About
IT and cybersecurity consultant with a background as a systems developer, agile team lead and project manager.
I've spent my career inside large industrial IT rather than looking at it from the outside. I started as a systems developer, moved into leading agile teams as a scrum master and team lead, and then ran IT projects with budgets from half a million to 23 million kronor — everything from upgrades to full platform implementations.
Most recently I've worked on securing Manufacturing Execution Systems in production-near IT/OT environments at Sandvik Coromant: as security lead for introducing security into systems and applications, building out code scanning and vulnerability management in a GitHub and Azure DevOps environment, writing the security operating model for how MES security should actually be worked with, and setting a risk-prioritised five-year plan for the area. I've also taken part in business impact analysis for critical systems.
Alongside that I've built AI agents — among them an agent that finds information across the full body of MES documentation — and, as a full-stack developer, systems such as one that automatically generates photorealistic product images and publishes them to the web.
I live in Sandviken, just outside Gävle.
Approach
Security effort goes where the real exposure is. A prioritised short list beats a complete one nobody works through.
Security that lives inside the delivery pipeline and the way of working survives after the consultant leaves. Security beside it doesn't.
I've written the code and run the projects. Recommendations are written so the people receiving them can act on them.
Credentials
Working knowledge of ISO 27001/27002, ISO/IEC 42001 (AI management systems) and the Cybersecurity Act (NIS2 / CRA).
Describe the situation and I'll tell you whether I can help. I reply within 5 business days.