Erik Gibson

Head of Information Security @ATOSS Software SE

Munich, DE
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Mar 2026 — Present

Head of Information Security @ATOSS Software SE

View department →

Munich, DE

As Head of Information Security at a publicly listed enterprise software company (SDAX/TecDAX), responsible for security strategy, ISMS governance, and regulatory compliance across the organisation and product landscape.• Ensuring compliance with ISO 27001, GDPR, NIS2, EU AI Act, and Cyber Resilience Act• Translating regulatory requirements into actionable measures for products and services, with a focus on AI and R&D enablement• Building Incident Response, Crisis Management, and Business Continuity frameworks• Aligning customer security requirements during the sales cycle to support business enablement• Driving security awareness through training for employees, sales, and R&D teams

EDUCATION

2007 — 2008

Offensive Security

OSCP, Offensive and Defensive Security, Wireless Security

2013 — 2014

Pm-Ideas

Project Management Professional (PMP), Project Management Institute

2019 — 2020

Dataquest.io

Data Scientist in Python, Data Science

2015 — 2016

University of Johannesburg

Bachelor of Technology Degree, IT (IS & Technology Management)

1993 — 1997

Bracken High School

Matric

2017 — 2018

University of Johannesburg

Bachelor of Commerce Honours (IT Management) , Computer/Information Technology Administration and Management

1998 — 2000

Vaal University of Technology (VUT)

Computer System Engineering

SKILLS

SecurityIso 27001Pci DssPayment Card Industry Data Security Standard (Pci Dss)NetworkingVirtualizationConsultingProject ManagementDatabasesSystem & Database DesignEmvInformation TechnologyIT ManagementIntegrationComputer SecurityCryptographyIT AuditBusiness AnalysisSoftware DevelopmentIT SecurityItilFirewallsInformation Security

ABOUT ERIK GIBSON

Security leader with 20+ years building, scaling, and securing technology businesses - from co-founding a secure bank card personalisation startup (acquired by IDEMIA in 2016) to advising European Private Equity firms on portfolio company cybersecurity posture. Now leading information security, technology compliance, and AI governance for a publicly listed enterprise software company. I drive security strategy, ISMS governance, and regulatory compliance spanning ISO 27001, GDPR, NIS2, the EU AI Act, and the Cyber Resilience Act. My mandate spans risk management, product security enablement, and operational resilience - with a focus on translating regulatory requirements into business-enabling measures for products, services, and R&D. I actively leverage AI tools to augment security operations, from employee training, threat analysis and policy drafting to audit preparation and compliance monitoring.At OMMAX, I served a dual role as CISO and leader of cybersecurity advisory services, assessing 40+ companies as part of PE technical due diligence, delivering security-focused value creation initiatives that supported a consistently high rate of successful acquisitions and exits across PE client portfolios. Internally, I certified a new ISMS to ISO 27001:2022 within 12 months, a target two previous appointees were unable to achieve.At KONUX, I led IT and Information Security for an AI industrial IoT scale-up, building an ISO 27001 ISMS from the ground up, implementing Zero Trust and DevSecOps strategies, and reducing operational costs by 20%. Promoted from Information Security Officer to Team Lead within 6 months of joining.Previously, I spent 12 years as Co-Founder and CISO of Xantium Integrated Solutions, a PCI-accredited bank card personalisation company serving blue-chip financial institutions across Africa, wholly acquired by IDEMIA in 2016.Core expertise: ISMS governance, security strategy, regulatory compliance (ISO 27001, NIS2, GDPR, EU AI Act, CRA), product security enablement, AI governance, and PE tech due diligence.

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.