Skip to content
View pethers's full-sized avatar

Organizations

@Hack23

Block or report pethers

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
pethers/README.md

Security & Open Source Expert | Cloud Security Specialist | Information Security Professional

Website LinkedIn GitHub OpenHub

About Me

Experienced security professional with over 30 years in information technology, specializing in security architecture, cloud security, and compliance. Currently serving as Application Security Officer at Stena Group IT, with prior roles including Information Security Officer at Polestar and Senior Security Architect at WirelessCar. Strong advocate for transparency in organizations, secure software development practices, and innovative open source solutions.

I develop advanced open source tools focused on:

  • 🔐 CIA Triad (Confidentiality, Integrity, Availability)
  • 📊 Compliance Management
  • 🔍 Political Transparency
  • ☁️ Secure Cloud Architectures

GitHub Org's stars GitHub stats

Professional Certifications

CISSP CISM AWS Security AWS Solutions Architect

Featured Projects

🔐 CIA Compliance Manager

CIA Compliance Manager Logo

Security assessment platform for the CIA triad with compliance mapping to regulatory frameworks

License CII Best Practices SLSA 3

🔍 Citizen Intelligence Agency

CIA Logo

Political transparency platform monitoring Swedish political activity with data-driven insights

License CII Best Practices SLSA 3

☁️ Lambda in Private VPC

AWS Lambda

Multi-region active/active site leveraging Resilience Hub policy compliance and runbooks

License OpenSSF Scorecard

🧪 Sonar-CloudFormation-Plugin

SonarQube Plugin

SonarQube plugin for analyzing AWS CloudFormation templates with security best practices

License CII Best Practices

Project Architecture & Documentation

Project Current Architecture Security Architecture Future Vision
CIA Compliance Manager 🏛️ Architecture 🔒 Security 🔮 Future
Citizen Intelligence Agency 🏛️ Architecture 🔒 Security 🔮 Future
Project Process Flows State Diagrams Mindmaps
CIA Compliance Manager 📊 Flowcharts 🔄 States 🧠 Mindmaps
Citizen Intelligence Agency 📊 Flowcharts 🔄 States 🧠 Mindmaps

Professional Experience & Skills

%%{
  init: {
    'theme': 'base',
    'themeVariables': {
      'primaryColor': '#a0c8e0',
      'primaryTextColor': '#1a1a1a',
      'primaryBorderColor': '#86b5d9',
      'lineColor': '#86b5d9',
      'secondaryColor': '#c8e6c9',
      'tertiaryColor': '#ffda9e'
    }
  }
}%%
mindmap
  root((James Pether<br>Sörling))
    Information Security
      ::icon(fa fa-shield)
      Risk Assessment & Management
      CISSP & CISM Certified
      Security Architecture Design
        Zero Trust Principles
        Defense-in-Depth
      Compliance Frameworks
        ISO 27001
        NIST 800-53 
        VDA-ISA
        CIS Controls
        GDPR
      Security Operations
        Incident Response
        Vulnerability Management
        Security Monitoring
    Cloud Security
      ::icon(fa fa-cloud)
      Multi-Cloud Expertise
        AWS Advanced
        Microsoft Azure
      Enterprise Architecture
        High Availability Designs
        Multi-Region Deployments
        Resilience Engineering
      Infrastructure as Code
        CloudFormation
        Terraform
      Secure Cloud Services
        AWS Security Hub
        AWS GuardDuty
        KMS Encryption
        AWS WAF
    Leadership & Governance
      ::icon(fa fa-users)
      Information Security Officer
      Security Architect
      Policy Development
      IT Governance
      Team Leadership
      Open Source Program Office
      AI Governance & Security
    Software Engineering
      ::icon(fa fa-code)
      Secure Development (SSDLC)
      Java/Spring Full-Stack
      TypeScript/JavaScript/React
      Automated Testing
      CI/CD Pipelines
      Code Quality
        SLSA Level 3
        SonarQube
    Open Source Leadership
      ::icon(fa fa-github)
      Project Creator & Maintainer
      Community Contributor
      Security Tool Development
      Code Review
Loading

Technology & Skills

Security & Compliance

Security Architecture Risk Management ISO 27001 NIST 800-53 GDPR CIS Controls Vulnerability Management Incident Response SSDLC AI Governance Information Security Governance Security Compliance IT Audit Information System Audit

