
Head DDIT ISC Software Development Governance, Integrity & Secure Software Development Life Cycle (SDLC)
Novartis4 days ago
Barcelona, SpainStaff+
Responsibilities
- Own enterprise policies, standards, and controls for source control, branching, peer review, testing, release management, change control, configuration, and release documentation.
- Consolidate GxP, SOX, privacy, security, and IT-quality requirements into a risk-based SDLC governance framework.
- Implement policy as code and controls as code for branch protection, mandatory review, signed commits, segregation of duties, deployment approvals, and immutable audit trails.
- Build automated evidence pipelines and define telemetry for coverage, exceptions, drift, remediation time, and control effectiveness.
- Establish secure-by-default guardrails in golden pipelines and paved-road platforms aligned with applicable recognized frameworks.
- Define governance for AI-assisted software engineering and AI-containing products, including acceptable use, provenance, model lifecycle, evaluation, drift monitoring, explainability, and human oversight.
- Use AI to automate risk assessment, control mapping, test generation, deviation triage, and documentation synthesis.
- Lead a federated community of engineering, quality, security, and compliance practitioners and advise senior stakeholders, auditors, and inspectors.
Requirements
- Substantial current hands-on software engineering experience, including production coding, CI/CD pipeline ownership, and the ability to modify pipeline configuration, infrastructure-as-code, and policy code independently.
- At least 10 years of experience in software engineering, platform engineering, DevSecOps, or engineering quality, including senior technical ownership of delivery pipelines at scale.
- Experience designing and operating automated controls in regulated environments and replacing manual compliance work with software.
- Working fluency with GxP, GAMP 5 2nd Edition, CSA, 21 CFR Part 11, EU Annex 11, and ALCOA+ data-integrity principles.
- Security engineering depth in application security, software supply-chain security, secrets and identity management, and vulnerability management.
- Technical judgment concerning AI in the SDLC and its governance implications.
- Ability to influence without authority across engineering, quality, business, senior stakeholders, and auditors.
- Excellent written English.
- Preferred experience in pharma, biotech, medical devices, finance, aviation, nuclear, inspections, or audits.
- Preferred experience with SOX ITGC, IEC 62304, software as a medical device, GDPR privacy by design, Git-based platforms, container orchestration, cloud, infrastructure as code, policy engines, test automation, SBOM, and signing tooling.
Benefits
- Annual base salary range of €92,600.00–€172,000.00, with potential performance-based bonus.
- Barcelona, Spain location with flexible and hybrid working options where possible.
- Insurance plans, retirement plans, wellbeing resources, and global recognition programs.
- Minimum 14 weeks of paid parental leave.
- Benefits and compensation vary by country and applicable local legal requirements.
About Novartis
Novartis is an innovative medicines company. Every day, working to reimagine medicine to improve and extend people’s lives so that patients, healthcare professionals and societies are empowered in the face of serious disease. Our medicines reach more than 250 million people worldwide. Find out more at https://www.novartis.com See our community guidelines: https://go.novartis.social/3Nboxki