Sampo Laine

Director of Global IT & Information Security — building enterprise security programs and driving risk-based controls

Cybersecurity leader with a track record of building security organizations and programs from the ground up and strengthening existing controls across global IT environments. Deep expertise in IT audit and compliance (SOX, PCI DSS), risk management and assessments, vendor risk, internal controls and program management (COBIT/PMO). Proven ability to lead cross-functional teams, partner with executives and stakeholders, and translate business objectives into pragmatic security and control frameworks. Creative problem-solver and motivated self-starter who thrives in collaborative team environments and focuses on reducing risk while enabling business outcomes.
Sampo Laine

Experience

  • Tuxera

    Tuxera

    Director, Global IT and Security

    Jan 2023 - Present

    Tuxera provides quality-assured data storage management software and networking technologies used in billions of embedded and cloud-connected devices. The company focuses on reliable data integrity, high-performance storage, and certifiable solutions for industries including automotive, aerospace, industrial automation, and media workflows.

    • Owned global IT and security strategy for a distributed R&D and commercial organisation supporting embedded and enterprise products.
    • Built and operationalised an information security program (policy, risk assessment, control framework) aligned to embedded-software and certifiable-product requirements.
    • Established vendor/security due‑diligence and third‑party risk processes for firmware, cloud, and SaaS suppliers.
    • Designed incident response and business continuity plans tailored for long‑lifecycle embedded product contexts (OTA, field devices).
    • Led compliance and assurance activities for audits and certifiable products (safety/security evidence, supplier traceability), reducing control gaps across engineering and product teams.
    • Partnered with HR, legal and regional offices to enable secure remote work, cloud adoption and cost‑effective tooling while protecting IP and sensitive customer projects.
  • Arm

    Arm

    Senior Manager, Cybersecurity GRC

    Jun 2018 - Apr 2022

    Arm is a global technology provider of processor IP and software tools, delivering energy‑efficient processor architectures licensed across billions of devices.

    • Directed Cybersecurity GRC for multi‑disciplinary teams, translating board‑level risk appetite into measurable security objectives and control requirements.
    • Built and matured a risk‑based GRC program incorporating policy management, risk assessments, control tracking and automated evidence collection.
    • Operated third‑party risk and supply‑chain assurance processes for IP partners and foundry/OSV ecosystems.
    • Coordinated regulatory and standards alignment (e.g., industry best practices, NIST/ISO mappings) and supported external assurance activities.
    • Implemented recurring stakeholder reporting and dashboards to reduce audit findings and accelerate remediation cycles.
    • Ran cross‑functional security awareness, control ownership and tabletop exercises to strengthen operational readiness.
  • AMD

    AMD

    IT Compliance Manager

    Nov 2014 - Jun 2018

    AMD is a multinational semiconductor company delivering high‑performance computing and graphics solutions across consumer, enterprise and data‑centre markets.

    • Managed enterprise IT compliance across a global hardware and software organisation, focusing on SOX and enterprise control frameworks.
    • Planned and executed internal control testing, gap remediation and process improvements with application and infrastructure owners.
    • Automated control evidence collection and reporting to reduce manual audit effort and improve control transparency.
    • Collaborated with Finance, Security and Engineering to design controls for cloud migrations and new platform rollouts.
    • Coordinated external auditors and prepared executive‑level compliance reporting to reduce remediation backlogs and audit exceptions.
  • DilogR

    Scrum Master, Team Organizer, Product Owner

    Jul 2014 - Oct 2014

    DilogR is a company.

    • Served as Scrum Master/Product Owner across delivery teams, facilitating ceremonies and removing impediments to improve predictability.
    • Organised backlog refinement and release planning to align product outcomes with stakeholder priorities and timelines.
    • Coached teams on agile practices, introducing metrics (velocity, lead time, WIP) to drive continuous improvement.
    • Coordinated cross‑functional stakeholders (design, QA, operations) to streamline delivery and reduce handover delays.
    • Prioritised customer feedback and acceptance criteria to increase delivery of high‑value increments per sprint.
  • Visa Inc.

