CV
LinkedIn: alexandernorell
Summary
Senior cybersecurity, privacy, and compliance leader with nearly three decades of experience spanning security architecture, regulatory compliance, risk management, and executive advisory. Proven ability to build and scale consulting organizations, lead international teams, and help highly regulated enterprises extract value from complex compliance landscapes by reducing duplication, audit fatigue, and operational risk.
Strong background across PCI DSS, ISO/IEC 27001, privacy, cloud security, payment systems, and enterprise security architecture, with extensive experience working with executive stakeholders and assurance programs.
Core competencies
- Cybersecurity & Security Architecture
- Compliance & Regulatory Advisory (PCI DSS, ISO/IEC 27001, Privacy)
- Risk Management & Governance
- Enterprise & Cloud Security
- Payment Security (PCI, P2PE, PIN, EMV)
- Executive Advisory & C-level Engagement
- Business Development & Go-to-market
- Team Leadership & Global Delivery
- Audit Strategy & Assurance Optimization
Experience
VikingCloud
Global Security Architect (Jul 2022 – Present)
Helping organizations maximize the return on cybersecurity, privacy, and compliance investments by identifying efficiencies and overlaps across regulatory and assurance frameworks—reducing audit fatigue while strengthening security posture.
- Business development / sales enablement (enterprise)
- Relationship management
- Service development
- Spokesperson / presenter / thought leadership
- Marketing support
- Privacy and risk
- System and architecture design
Senior Director – Consultant & Advisory Services, EMEA (Jan 2021 – Jul 2022)
Senior Director responsible for delivery of professional services across EMEA. Led teams delivering information and cybersecurity consulting, privacy advisory, and risk assessments.
- People management
- Relationship management and enterprise accounts
- Privacy and risk advisory
- Business development, forecasting
- System and architecture design oversight
- Quality and integrity of delivery
- Integration
Focus areas:
- Privacy
- Application security
- P2PE / PIN / SSF
- Cloud security
- Compliance
SecureTrust (Trustwave division)
Director, EMEA – Global Compliance & Risk Services (GCRS) (Oct 2018 – Jan 2021)
Director for the delivery of compliance and risk services in EMEA. Responsible for managing the teams that deliver compliance assessments, information security consulting, IT governance consulting, and risk assessments.
- People management
- Enterprise accounts
- Privacy and risk
- Business development
- System and architecture design
- Quality and integrity
- Forecasting
Trustwave
Director, EMEA & APAC – Global Compliance & Risk Services (GCRS) (Jul 2017 – Oct 2018)
Director for the delivery of compliance and risk services in EMEA and APAC. Responsible for managing the teams that deliver compliance assessments, information security consulting, IT governance consulting, and risk assessments.
- People management
- Enterprise accounts
- Privacy and risk
- Business development
- System and architecture design
- Quality and integrity
Director, EMEA – Global Compliance & Risk Services (GCRS) (Jan 2015 – Jul 2017)
Director for the delivery of compliance and risk services in EMEA. Responsible for managing the teams that deliver compliance assessments, information security consulting, IT governance consulting, and risk assessments.
Director, EMEA – Northern Europe & Africa (Oct 2014 – Jan 2015)
Director for the delivery of compliance and risk services in the region including Northern Europe, BENELUX, Russia and Africa.
Managing Consultant (Jul 2009 – Oct 2014)
Managing Consultant responsible for the Nordics and Eastern Europe at Trustwave in Stockholm, building and leading payment security and information security consulting.
- PCI DSS, PA-DSS, P2PE, ISO/IEC 27001 advisory
- QSA / PA-QSA / P2PE QSA compliance validations
- Risk assessments (ISO, COBIT)
- Payment application and architecture reviews
- Visa Best Practice for Data Field Encryption reviews
- Network security assessments (encryption, IDS/IPS, monitoring, firewall/router)
- Systems design and architecture advisory
- Mentoring consultants; building assessment frameworks
- Pre-sales, business development, and client portfolio management
- Engagement with Visa and PCI SSC during audits and ROC reviews
Senior Security Consultant (May 2007 – Jul 2009)
Senior security consultant delivering PCI DSS pre-assessment and remediation engagements and senior-level security advisory.
- PCI DSS readiness and remediation
- Security policies, standards, and procedures development
- Network security architecture
- Encryption and key management
- Vulnerability and threat assessments
- Access controls
- Application security
Independent consulting
Network & Security Consultant (1997 – 2007)
Consultant / contractor supporting enterprise clients across payments, finance, retail, and telecoms.
- PCI DSS and EMV payment initiatives
- Payment card environment security
- Network and systems management
- System and architecture design
- OS hardening and security patching
- Pen-testing
- Payment platform and infrastructure design and implementation
- Technical project management
Selected clients & employers
- Axfood
- GE Money Bank
- Statoil Retail
- WM-data (Axfood)
- OM London
- Giga Real Time Ltd
- Datarutin
- Manpower Technical
- Martinsson Information System / Atea
- Yarrow
Certifications
Edit to match exactly what you want shown publicly.
PCI SSC
- QSA, P2PE Assessor, P2PE Application Assessor
- SSA, SSLCA, QPA, 3DS Assessor, PA-QSA
Information Security
- ISC2: CISSP, CSSLP, CCSP
- ISACA: CISM, CISA, CRISC, CDPSE, CCOA, AAISM
- CSA: CCSK, CCZT
- IAPP: CIPP/E, CIPM
- Ec-Council: C|CISO
Technical - +40 Certifications
- CISCO: CCSP, CCNP, CCDP, CIPT
- MS: MCSE
- Checkpoint: CCSE
- RedHat: RHCE
- and more.....
Credly
Last updated: 2025-12-26.