BACK to Blog

(mini) Curriculum Vitae
Education and
certificates
2009Certified Secure Software Lifecycle Professional (CSSLP)
International Information Systems Security Certification Consortium
2004 - 2006 Security Management Training Programme
Helsinki University of Technology, Lifelong Learning Institute Dipoli
(Thesis: Evaluating a commercial SDLC-method from information security point of view )
2002 Certified Information Systems Auditor (CISA)
Information Systems Audit and Control Association
1998 Certified Information Systems Security Professional (CISSP)
International Information Systems Security Certification Consortium
1987 - 1988 Finnish Army, Reserve Officer School (Second Lieutenant)
1981 - 1987

Master of Science, Computer science 
University of Joensuu, Finland
secondary subjects: mathematics, statistics
(Thesis: Computer system performance evaluation with practical approach to Unix)

Professional skills
        Understanding the information security in general - both the business perspective and technical issues.
  • Security
    • Security business role
    • Risk management
    • Business continuity 
  • Information Security 
    • Strategies, principles, policies, procedures 
    • Security architectures
    • Security in software development
    • Security solutions
    • Business continuity planning
    • Identity Management
  •  IT
    • Internet-technologies and architectures
    • Software development and programming
    • Unix
  • Management skills
    • Integrating security into business strategy
    • Change management
    • Budgeting
    • Setting targets and evaluating achievements
    • Organizing
    • Project management
  • Soft skills
    • Good communication and presentation skills
    • Co-operative
    • Ability to understand the big picture
  • Language skills
    • Finnish - native
    • English - good
    • Swedish - basics
    • German - basics

Professional memberships
       
Work experience
8/2004- Samlink - financial services provider
Security Director

Responsible of corporate security and customer security services. Duties include management of the security department, advising corporate board and management on security issues, developing security principles and guidelines, coordinating business continuity planning, evaluating and designing security solutions, developing security awareness and behaviour.

4/2004-7/2004 Netsol Solutions information security service provider (employment by acquisition)
(currently part of Secode)
Senior Consultant

Consulting in
information security infrastructures, processes, architectures and solutions. Projects included participating developing security guidelines for Government critical information systems, SSO, PKI and disaster recovery planning.

1998 - 3/2004

AtBusiness Communications - sofware and consulting services provider
Information Security Manager / Senior Consultant

Developing Atbusiness information security policy and guidelines, advising management in security issues, educating  users, software developers, project managers and sales, integrating security into internal software development process, planning application-specific security solutions.

Evangelizing the importance of information security.

Consulting, project management and  training in various customer projects including PKI, LDAP and directories, SSO, VPN, security architectures, security auditing and developing security policies.

1989 – 1997 Hewlett-Packard - global technology and service provider
Unix-expert, Product manager, Consultant, Trainer, Education Center Manager

Duties included planning and scheduling customer training, instructing on several courses (Unix security, advanced HP-UX system management, highly-available systems, Unix system programming, Unix shell programming, X-Window and Motif programming), consulting (security, HP-UX, high-availability, programming) and providing technical expertise.

1988 – 1989

Kuopion Ammatillinen Kurssikeskus - educational service provider
(currently Savon ammatti- ja aikuisopisto)

Instructor, Systems development

Teaching systems development and programming: system development and programming principles, VAX/VMS system management, Unix system management, programming languages (Pascal, C, Cobol, Unix shell, Prolog, VAX/VMS DCL)

1984 – 1987 Joen Mikrotalo - software services provider
System designer, programmer

Software design and programming in MS-DOS, Windows and Unix environments using Pascal, C, 4GL and SQL.

Examples of presentations provided
       
  • Information Security Management, ISACA Finland
  • Information Systems Development, ISACA Finland
  • Information Security Training Programme / Security Architectures, Helsinki University of Technology Lifelong Learning Institute Dipoli, session planning and chair
  • The Continuing Professional Development Programme for Security Management / Information Security, Helsinki University of Technology Lifelong Learning Institute Dipoli, session planning and chair 
  • Information Security Program Development for CISM, KPMG
  • Business Continuity Planning for CISSP, Teleware
  • Information Security of Online Services, Bank of Finland
  • Topical Challenges of Information Security, Confederation of Finnish Industries  
  • Infomation Security, Tieturi Security Management Conference, chair
  • Information Security and Outsourcing, Finnish Information Security Association, chair
  • Security of Sofware Applications, Merito Forum, chair
  • Software Security, Infosec World Lapland. MISTI
  • Findings From Security Evaluation of a Software Development Process, Merito Forum
  • Identity and Access Management, Teleware Corporate Security Conference 
  • Web Services Security, Tieturi