    Visa Inc.

    Director, Technology Portfolio Management

    Nov 2013 - Jul 2014

    Visa is a global payments technology company connecting consumers, businesses, financial institutions and governments to fast, secure and reliable electronic payments.

    • Directed technology portfolio governance for enterprise and product initiatives, aligning investments to strategic business outcomes.
    • Defined and ran portfolio prioritisation, budgeting and stage‑gate processes to optimise spend and speed to market.
    • Implemented governance for vendor selection, contract governance and risk assessment across platform and payments projects.
    • Coordinated cross‑enterprise roadmaps and dependencies, reducing duplicate spend and accelerating key platform upgrades.
    • Measured portfolio performance using KPIs (ROI, time‑to‑value, risk heatmaps) and reported to senior leadership to inform investment decisions.
  • Visa Inc.

    Visa Inc.

    Director, IT Methodology Management

    Feb 2010 - Nov 2013

    • Led IT methodology strategy and rollout, standardising delivery models (Agile/Hybrid/Waterfall) across global IT teams.
    • Designed governance, templates and training to embed consistent project controls, lifecycle artefacts and decision gates.
    • Drove enterprise adoption of scaled‑Agile and product‑centric delivery practices, improving predictability and release cadence.
    • Introduced metrics and dashboards to measure methodology adoption, delivery quality and cycle time improvements.
    • Partnered with PMO, engineering and security teams to ensure methodology compliance for regulated and mission‑critical projects.
  • Visa Inc.

    Visa Inc.

    Senior IT Auditor

    Oct 2008 - Feb 2010

    • Executed IT audit plans covering infrastructure, applications and cloud services, focussing on controls that support critical payment flows.
    • Performed SOX testing, documented deficiencies and worked with process owners to design and validate remediation.
    • Coordinated with external auditors and internal stakeholders to streamline evidence requests and reduce audit cycle time.
    • Assessed IT general controls, change management, access management and segregation‑of‑duties across global systems.
    • Produced clear risk findings and pragmatic remediation roadmaps that improved control maturity for high‑risk systems.
  • Visa Inc.

    Visa Inc.

    SOX 404 IT Lead

    Mar 2007 - Feb 2010

    • Served as SOX 404 IT Lead, owning scoping, testing and remediation tracking for IT‑dependent controls.
    • Coordinated walkthroughs, control evidence collection and testing scripts with application owners and control custodians.
    • Led deficiency triage and remediation efforts, prioritising fixes with the highest control impact and risk reduction.
    • Implemented process improvements to evidence retention and testing automation, reducing future audit effort.
    • Reported status and residual risk to finance and audit leadership, driving timely closure of material weaknesses.
  • KPMG LLP

    KPMG LLP

    Senior Associate, Information Risk Management

    Jan 2005 - Mar 2007

    KPMG is a global professional services network providing audit, tax and advisory services, including information risk, cybersecurity and regulatory advisory to enterprise clients.

    • Delivered information risk and cybersecurity assessments for clients in regulated industries, identifying control gaps and remediation priorities.
    • Performed control testing and prepared audit deliverables to support client remediation and compliance efforts.
    • Advised on security frameworks and mappings (ISO/NIST) and recommended practical control implementations for enterprise environments.
    • Supported client risk reporting, executive briefings and stakeholder workshops to align security investments with business risk.
    • Contributed to proposal and engagement planning, ensuring scope and resourcing matched client risk profiles.
  • Brigham Young University

    Brigham Young University

    Technical Support Representative

    Dec 2003 - Apr 2004

    Brigham Young University (BYU) is an educational institution offering undergraduate and graduate programs and supporting campus IT and student services.

