Andrey Prozorov

CEO

Helsinki, Uusimaa, Finland15 yrs 10 mos experience

Key Highlights

  • Over 15 years of experience in GRC and cybersecurity.
  • Expert in ISO 27001 and GDPR compliance.
  • Creator of practical ISMS and privacy toolkits.
Stackforce AI infers this person is a Cybersecurity and GRC expert with extensive experience in regulatory compliance.

Contact

Skills

Core Skills

Information Security Management System (isms)Iso 27001GrcDoraDpoDlp

Other Skills

CybersecurityPrivacyInformation Security GovernanceGeneral Data Protection Regulation (GDPR)Compliance ManagementPersonal Data ProtectionInformation Security AwarenessPrivacy ComplianceInsider Risk ManagementISMSBusiness ContinuityNetwork SecurityPIMSAIMSOneTrust

About

A highly competent and results-oriented GRC, cybersecurity and privacy expert with over 15 years of experience. I specialise in designing and implementing Information Security and Privacy Management Systems (ISMS, PIMS) and ensuring compliance with a wide range of regulatory and industry requirements and frameworks. I possess a strong understanding of Governance, Risk, and Compliance (GRC) and know how to embed it effectively into organisational processes. I am experienced with leading standards and methodologies, including ISO 27001, ISO 27701, GDPR and EDPB guidelines, NIS 2 Directive, EU DORA, COBIT, NIST CSF, ISF SoGP, IAEA Nuclear Security Series, Katakri, and PMBOK. I also create practical ISMS and privacy toolkits and handbooks for GRC professionals on Patreon, assisting them in accelerating implementation and aligning with complex regulatory requirements and best practices. I am open to new opportunities and always ready to take on challenging projects.

Experience

15 yrs 10 mos
Total Experience
1 yr 10 mos
Average Tenure
--
Current Experience

Finom

Information Security Officer (GRC Lead)

Mar 2024Present · 2 yrs 3 mos · Amsterdam, North Holland, Netherlands · Remote

  • Designed and implemented a company-wide Information Security Management System (ISMS) from the ground up, fully aligned with ISO 27001:2022. Successfully led the organization through its first ISO 27001 certification audit with no major nonconformities.
  • Responsible for developing and continuously improving the cybersecurity Governance, Risk, and Compliance (GRC) framework — including risk assessment, design of security controls, ISMS performance monitoring, reporting, nonconformity management, and coordination of internal and external audits.
  • Ensured compliance with the Digital Operational Resilience Act (DORA) by embedding cybersecurity and resilience principles into key business functions through close collaboration with Legal, Compliance, Risk, and IT departments. Authored the organisation’s Information Security Statement and Digital Operational Resilience Strategy to define a long-term vision for security governance aligned with stakeholders’ needs and expectations.
  • Developed original methods for the integrated implementation of DORA and ISO 27001, enabling streamlined compliance and improved operational efficiency.
Information Security Management System (ISMS)ISO 27001DORACybersecurityGRC

Finnplay technologies oy

Technical Compliance Manager

Oct 2022Mar 2023 · 5 mos · Helsinki, Uusimaa, Finland

  • Led the ISO 27001 implementation project as an architect and project manager. Prepared the ISMS for certification.
  • Responsible for technical compliance across cybersecurity and data privacy domains, ensuring alignment with regulatory requirements and industry best practices.
Information Security Management System (ISMS)General Data Protection Regulation (GDPR)CybersecurityCompliance ManagementISO 27001

Isms pro

Cybersecurity and Privacy Advisor

Jul 2022Present · 3 yrs 11 mos · Helsinki, Uusimaa, Finland

  • Providing strategic cybersecurity and privacy consulting to organizations across sectors, with a focus on regulatory compliance, cybersecurity and operational resilience. Specialising in ISO 27001, ISO 27701, GDPR, NIS 2 Directive, DORA, and NIST CSF.
  • Supporting and mentoring clients in designing and implementing ISMS and privacy programs, conducting gap assessments and audits, developing implementation roadmaps, preparing for certification audits, and delivering training for executives and staff.
  • Serving as a trusted advisor to CISOs, DPOs, and senior leadership to align security and privacy practices with business goals.
  • Serving as an external Data Protection Officer (DPO) for select clients.
  • Additionally, advised GRC vendors on aligning their tools with leading standards and best practices.
Information Security Management System (ISMS)DORAPrivacyInformation Security GovernanceDPOGRC+2