Cloud & Infrastructure

AWS CloudFormation Azure Lambda Terraform Docker Linux Unix Security Hub GuardDuty Cloud Computing Solution Architecture

Development & Languages

Java Spring TypeScript JavaScript React PostgreSQL Hibernate REST APIs Maven Software Development Software Engineering

DevOps & Tools

SonarQube GitHub Actions Jenkins ElasticSearch Kibana OWASP ZAP cfn-nag SLSA IT Operations

Leadership & Management

Leadership Security Management Information Security Management Team Management Policy Development Open Source Program Office Organizational Leadership People Management Strategic Planning

Additional Skills

Artificial Intelligence Open Source Digital Transformation Cyber Insurance Six Sigma Black Belt Business Strategy Corporate Finance ESG

Career Highlights

%%{
  init: {
    'theme': 'base',
    'themeVariables': {
      'primaryColor': '#d1c4e9',
      'primaryTextColor': '#1a1a1a',
      'primaryBorderColor': '#9575cd',
      'lineColor': '#9575cd',
      'secondaryColor': '#bbdefb',
      'tertiaryColor': '#c8e6c9'
    }
  }
}%%
timeline
    title Professional Journey
    section Enterprise Security
      2024 : Application Security Officer, Stena Group IT
            : Risk Assessment, Cloud Security, Microsoft Azure, AI Governance
      2022 - 2024 : Information Security Officer, Polestar
            : ISMS Implementation, Security Compliance, Risk Management, OSPO Lead
      2018 - 2022 : Senior Security Architect, WirelessCar
            : Security Architecture, AWS Security, Secure Development Practices
    section Cloud & Security Engineering
      2017 - 2018 : Consultant, Consid AB
            : Open Source Development, CI/CD, Docker, AWS
      2010 - 2017 : Cloud Architect, Keypasco
            : Cloud Security Solutions, Multi-Tier Architecture, AWS Infrastructure
    section Software Development
      2008 - 2009 : Consultant, Redpill Linpro
            : Technical Support, System Administration, Development
      2006 - 2007 : System Developer, Sky
            : J2EE Projects, Agile Development, Test-Driven Development
      2003 - 2005 : J2EE Developer, Glu Mobile
            : Mobile Services, Integration
      2000 - 2002 : Software Engineer, Volantis Systems
            : Multi-Channel Server Product Development
Loading

Project Badges & Status

CIA Compliance Manager

GitHub Release License FOSSA Status CII Best Practices OpenSSF Scorecard SLSA 3

Citizen Intelligence Agency

GitHub Release CII Best Practices OpenSSF Scorecard SLSA 3 Quality Gate Status Security Rating


Notable Contributions & Appearances

  • Information Security Officer at Polestar, leading security practices and the Open Source Program Office
  • Senior Security Architect at WirelessCar, supporting secure delivery practices and security risk management
  • Open source contributor for cfn-nag, developing integration with SonarQube for CloudFormation security analysis
  • Speaker at Javaforum Göteborg on secure architecture patterns
  • Guest on Shift Left Like A Boss security podcast
  • Featured in Computer Sweden and Riksdag och Departement for political transparency work
  • Mentioned in National Democratic Institute survey on parliamentary monitoring organizations
  • Operated Equal Rites BBS in the 1990s, part of Fidonet (Node 2:203/454)
  • committers.top badge

Connect With Me

LinkedIn GitHub Blog Tech Talks

Profile Views

Last updated: 2025-05-13 09:23:38

Pinned Loading

  1. Hack23/cia Hack23/cia Public

    Comprehensive open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government institutions, and parliamentary data, offering…

    Java 169 46

  2. Hack23/talks Hack23/talks Public archive

    How to secure your development pipeline with static application security test (SAST) / Dynamic application security test (DAST), software composition analysis (SCA) using Sonarqube.

    6

  3. Hack23/cia-compliance-manager Hack23/cia-compliance-manager Public

    The CIA Compliance Manager is an application that helps organizations assess and manage the availability, integrity, and confidentiality of their systems and data based on customizable security lev…

    TypeScript 6 3

  4. Hack23/homepage Hack23/homepage Public

    Webpage for org https://hack23.com

    HTML 2 1