security engineering across the platform, together with the Security Champions Community of Practice spanning all engineering teams.
- Daily operational and strategic risk management across development and production.
- Held monthly CTO updates on security posture and progress.
- Well versed in the CNCF landscape and OWASP tooling, integrating both process and tooling to mature the cloud-native Snow Atlas platform.
Remote
SaaS, software asset management
Head of Security Engineering
Snow Software
Grew from manager of 1 to a full security engineering function through to the Flexera acquisition.
Owned product security, application security, and cloud infrastructure security for the SaaS platform. The platform was an Azure-native, multi-tenant lift-and-shift of Snow Software's historic on-prem product. Started as a single manager with one report and grew the function through to Flexera's acquisition of Snow Software, which closed in February 2024.
- Owned the full AppSec and cloud security toolchain on Azure: SAST, DAST, SCA, and CSPM, plus external penetration testing and the bug bounty programme.
- Platform security owner for ISO 27001 certification and SOC 2 Type 2 accreditation (Security Trust Service Criterion). Sat in audit interviews, collected evidence, and improved policies and SDLC controls across the platform.
- Established the Security Champions Community of Practice with representation from every engineering team.
- Aligned security into all phases of the SDLC through shift-left principles, threat modelling, team autonomy, and automated tooling.
Karlstad, Sweden
Swedish government agency, defence and protective security
Chief Information Security Officer
Swedish Defence Conscription and Assessment Agency
Promoted from IT Security Manager. Functional CISO, working closely with the Protective Security Organisation and the IT team (CIO and IT enterprise architect).
Acted as the functional CISO at the agency. Rebuilt the ISMS largely from scratch, establishing a clear separation between information governed by the Swedish Protective Security Act and standard information, two domains with fundamentally different handling requirements. Worked closely with the protective security organisation and the IT team, including the CIO and the IT enterprise architect, and with development teams to embed security requirements into internal systems. Much of the work supported systems to be accredited according to KSF (Requirements on Security Functions) and uphold communications security.
- Designed and implemented controls for both ISO 27001/27002 and protective security legislation.
- Served as acting unit manager and member of department leadership team.
- Established security requirements processes for in-house software development. Based the ISMS on ISO 27001 and 27002, and authored a requirements catalogue aligned with the information classification levels of systems.
Karlstad, Sweden
Swedish government agency, defence and protective security
IT Security Manager
Swedish Defence Conscription and Assessment Agency
Technical security architecture for both COTS and in-house development. Promoted to CISO.
Responsible for technical security architecture with regard to the design and implementation of both COTS and in-house development. Promoted to Chief Information Security Officer.
Karlstad, Sweden
Swedish government agency
Information Security Specialist
MSB (Swedish Civil Contingencies Agency)
Six-month secondment from the Swedish Defence Conscription and Assessment Agency.
Six-month secondment from the Swedish Defence Conscription and Assessment Agency to MSB's information security function. Worked on defining the national nomenclature for information security, establishing Swedish-language terminology for concepts that had until then been used inconsistently across agencies. The work was later published as Termbanken, the reference terminology bank for information security in Swedish public administration. Also contributed to the security work on Ena, Sweden's national digital infrastructure programme developed jointly by Digg, MSB, and other agencies to standardise secure data exchange, identity management, and cross-agency collaboration across the public sector.
Remote
Independent consulting practice
Principal Security Consultant
Versitile Consulting AB
Independent practice running alongside primary engagements. Startup CISO and security advisor work through to hands-on architecture, compliance, and assessment.
Independent consulting practice delivering information security engagements that range from startup CISO and security advisor work to hands-on architecture, compliance, and security assessment.
- Startup CISO for an AI startup. Took the company through alignment with SOC 2 and ISO 27001, maturing boilerplate ISMS content into tailored, company-specific policies. Built a GRC pipeline on Vanta and GitOps: policies authored as markdown in Git, rendered to PDF, and uploaded to Vanta through a GitHub Actions workflow. Delivered in-house OWASP Top 10 training and acted as IT security architect in feature development.
- Security advisor in the energy sector (ongoing engagement). Procurement support, policy writing and ISMS work, SIEM tuning, and applying GDPR and NIS2 to the operating context.
- Security assessment of a mid-sized SaaS product, including review of source control and the CI/CD environment.
- Senior security advisor for a web-based animal medical records system used by veterinarians to report deviations and violations (for example, sheep diseases) and compile statistics. Supported both data quality and security.
- Online doctor service. Helped form their first ISMS and aligned operational procedures with legislation across multiple jurisdictions: Sweden, Germany, UK, and USA.
Karlstad, Sweden
Cyber security consultancy
Senior Consultant & Business Area Manager
Bitsec AB
P&L responsibility for the IT and information security business area. Procurement, staffing, and delivery.
Led the IT and information security business area covering procurement, consultant assignments, and delivery. Key engagements included security architecture for a mainframe migration at the Swedish Transport Agency, developing Secure Development Lifecycle processes, and creating a cyber security strategy for a multinational corporation.
Karlstad, Sweden
Engineering and technology consultancy
Senior Information Security Consultant
ÅF Technology AB
Technical security consultant, primarily industrial control systems clients.
Technical information security for industrial control systems (ICS) covering security requirement profiling, SIEM implementation, and security reviews. Represented Sweden in SIS TK 318, the standardization committee for the ISO 27000 family.
Oslo, Norway
Cyber security consultancy
Senior Information Security Consultant
Avan AS
Enterprise PKI specialist for large organizations.
Enterprise PKI covering design, implementation, and operations for large organizations. Also performed IT security reviews and assessments.
Karlstad, Sweden
Information security consultancy
Technical Information Security Consultant
Veriscan Security AB
Technical security specialist across enterprises, municipalities, and government agencies.
Technical security specialist across a broad client base including enterprises, municipalities, and government agencies. Led ISO 27001/27002 compliance assessments and served as security advisor for high-security ICS environments.
Certifications
Certified Information Systems Security Professional
ISC²
Since 2011
Certified Information Security Manager
ISACA
2018 - 2026
SABSA Chartered Security Architect, Foundation
SABSA Institute
Since 2021
ISO 27001 Lead Implementer
IT Governance
Since 2021
Education & Courses
B. Sc. Computer Science
Karlstad University
Graduated 2012
Information Security (30 ECTS)
Luleå University of Technology
2017
Understanding Group & Leaders (UGL)
Leadership Course
2020