AI Governance & Regulated Systems Leader
From regulated code
to trustworthy AI.
22 years of experience building and operating governance, risk and compliance frameworks for highly regulated software systems. I translate regulatory expectations into working controls — and now bring that discipline to AI governance.
AI-Ready Software & Systems Leader
Positioning
Governance isn’t a brake — it’s what makes scale possible.
For 22 years I’ve designed and operated governance, risk and compliance frameworks for highly regulated software systems — from component-level risk classification to company-wide certification under ISO 27001, IEC 62304 and ISO 14971. The discipline is industry-agnostic: it starts with a risk register, runs on review boards and approval gates, and only holds up when engineering, legal, compliance and senior management speak the same language.
The standards now shaping AI regulation — ISO/IEC 42001, the NIST AI RMF — echo much of what I’ve spent years operationalizing in MedTech: risk classification by use context, independent validation, airtight documentation, continuous monitoring. I’m bringing that governance discipline to where it’s needed most right now.
“Governance is the difference between a pilot that never ships and a system people can actually trust.”
Three companies, one continuous flow
The Journey
Through three company transitions — from Biosafe, through GE HealthCare, to Cytiva (Danaher) — he never let go of governance ownership; each move raised it a level, from component-level risk to enterprise-wide security and quality governance.
- As Privacy & Security Representative, designed and enforced ISO 27001 governance standards for biomedical platforms at enterprise scale
- Established vulnerability management, response procedures and CIS hardening as recurring control processes
- Led global engineering teams, serving as a cross-functional expert between engineering, quality and compliance
- Stabilized product quality to zero critical bugs while the business scaled in maturity
- Drove the software evolution of market-leading cell-processing platforms (Sefia, Sepax, Smart-Max), including ISO 14971 risk classification, from startup innovation to global scale
- Built and led a 9-person local team plus international offshore units to deliver the flagship Sefia Select platform
- Pioneered cloud and on-premise lab infrastructure (Chronicle) while meeting CSV and data-protection requirements
- Held technical responsibility for risk management (dFMEA/pFMEA) and the software portfolio across cell therapy, bioprocessing, regenerative medicine and cord blood banking
- Shaped the IEC 62304-compliant software development of medical devices Sepax 2 and SepaxNet from the ground up
Earlier: SpinX Technologies, Bytewert, IngMar Medical, Cordylus (Founder) — stops ranging from molecular-diagnostics startups to freelance projects and his own multimedia agency in Berlin.
Four modules, one system
Core Expertise
The same governance discipline, applied to a new class of systems — from medical devices to AI.
Governance Frameworks
- Policies, standards & controls aligned to risk appetite (GAMP5, CSV)
- IEC 62304, ISO 60601, ISO 61010 — lifecycle governance from PoC to production
- ISO 14971 — risk classification / FMEA (dFMEA, pFMEA)
- MD / non-MD classification, CRA, component matrix HW/SW/µC/App/OS
Risk & Security Governance
- Privacy & Security Representative, ISO 27001 — directly transferable to responsible-AI & privacy-by-design controls
- Vulnerability management & response procedures (incl. risk assessment)
- CIS Benchmark / OS hardening, isolated networks
- Penetration testing (Kali Linux, SQL injection), SAST/DAST
Technical Fluency
- Software development & deployment, across product lines — understanding systems well enough to assess risk credibly
- Systems for high-throughput & liquid-processing at scale
- Robotics integration, application design (UCD)
Stakeholders & Governance Forums
- Review boards, approval gates & agile governance rhythms (Scrum of Scrums, daily management)
- Project & visual project management (VPM)
- Internal training & AI-literacy programs, audit reports
- Certified in communicating to senior management & key stakeholders
By the numbers
Selected Impact
The fine print
Languages, Certifications & Education
Languages
- GermanNative
- FrenchFull professional
- EnglishFull professional
- SpanishProfessional working
- RussianElementary
Certifications
- Quality for Medical Software
- AABB Cellular Therapies Certificate Program
- Communicating to Senior Management & Key Stakeholders
- Creativity Training
Education
- MSc Biomedical EngineeringUniversität zu Lübeck, 2003 – 2006
- Dipl.-Inf. (FH) / MSc Computer ScienceUniversity of Applied Sciences Berlin (FHTW), 1998 – 2002
Next step
Let’s talk.
I’m looking for my next mission — with a focus on AI governance, risk & compliance in regulated environments. As a full-time role, a strategic mandate, or an entrepreneurial partnership. If you’re building a resilient governance structure for AI, I’d love to hear from you.