
Head DDIT ISC Software Development Governance, Integrity & Secure Software Development Life Cycle (SDLC)
Novartis5 days ago
Hyderābād, IndiaStaff+
Responsibilities
- Own enterprise software engineering policies, standards, and SDLC controls covering source control, branching, peer review, testing, releases, environments, change control, configuration, and documentation.
- Create a risk-based framework that integrates GxP, SOX, privacy, security, and IT-quality requirements.
- Implement policy-as-code and controls-as-code for branch protection, mandatory reviews, signed commits, segregation of duties, deployment approvals, and immutable audit trails.
- Build automated evidence pipelines and define telemetry for coverage, exceptions, drift, remediation time, and control effectiveness.
- Establish secure-by-default guardrails in golden pipelines and paved-road platforms using recognized security and software-quality frameworks.
- Define governance for AI-assisted engineering and AI-containing products, including acceptable use, provenance, model lifecycle, documentation, evaluation, monitoring, explainability, and human oversight.
- Use AI to automate risk assessment drafting, control mapping, test generation, deviation triage, and documentation synthesis.
- Serve as a technical authority for inspections, audits, certifications, and SDLC remediation.
- Lead a federated community of engineering, quality, security, and compliance practitioners and advise senior leaders and auditors.
Requirements
- Substantial hands-on software engineering experience, including production coding, CI/CD pipeline ownership, and the ability to modify pipeline configuration, infrastructure-as-code, and policy code.
- At least 10 years of experience in software engineering, platform engineering, DevSecOps, or engineering quality, including senior technical ownership of delivery pipelines at scale.
- Experience designing and operating automated controls in regulated environments and replacing manual compliance work with software.
- Working fluency in GxP, GAMP 5, CSA, 21 CFR Part 11, EU Annex 11, and ALCOA+ data-integrity principles.
- Security engineering depth in application security, software supply-chain security, secrets and identity management, and vulnerability management.
- Technical judgment regarding AI in the SDLC, including both engineering tools and governance implications.
- Ability to influence without authority across engineering, quality, business lines, senior stakeholders, and auditors.
- Excellent written English.
- Preferred experience in pharma, biotech, medical devices, finance, aviation, nuclear, or another regulated industry with inspection or audit exposure.
- Preferred experience with SOX ITGC, IEC 62304, SaMD, privacy-by-design under GDPR, Git-based platforms, container orchestration, cloud, infrastructure-as-code, policy engines such as OPA/Rego, test automation frameworks, SBOM, and signing tools.
Benefits
- Benefits and rewards are provided through the Novartis Life Handbook.
About Novartis
Novartis is an innovative medicines company. Every day, working to reimagine medicine to improve and extend people’s lives so that patients, healthcare professionals and societies are empowered in the face of serious disease. Our medicines reach more than 250 million people worldwide. Find out more at https://www.novartis.com See our community guidelines: https://go.novartis.social/3Nboxki