Stefan Lund
Senior Consultant, QSA at SecureTrust- Claim this Profile
Click to upgrade to our gold package
for the full feature experience.
Topline Score
Bio
Experience
-
SecureTrust
-
United States
-
Computer and Network Security
-
1 - 100 Employee
-
Senior Consultant, QSA
-
Nov 2015 - Present
Stockholm, Sweden Security consultant regardning PCI related security.
-
-
-
ÅF
-
Sweden
-
Civil Engineering
-
700 & Above Employee
-
Senior Consultant
-
Dec 2014 - Nov 2015
Uppsala, Sweden
-
-
-
-
Consultant, owner.
-
2004 - Dec 2014
Alingsås Design and review of security systems relating to payment cards. Security groups • Chairman of PNC SAC for 3 years. This includes defining rules for PNC. Reviewing and commenting on rules from PCI, SEPA and EPAS. Representing PNC in EPAS work.’ • Participated in “BCA SEC”, a Swedish bank security committee that later became PNC SAC for the Nordic area. • Participated in “BCA Spec.”, a Swedish bank organization that worked with Security Specifications. PCI review/QSA… Show more Design and review of security systems relating to payment cards. Security groups • Chairman of PNC SAC for 3 years. This includes defining rules for PNC. Reviewing and commenting on rules from PCI, SEPA and EPAS. Representing PNC in EPAS work.’ • Participated in “BCA SEC”, a Swedish bank security committee that later became PNC SAC for the Nordic area. • Participated in “BCA Spec.”, a Swedish bank organization that worked with Security Specifications. PCI review/QSA related • Approximately 100 code reviews of PED applications according to rules of Swedish banks. • Approximately 30 hardware reviews according to rules of PNC SAC. (PNC extended rules to PCI PED 1.3/2.1 and PCI PTS) • Approximately 30 reviews of UPTs (Unattended Payment Terminals) according to rules of PNC SAC and BSK (Bankens Standardiserings Kontor, Norway) • 4 PNC E2EE reviews. According to PNC rules. Similar to PCI E2EE (P2P). • Review of HSM configurations used by collectors in Sweden. • Supported Swedish banks and Swedish police in more than 15 skimming cases. • Attended as expert witness in PIN fraud case in Swedish court. Design and implementation • Designed HSM used by PSP • Designed and implemented signing system for PED FW and display text. • Designed key management and communication protocol for device used for EMV based mobile payment. (Patent holder) • Designed and implemented complete PED application running in Swedish PED. • Designed PED application used in connection with mobile payments to be used worldwide. • Designed and implemented scanning tool for track2 and PAN in servers running at vendors. (used in skimming cases) • Design of PIN printing systems. • Design of Key Management Systems. • Design and implementation of PED management systems, including key loading. • Design and implementation of data encryption programs used for PCI DSS compliance. Teacher: • EMV • Cryptography, basic course • Cryptography and Key Management • PED Lifecycle (How PED works and operates) Show less
-
-
-
-
Consultant
-
2004 - 2004
Göteborg, Köln New network concept for Volvo/Ford.
-
-
-
-
Consultant
-
2002 - 2003
Göteborg Volvo PV - Infotainment. SAAB Automobil - Infotainment, gearbox display.
-
-
-
-
Consultant, owner, C.E.O.
-
2000 - 2002
Bollebygd Ericsson - Java, XML, Chalmers - teacher C+Lab Windows, Nohau - teacher C for safety critical systems. SecureCom - Implemented DUKPT 3DES. Performance optimizing server.
-
-
-
-
Consultant
-
2001 - 2001
Göteborg Carmen - Unix, C++
-
-
-
-
Consultant
-
1997 - 2000
Göteborg Teacher C basic, C Advanced, C realtime programming, Web master. Volvo PV - Mesc project, Statemate, CAN, Canalyzer, Volcano, PVCS. Volvo trucks - C programming and design. Code review. Visual source safe.
-
-
-
-
designer, technical project leader
-
1995 - 1997
Mölndal TIMS (BSS) design, EHS/LB C programming, teaching, UNIX, Oracle.
-
-
Support
-
1994 - 1995
Mölndal TMOS Global Support Centre (EHS/AG). TMOS support, TR handling, UNIX, SUN, HP. TMOS installation on test site. Sybase.
-
-
-
-
designer, programmer
-
1991 - 1993
Alingsås Programming, embedded systems (ATM/PED/Chip cards)
-
-
-
-
Designer
-
1989 - 1990
Mölndal Programming payment ICA including new payment terminal for credit cards.
-
-
-
-
Teacher
-
1986 - 1988
Göteborg Teacher programming techniques. Z, E, D, V and DDA.
-
-
-
-
programming, test
-
1985 - 1985
Västerås Electronics and programming during summer.
-
-
-
-
Tester
-
1984 - 1984
Västerås Testing of industry robots.
-
-
Education
-
Chalmers University of Technology
MSc, Electronics -
Kungliga tekniska högskolan
MsC, Electronics