Mark S.

Cybersecurity Leader | (ex) Chief Information Security Officer (CISO) | Conference Speaker | Leadership | Mentor

Gothenburg, Västra Götaland County, Sweden

About

I am a passionate leader with over 20 years of experience in the field of Information and Cyber Security. My genuine enthusiasm and energy for this industry fuel my drive to protect organizations from evolving threats and foster a culture of security. With a strong technical and business background, I have operated on strategic, tactical, and operational levels, enabling me to understand and address security challenges from multiple perspectives. I firmly believe in the value of transparency, open communication, and continuous learning, as they are essential in building robust security programs. My leadership approach emphasizes factual decision-making, persistence, and effective execution. I thrive on delivering tangible results that positively impact organizations, helping them navigate the complex landscape of cyber threats and compliance requirements. One of my key strengths lies in my ability to effectively communicate with stakeholders at all levels. I tailor my communication style to suit diverse audiences, making technical concepts accessible and actionable. By fostering collaboration and understanding, I ensure that security initiatives align with business objectives and garner support from key stakeholders. Throughout my career, I have had the privilege of positively influencing people and organizations. I take great pride in guiding teams toward achieving their full potential and creating a security-conscious culture that safeguards critical assets. If you are looking for a dedicated and results-driven CISO who values continuous improvement and is committed to securing your organization's future, I invite you to connect with me. Let's collaborate and strengthen our collective defences against cyber threats. - Information & Cyber Security Strategy - Information Security Management - Information Security and compliance frameworks: NIST CSF, ISO 2700x, CIS, SOX and GDPR. - Cyber Security capabilities - Cyber Security Risk Management - Operational Technology Manufacturing Security - Incident response & Crisis Management - 3rd party & vendor Management - Leadership & Team management skills - Budget & Portfolio management - Communication skills & public speaking - Advanced LEAN certified - 2008 Certified Information Systems Auditor (CISA) - 2006 Certified Information Systems Security Professional (CISSP)

Experience

  • Volvo Cars ()
    • Senior Cyber Security Internal Auditor
      Jun 2024 - Present · 2 yrs 2 mos

      Provide independent assurance regarding cybersecurity and digital domains.

    • Temporary assignment, interim Head of Cyber Security / Global CISO
      Jun 2025 - Jan 2026 · 8 mos

      After conducting the cybersecurity audit earlier in 2025, this temporary assignment was to support the organization in addressing this important topic. (Executive Management Presentation, Prioritisation, Budget etc.

  • Signify (5 yrs 3 mos)
    • Chief Information Security Officer (CISO) & Head of Cyber Security
      Apr 2019 - Jun 2024 · 5 yrs 3 mos

      Signify is the world leader in connected LED lighting products, systems and services. Through our innovations, we unlock the extraordinary potential of light for brighter lives and a better world. The CISO role in Signify is an business function in Finance reporting to the Chief Security Officer (CSO). Corporate Security exists of 4 teams GRC, Operations (physical), Product and Information and Cyber Security. As CISO I am responsible for: - Information & Cyber Security Strategy - Policy & Standards (ISO\NIST\SOGP) - OT Manufacturing Security - Cyber Threat Intelligence & Analyses - Insider Threat and Information Protection - Information Risk Assessments - Security Awareness - Cyber Crisis Management - Team performance, implemented Agile methodology leading to NPS scoring above company average. - Representing Signify at Multinationals ISAC (government)

    • Director Security Operations Center (ad-interim)
      Aug 2019 - Apr 2020 · 9 mos

      - Responsible for Protect, Detect, Defend Security Operational Center (SOC) - Security Engineering / Vulnerability Management / Data Leakage Prevention

  • NXP Semiconductors ()
    • Sr. Cyber Security Manager at NXP Semiconductors | Security awareness | Risk Management
      Dec 2015 - Mar 2019 · 3 yrs 4 mos

      - Deputy-CISO. - Responsible for defining and executing Cyber Security strategy. - Strong focus on team performance, process improvements, change management and way of working (for example Agile). - Leading a team of experts in the field of risk management, 3rd party assurance, Mergers & Acquisitions - Responsible for cyber security policy framework, policies & processes to get measurable and fact-based security. - Responsible for the design and implementation of the global cyber security awareness program to make our employees (~38.000) our strongest control by becoming secure by choice. This program supports NXP’s brand slogan: "Secure connections for a smarter world" - Liaison to Dutch, German and European Work Council for cyber security topics and advisor regarding general IT topics. - Representing NXP at Cyber Security Eindhoven Group. NXP Semiconductors (www.nxp.com) is the leader in innovative high-performance mixed-signal solutions which, combined with deep application insight, enable the secure connections needed for a smarter world. NXP is listed in Nasdaq stock exchange, Headquartered in Eindhoven, Netherlands. Revenue 9.5B$, headcount 31 000 (11 000 engineers)

    • Internal Auditor
      Sep 2014 - Dec 2015 · 1 yr 4 mos

      Mark's job is to provide an independent and objective assurance to the Board of Management and the Audit Committee about the quality of business controls, governance and the effectiveness of risk management procedures within the company. His specialism is information security, cyber security and risk management.

    • IT-Risk Security Compliance & Quality Officer for HRM and Sales & Marketing
      Jan 2012 - Aug 2014 · 2 yrs 8 mos

      Single point of contact for HRM and Sales & Marketing business regarding all the challenges in the IT Risk, Security, Compliance and Quality domain.

  • Philips (4 yrs 8 mos)
    • IT Security and Risk Manager
      Apr 2010 - Jul 2011 · 1 yr 4 mos

      As part of the CSIRT Risk Assesment team I am responsible for giving BIA (business impact assessment) support to the business / project teams and performing risk assessments to create risk transparency. I have a strong focus on structural process and quality improvements and therefore I help the CSIRT operational team in documenting, reviewing and improving there internal processes. As part of this role, I need to extend the current CSIRT reporting with security performance indicators of our IT vendors. I am responsible as project lead for implementing Governance Risk & Compliance tool from Modulo. Coaching of team members.

    • (Organizational) Change Support Officer
      Nov 2010 - Mar 2011 · 5 mos

      Supporting the evaluation of the organizational change "Shape to Value." Assess Organization: strategy, structure, processes, rewards, people (STAR model) Responsible for creating the interview used for the evaluation with the value space CIO's and consolidating the result.

    • Site IT Security Operational Manager
      Jun 2009 - Apr 2010 · 11 mos

      I was responsible for the IT-Security of 3500+ systems, the complete infrastructure for Healthcare in Best. I give security advice to the Site IT Delivery manager and made security work instruction and guidelines for the help desk. Perform Risk Assessments for divers project also corporate projects. (for example RA on BI SAP environment of Philips) Chairman of the Change Advisory Board in Best.

  • Logica (5 yrs 5 mos)
    • Governance Risk & Compliance Consultant
      Oct 2009 - Apr 2010 · 7 mos

      I switched from Security consultant to the Business Consultancy group, Governance Risk & Compliance within Logica to expand my business & GRC knowledge.

    • IT-Security Consultant
      Dec 2004 - Oct 2009 · 4 yrs 11 mos

      IT-Security Consultant