Erik Gibson
Head of Information Security @ATOSS Software SE
Signup · Get unlimited contacts
WORK HISTORY
Head of Information Security @ATOSS Software SE
Munich, DE
As Head of Information Security at a publicly listed enterprise software company (SDAX/TecDAX), responsible for security strategy, ISMS governance, and regulatory compliance across the organisation and product landscape.• Ensuring compliance with ISO 27001, GDPR, NIS2, EU AI Act, and Cyber Resilience Act• Translating regulatory requirements into actionable measures for products and services, with a focus on AI and R&D enablement• Building Incident Response, Crisis Management, and Business Continuity frameworks• Aligning customer security requirements during the sales cycle to support business enablement• Driving security awareness through training for employees, sales, and R&D teams
EDUCATION
Offensive Security
OSCP, Offensive and Defensive Security, Wireless Security
Pm-Ideas
Project Management Professional (PMP), Project Management Institute
Dataquest.io
Data Scientist in Python, Data Science
University of Johannesburg
Bachelor of Technology Degree, IT (IS & Technology Management)
Bracken High School
Matric
University of Johannesburg
Bachelor of Commerce Honours (IT Management) , Computer/Information Technology Administration and Management
Vaal University of Technology (VUT)
Computer System Engineering
SKILLS
ABOUT ERIK GIBSON
Security leader with 20+ years building, scaling, and securing technology businesses - from co-founding a secure bank card personalisation startup (acquired by IDEMIA in 2016) to advising European Private Equity firms on portfolio company cybersecurity posture. Now leading information security, technology compliance, and AI governance for a publicly listed enterprise software company. I drive security strategy, ISMS governance, and regulatory compliance spanning ISO 27001, GDPR, NIS2, the EU AI Act, and the Cyber Resilience Act. My mandate spans risk management, product security enablement, and operational resilience - with a focus on translating regulatory requirements into business-enabling measures for products, services, and R&D. I actively leverage AI tools to augment security operations, from employee training, threat analysis and policy drafting to audit preparation and compliance monitoring.At OMMAX, I served a dual role as CISO and leader of cybersecurity advisory services, assessing 40+ companies as part of PE technical due diligence, delivering security-focused value creation initiatives that supported a consistently high rate of successful acquisitions and exits across PE client portfolios. Internally, I certified a new ISMS to ISO 27001:2022 within 12 months, a target two previous appointees were unable to achieve.At KONUX, I led IT and Information Security for an AI industrial IoT scale-up, building an ISO 27001 ISMS from the ground up, implementing Zero Trust and DevSecOps strategies, and reducing operational costs by 20%. Promoted from Information Security Officer to Team Lead within 6 months of joining.Previously, I spent 12 years as Co-Founder and CISO of Xantium Integrated Solutions, a PCI-accredited bank card personalisation company serving blue-chip financial institutions across Africa, wholly acquired by IDEMIA in 2016.Core expertise: ISMS governance, security strategy, regulatory compliance (ISO 27001, NIS2, GDPR, EU AI Act, CRA), product security enablement, AI governance, and PE tech due diligence.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.