AI Governance & Regulated Systems Leader

From regulated code
to trustworthy AI.

22 years of experience building and operating governance, risk and compliance frameworks for highly regulated software systems. I translate regulatory expectations into working controls — and now bring that discipline to AI governance.

GENEVA, SWITZERLAND  ·  Open to full-time roles, mandates & partnerships

Tobias Gorsleben, AI Governance & Regulated Systems Leader AI-Ready Software & Systems Leader
Switzerland — based in Geneva, unrestricted right to work
German, English & French — native or full professional fluency
20+ years of governance, risk & compliance in highly regulated systems
Hands-on experience with review boards, audits & senior-management reporting
Portrait of Tobias Gorsleben

Positioning

Governance isn’t a brake — it’s what makes scale possible.

For 22 years I’ve designed and operated governance, risk and compliance frameworks for highly regulated software systems — from component-level risk classification to company-wide certification under ISO 27001, IEC 62304 and ISO 14971. The discipline is industry-agnostic: it starts with a risk register, runs on review boards and approval gates, and only holds up when engineering, legal, compliance and senior management speak the same language.

The standards now shaping AI regulation — ISO/IEC 42001, the NIST AI RMF — echo much of what I’ve spent years operationalizing in MedTech: risk classification by use context, independent validation, airtight documentation, continuous monitoring. I’m bringing that governance discipline to where it’s needed most right now.

“Governance is the difference between a pilot that never ships and a system people can actually trust.”

Three companies, one continuous flow

The Journey

Through three company transitions — from Biosafe, through GE HealthCare, to Cytiva (Danaher) — he never let go of governance ownership; each move raised it a level, from component-level risk to enterprise-wide security and quality governance.

Principal Software Engineer 04/2020 – 01/2026 · 5Y 10M
Cytiva (Danaher) · Grens, Switzerland
  • As Privacy & Security Representative, designed and enforced ISO 27001 governance standards for biomedical platforms at enterprise scale
  • Established vulnerability management, response procedures and CIS hardening as recurring control processes
  • Led global engineering teams, serving as a cross-functional expert between engineering, quality and compliance
  • Stabilized product quality to zero critical bugs while the business scaled in maturity
Software Technical Leader 08/2016 – 04/2020 · 3Y 9M
GE HealthCare · Eysins, Switzerland
  • Drove the software evolution of market-leading cell-processing platforms (Sefia, Sepax, Smart-Max), including ISO 14971 risk classification, from startup innovation to global scale
  • Built and led a 9-person local team plus international offshore units to deliver the flagship Sefia Select platform
  • Pioneered cloud and on-premise lab infrastructure (Chronicle) while meeting CSV and data-protection requirements
Software Technical Leader → Senior R&D Engineer, PM 10/2009 – 07/2016 · 6Y 10M
Biosafe SA · Eysins, Switzerland
  • Held technical responsibility for risk management (dFMEA/pFMEA) and the software portfolio across cell therapy, bioprocessing, regenerative medicine and cord blood banking
  • Shaped the IEC 62304-compliant software development of medical devices Sepax 2 and SepaxNet from the ground up

Earlier: SpinX Technologies, Bytewert, IngMar Medical, Cordylus (Founder) — stops ranging from molecular-diagnostics startups to freelance projects and his own multimedia agency in Berlin.

Four modules, one system

Core Expertise

The same governance discipline, applied to a new class of systems — from medical devices to AI.

GOV

Governance Frameworks

  • Policies, standards & controls aligned to risk appetite (GAMP5, CSV)
  • IEC 62304, ISO 60601, ISO 61010 — lifecycle governance from PoC to production
  • ISO 14971 — risk classification / FMEA (dFMEA, pFMEA)
  • MD / non-MD classification, CRA, component matrix HW/SW/µC/App/OS
RISK

Risk & Security Governance

  • Privacy & Security Representative, ISO 27001 — directly transferable to responsible-AI & privacy-by-design controls
  • Vulnerability management & response procedures (incl. risk assessment)
  • CIS Benchmark / OS hardening, isolated networks
  • Penetration testing (Kali Linux, SQL injection), SAST/DAST
SYS

Technical Fluency

  • Software development & deployment, across product lines — understanding systems well enough to assess risk credibly
  • Systems for high-throughput & liquid-processing at scale
  • Robotics integration, application design (UCD)
LEAD

Stakeholders & Governance Forums

  • Review boards, approval gates & agile governance rhythms (Scrum of Scrums, daily management)
  • Project & visual project management (VPM)
  • Internal training & AI-literacy programs, audit reports
  • Certified in communicating to senior management & key stakeholders

By the numbers

Selected Impact

22
Years of governance, risk & compliance experience in regulated systems
3
Company transitions steered with unbroken governance continuity
9+
People in the core team he led directly, plus global offshore units
0
Critical bugs in the stabilized product — business maturity at full quality

The fine print

Languages, Certifications & Education

Languages

  • GermanNative
  • FrenchFull professional
  • EnglishFull professional
  • SpanishProfessional working
  • RussianElementary

Certifications

  • Quality for Medical Software
  • AABB Cellular Therapies Certificate Program
  • Communicating to Senior Management & Key Stakeholders
  • Creativity Training

Education

  • MSc Biomedical EngineeringUniversität zu Lübeck, 2003 – 2006
  • Dipl.-Inf. (FH) / MSc Computer ScienceUniversity of Applied Sciences Berlin (FHTW), 1998 – 2002

Next step

Let’s talk.

I’m looking for my next mission — with a focus on AI governance, risk & compliance in regulated environments. As a full-time role, a strategic mandate, or an entrepreneurial partnership. If you’re building a resilient governance structure for AI, I’d love to hear from you.

Tobias Gorsleben smiling