    • Provided tier‑1 and tier‑2 technical support to students and faculty, resolving hardware, software and access issues.
    • Managed ticket queue, prioritised incidents and communicated status updates to users to maintain high satisfaction.
    • Documented troubleshooting procedures and contributed to knowledge base articles to shorten future resolution times.
    • Collaborated with campus IT teams to escalate complex incidents and support classroom technology availability.
    • Trained new support staff on service processes and customer service best practices.
  • Brigham Young University

    Brigham Young University

    Language Instructor

    Sep 2001 - Dec 2003

    • Planned and delivered language instruction to undergraduate students, creating lesson plans aligned to curriculum objectives.
    • Designed formative and summative assessments to measure student progress and provide actionable feedback.
    • Provided one‑on‑one tutoring and mentoring, improving student retention and course outcomes.
    • Developed course materials and classroom activities to promote engagement and practical language use.
    • Coordinated with department faculty on grading standards and curriculum alignment.
  • FinnYards

    Carpenter/Metal Worker

    Mar 2001 - Jun 2001

    FinnYards is a company.

    • Interpreted technical drawings and blueprints to fabricate and assemble steel and wood components to specification.
    • Operated metal‑working and woodworking equipment (cutting, welding, grinding, finishing) while maintaining quality standards.
    • Performed fitting, alignment and finishing work to ensure assemblies met dimensional and aesthetic requirements.
    • Maintained a safe workshop environment by following PPE and safety procedures and participating in tool maintenance.
    • Collaborated with project leads and tradespeople to meet delivery schedules and project specifications.
  • Greece Athens Mission

    Volunteer Missionary

    Mar 1999 - Mar 2001

    Greece Athens Mission is a missionary organisation conducting community and volunteer activities in the Athens region.

    • Led community outreach and volunteer programs, coordinating events and local partnerships.
    • Delivered public‑facing communications and taught in cross‑cultural contexts, developing language and interpersonal skills.
    • Managed schedules, logistics and small‑team coordination to ensure program coverage and follow‑up.
    • Provided humanitarian assistance and supported local initiatives focused on education and welfare.
    • Demonstrated adaptability and resilience while living and working in a foreign cultural environment.
  • The Finnish Military

    Reserve Lieutenant/Staff Sergeant

    Jul 1996 - Dec 1998

    The Finnish Military is the national defence organisation responsible for Finland’s territorial defence, training conscripts and reservists, and maintaining operational readiness.

    • Led and trained small teams as Reserve Lieutenant/Staff Sergeant, focusing on discipline, readiness and unit cohesion.
    • Planned and executed field exercises, logistics movements and mission‑oriented training operations.
    • Supervised maintenance and accountability of equipment, ensuring operational availability.
    • Provided mentoring and performance feedback to junior personnel, improving team effectiveness.
    • Applied decision‑making under pressure and maintained high standards of security, safety and compliance.

Similar Members

  • Akshi Federici profile image
    Akshi Federici
    Management
    1. BlackRockBlackRock
    2. Boston Consulting Group (BCG)Boston Consulting Group (BCG)
    3. KrakenKraken
    ENTREPRENEURIAL LEADER ✦ STRATEGIC PLANNING ✦ STRATEGIC OPERATIONS ✦ DATA AND ANALYTICS ✦ GROWTH ✦ INDUSTRY EXPERT
    Hire Akshi Federici
  • Alexander Hladky profile image
    Alexander Hladky
    Management
    1. PfizerPfizer
    2. Johnson ControlsJohnson Controls
    3. Phibro Animal HealthPhibro Animal Health
    Global Pharmaceutical Executive | Supply Chain & Procurement Leader | ESG & Quality Advocate
    Hire Alexander Hladky
  • Aaron Vigil-Martinez, MBA profile image
    Aaron Vigil-Martinez, MBA
    word
    1. Indiana Public Retirement SystemIndiana Public Retirement System
    2. Sidley Austin LLPSidley Austin LLP
    3. JHTJHT
    Strategic Innovator Bridging Life Sciences and Public-Private Partnerships
    Hire Aaron Vigil-Martinez, MBA