Skip to main content
ProfileConfidential

Tobias Lekman

Cloud & Security ArchitectManaging Director

25 years building secure digital solutions across startup incubators, SMBs, and regulated industries. I specialise in making security and compliance work at any scale, helping teams ship software faster without compromising on security or quality.

My expertise spans secure SDLC, Zero Trust architectures, and DevSecOps across AWS, Azure, and Google Cloud. I lead compliance initiatives in heavily regulated environments (GxP, SaMD, HIPAA) while maintaining rapid delivery cycles. I believe security should enable, not block, business goals.

Education
Information TechnologyOxford
Information TechnologyOpen University
Computer ScienceHarvard
Artificial IntelligenceMicrosoft / edX
Mobile App DevelopmentHarvard / edX
Certifications
Microsoft Azure Solutions ArchitectMicrosoft Cyber Security ArchitectMicrosoft Azure AdministratorMicrosoft Azure DevOps EngineerMicrosoft Certified TrainerAmazon AWS Solutions ArchitectAmazon AWS DevOps EngineerScaled Agile SAFe ArchitectScaled Agile SAFe DevOpsOpen Group TOGAF
01Service offerings

Enterprise Architecture

Business, data, application, and technology architecture. TOGAF-based frameworks, integration patterns, and governance strategies.

Deployment & Planning

On-site expertise for cloud and hybrid deployments across AWS, Azure, GCP. Migration planning, landing zones, multi-region.

DevOps Design & Execution

CI/CD pipeline design, GitOps, infrastructure-as-code with Terraform/Pulumi/CDK, zero-manual-change deployment.

Health & Risk Assessments

Security posture reviews, compliance gap analysis, and risk assessments against NIST, ISO 27001, CIS, GxP, DORA.

Quality Assurance

Secure SDLC, automated compliance checks, SAST/DAST integration, and audit-ready documentation for regulated environments.

Training & Ramp-up

Hands-on workshops in cloud architecture, secure coding, DevSecOps, and AI/ML. Delivered onsite and remotely across global teams.

02Tools & technologies
Azure
SQL Server · CosmosDB · Data Lake · Synapse · Data Factory · Fabric · ML/AI · Spark
AWS
KMS · Shield · WAF · CDK · Control Tower · ECS · EKS · Aurora · Redshift · DMS
Security standards
NIST SP 800-53 · ISO/IEC 27001:2022 · CIS Controls v8 · CIS Benchmarks
Security tools
GitHub Advanced Security · Snyk · SonarQube · 42Crunch · Semgrep · BurpSuite
Languages
C# · TypeScript/Node · Python · Kotlin/Java · Swift · PowerShell · Bash
Frameworks
.NET · React · Next.js · Express · FastAPI · Swift PM
DevOps & CI/CD
Azure DevOps · GitHub Actions · ArgoCD · Terraform · Bicep · Pulumi · CDK
Observability
Azure Monitor · App Insights · CloudWatch · Grafana · Prometheus · OpenTelemetry
Containers
Azure ACA · EKS / ECS / Fargate · Docker · Consul
Regulatory
GxP (21 CFR Part 11) · HIPAA · SaMD · ISO 13485 · IEC 62304 · GDPR · DORA
03Confidential record

Full client list & recent engagements.

🔒Confidential · access required

The complete client roster and the detailed engagement records include assignments that are not publicly listed. This material is confidential and shown to verified clients and partners only.

Enter the access password to view the confidential record.