Raos project oy

2 roles

Cybersecurity Expert

Sep 2021Oct 2022 · 1 yr 1 mo

  • Led the design and implementation of a comprehensive cybersecurity program for the Hanhikivi 1 nuclear power plant, ensuring full compliance with IAEA Nuclear Security guidelines, ISA/IEC 62443 standards, and STUK’s regulatory requirements.
  • Managed my team in preparing a complete set of cybersecurity documentation at the nuclear facility level, which was submitted to the Finnish Radiation and Nuclear Safety Authority (STUK) for approval to obtain a construction license.
Information Security Management System (ISMS)ISO 27001Information Security GovernanceCybersecurity

Information Security and Data Protection Lead Manager

Jun 2018Aug 2021 · 3 yrs 2 mos

  • Designed and implemented an Information Security Management System (ISMS) in accordance with ISO 27001, successfully preparing the organisation for initial certification and subsequent re-certifications.
  • Established and managed some information security processes from the ground up, including: Internal Information Security Audits, Monitoring and Evaluation of the ISMS, Information Security in Supplier Relationships (including audits), Information Security Awareness, Information Classification and Handling, Information Security Aspects of Business Continuity Management, Preparing for External Audits (ISO 27001 and KATAKRI), Leading the Information Security Committee meetings.
  • Served as head of the privacy working group and acted as Data Protection Officer (DPO) from September 2019 to August 2021, designed and implemented a comprehensive Privacy Management System in accordance with ISO 27701 with all necessary policies, templates, and processes to ensure GDPR compliance.
Information Security Management System (ISMS)ISO 27001Personal Data ProtectionInformation Security AwarenessGeneral Data Protection Regulation (GDPR)Information Security Governance+3

Freelance

Data Protection Adviser for IT Startups

Sep 2019Jul 2022 · 2 yrs 10 mos

  • Advised startups and helped them develop processes and documents (e.g., Privacy Policy, Privacy Notices, Consents, Data Processing Agreements, DPIA reports, Records of processing activities, Privacy Request Register) for GDPR compliance.
  • Provided tailored guidance to founders, developers, security, legal and compliance teams to embed privacy by design into products and services from the outset.
DPO

Solar security

Cybersecurity Leader

Jul 2015Jun 2018 · 2 yrs 11 mos

  • Responsible for providing methodological expertise, as well as positioning and promoting cybersecurity products (DLP, GRC, IgA, UEBA, source code scanner) and services (SOC and MDR) to enterprise clients and partners.
  • Authored the first edition of the Information Security Risk Management in Outsourcing standard (STO BR IBBS-1.4-2018), published by the Bank of Russia, establishing a regulatory framework for cybersecurity risk management in outsourced services.
GRCISO 27001DLP

Infowatch

Information Security Expert

May 2013Jun 2015 · 2 yrs 1 mo

  • Provided methodological expertise for the development of cybersecurity products, including the DLP solution InfoWatch Traffic Monitor, and delivered consulting services to enterprise clients.
  • Authored the first revision of the Data Leakage Prevention Standard (RS BR IBS-2.9-2016) for the Bank of Russia, establishing regulatory guidance for DLP implementation across the financial sector.
  • Developed a comprehensive DLP implementation toolkit (a set of documents and guidelines on the legal use of DLP from a privacy perspective) and the Insider Threat Mitigation Program to help organisations proactively detect and manage internal security risks.
DLPInsider Risk ManagementCybersecurity

Ibs platformix

Information Security Expert

Jul 2012May 2013 · 10 mos

  • I was responsible for information security, data protection and business continuity consulting.
ISO 27001ISMSBusiness ContinuityCybersecurity

Security analysis

Chief Information Security Officer (CISO)

May 2011May 2012 · 1 yr

  • I was responsible for internal information security as well as external consulting.
ISMSISO 27001PrivacyCybersecurity

Leta it-company

Head of Consulting, Lead Consultant

Apr 2008Sep 2011 · 3 yrs 5 mos

  • I was responsible for information security (ISO 27001, COBIT, ITIL) and privacy consulting (152-FZ). I implemented 4 ISMSs in accordance with ISO 27001 and several privacy management systems to comply with local requirements.
iso27001ISMSISO 27001GRC

Fpd oao rzd (russian railways)

Information Security Specialist

Feb 2007Apr 2008 · 1 yr 2 mos

ISO 27001CybersecurityNetwork Security

Education

Moscow State University of Geodesy and Cartography (MIIGAiK)

Specialist — Information Security

Jan 2003Jan 2008

Stackforce found 100+ more professionals with Information Security Management System (isms) & Iso 27001

Explore similar profiles based on matching skills and experience