Jens Heyn Roed Andersen
Cybersecurity Subject Matter Expert
Aarhus, Denmark
I like to think of myself as "the Swiss army-knife" of cybersecurity (or information security). Because I am what is called a "1st generation CISO", as I became Chief Information Security Officer/CISO around the turn of the century, when nobody really knew what it was and what the job included. I have been aboard the security journey most of the way and therefore, I have the practitioner’s approach and experience to solving problems, whether they are of strategic or practical nature at an operational level. As a freelance consultant I have helped a multitude of clients, increasingly as the “translator” between tech and business. Recently, emphasis has been on the CHANGE needed to get and stay in control of the increasingly important cybersecurity area, particularly on improving quality of the software being developed, resulting in my focus moving from “infrastructure” to “product and service security”. Leading smaller technical teams into changing minds, attitudes and culture or even management teams and entire organizations, has mainly been the task, as the cultural aspect of cybersecurity in the digital society has turned out to be more important than ever. Therefore, I master agile management and development methods, where SCRUM has been the primary choice. I started on the “BLUE team” back in the CISO-days, but being the “interpreter”, I now primarily work in the “blended” teams (PURPLE, GREEN and ORANGE). Whether it is in a traditional IT-organization, in a start-up, in IoT/OT development environment I have become the CHANGE AGENT for cybersecurity on operational, tactical, and strategic level. My primary skill is to quickly understand my clients’ business and assess their organization. And from there, identify the value-adding actions. And always from a business perspective, but equally as the technical Subject Matter Expert on the threats towards the digital economy. Therefore, I have expert knowledge on the technical and complex aspects of information security in a modern company, having become an SME in fields like the ISO2700x suite, secure SDLC, NIST CSF/SP800, Risk Management etc. I am also a leader with T-shaped skills, coming from a long career within IT, where I have obtained both general management skills as well as expert skills. I have kept it all up2date through market leading certifications like CISSP, CISM, CEH, CIPP/E, CIPT, PROSCI/ADKAR etc. My academic background is an MsC (Political Science), which basically taught me how to learn (fast). My professional experience comes from both large international companies, start-ups and from the SMB segment. My personal values are characterized by honesty and credibility, and I am a firm believer in leadership based on dialogue. I have a very curious nature with an eager for professional and personal development, and I believe that everyone can “learn for life”. I work in a very structured and systematic way and have strong analytical skills. I am used to a hectic business environment and working within IT for years has taught me how to perform in an environment of constant change.