ISO 27001 Lead Auditor · Product & GRC Leader · Author
I am a product leader and ISO/IEC 27001:2022 Lead Auditor (CQI/IRCA) based in Dubai, building software since 2008 across SaaS, fintech, payments, and enterprise platforms. Today I lead Product, Payments Risk & GRC at Meshtally, consult through SodaSoft, and advise Decot - with a growing focus on security governance, ISMS readiness, and ISO 27001 audit preparation. Former Head of Product at Webio (acquired by Aryza).

The story
Some businesses fail loudly. Others drift quietly for years. They add more pages, more offers, more features, more language, and somehow become harder to explain with every step. I have spent most of my career inside that problem, as someone doing the work.
I started in 2008 as a UI/UX designer. That taught me how people move, where they hesitate, and why friction usually starts long before anyone calls it a business issue. Design pulled me into product. Product pulled me into strategy. Strategy pulled me into the harder question behind most stalled companies: what are we actually building, for whom, and why should anyone care?
That question has followed me through enterprise software, payments, collections, regulated platforms, mobile products, specialist hiring, and venture building. As Chief User Experience Architect at Crossover (ESW Capital), I led UX architecture across 10+ enterprise platforms used inside a 130+ country distributed organization. As Chief Product Officer at Skout Deals, I shipped a B2C mobile platform end to end and cut customer churn by over 32% through clearer value delivery. At Japan Tobacco International I defined a global data visualization strategy and worked on Microsoft HoloLens prototypes for industrial use cases.
Most recently, as Head of Product at Webio, I led the product function for a conversational AI platform serving Tier 1 enterprise clients in collections and payments. That work helped shape the product foundation behind Webio being acquired by Aryza in 2025.
Lately, a deliberate move toward security governance.
The regulated edge of that work - audit preparation, control monitoring, evidence for enterprise buyers - is where I increasingly spend my time. I am an ISO/IEC 27001:2022 Lead Auditor (CQI/IRCA, TÜV SÜD) and an IRCA Associate ISMS Auditor, and since 2025 my advisory work has increasingly focused on security governance, ISMS readiness, and ISO 27001 audit preparation for SaaS, fintech, and payment companies.
As Managing Director for Product, Payments Risk & GRC at Meshtally, I own the intersection of product, payments risk, and governance for a payment orchestration platform (PSP routing, failed-payment reduction, settlement clarity) selected into Antler Dubai Residency and Web Summit Qatar 2026. In parallel I am building Nanotesting, an automated security assessment platform that runs the boring half before a pentester arrives and helps founders and security teams produce ISO 27001 and SOC 2 evidence.
Through SodaSoft, the independent practice I have run since 2014, I now work as Principal Consultant on product, delivery, and GRC - covering product strategy, QA governance, operational control, and ISO 27001 audit-preparation for SaaS, fintech, and payment companies. I also advise Decot as Product Strategist Advisor on contract governance, auditability, and GRC.
I have published two books written from this operator perspective: How to Niche Down (and Actually Make Money) and 7 Days to Your Fintech PM Offer. They are field-tested playbooks, not motivational reading.
That is the work. Practical, repeatable, and grounded in what buyers will actually pay for, not what looks good in a deck.
MSc Computer Science (Informatics)
Fimek, Novi Sad - completed 2025
UX and Interaction Design
The Interaction Design Foundation
LLB Bachelor of Laws
Pravni fakultet, Novi Sad
ISO/IEC 27001:2022 Auditor/Lead Auditor
CQI/IRCA certified - TÜV SÜD (UDN 712121)
IRCA Associate Auditor - ISMS
IRCA Membership 6238588
Lean Six Sigma - Black Belt (Educate 360)
Google Cybersecurity Specialization
English bilingual
Serbian native
Croatian native