
Head DDIT ISC Software Development Governance, Integrity & Secure Software Development Life Cycle (SDLC)
Novartis5 days ago
Prague, CzechiaStaff+
Responsibilities
- Own enterprise policies, standards, and controls covering source control, branching, peer review, testing, release management, environments, change control, configuration, and release documentation.
- Rationalize GxP, SOX, privacy, security, and IT-quality requirements into a risk-based SDLC framework.
- Implement policy-as-code and controls-as-code for branch protection, mandatory review, signed commits, segregation of duties, deployment approvals, and immutable audit trails.
- Build automated evidence pipelines and control telemetry covering coverage, exceptions, drift, remediation time, and control effectiveness.
- Establish secure-by-default guardrails in golden pipelines and paved-road platforms aligned with applicable recognized frameworks.
- Define governance for AI-assisted engineering and AI-containing products, including acceptable use, intellectual property, provenance, model lifecycle, evaluation, monitoring, explainability, and human oversight.
- Use AI to automate risk assessment, control mapping, test generation, deviation triage, and documentation synthesis.
- Lead a federated community of engineering, quality, security, and compliance practitioners and advise senior stakeholders, auditors, and inspection teams.
Requirements
- Substantial hands-on software engineering experience, including production code, CI/CD pipeline ownership, and the ability to modify pipeline configuration, infrastructure-as-code, and policy code independently.
- 10+ years of experience in software engineering, platform engineering, DevSecOps, or engineering quality, including senior technical ownership of delivery pipelines at scale.
- Experience designing and operating automated controls in regulated environments and replacing manual compliance work with software.
- Working fluency with GxP, GAMP 5 (2nd Edition), CSA, 21 CFR Part 11, EU Annex 11, and ALCOA+ data integrity principles.
- Security engineering depth in application security, software supply chain security, secrets and identity management, and vulnerability management.
- Technical judgment regarding AI in the SDLC, including both AI tooling and governance implications.
- Ability to influence without authority across engineering, quality, and business organizations and engage senior stakeholders and auditors.
- Excellent written English.
- Preferred experience includes pharma, biotech, medical devices, finance, aviation, nuclear, inspection or audit exposure, SOX ITGC, IEC 62304/SaMD, privacy by design under GDPR, Git-based platforms, container orchestration, cloud, infrastructure-as-code, policy engines such as OPA/Rego, test automation, SBOM, and signing tools.
Benefits
- Annual base salary range is 2,292,080.00–4,256,720.00 CZK, with potential performance-based bonus eligibility.
- Benefits include insurance plans, retirement plans, wellbeing resources, global recognition programs, flexible and hybrid working options where possible, and at least 14 weeks of paid parental leave.
- Benefits and compensation may vary by country and local legal requirements.
About Novartis
Novartis is an innovative medicines company. Every day, working to reimagine medicine to improve and extend people’s lives so that patients, healthcare professionals and societies are empowered in the face of serious disease. Our medicines reach more than 250 million people worldwide. Find out more at https://www.novartis.com See our community guidelines: https://go.novartis.social/3Nboxki