18 sep
|
Jobrapido
|
Barcelona
18 sep
Jobrapido
Barcelona
Overview
A continuación, encontrará un desglose completo de todo lo que se requiere de los posibles candidatos, así como la forma de presentar su candidatura. ¡Mucha suerte!
You will own the enterprise SDLC governance model, turning policy into code and automated controls to speed secure software delivery. In this hands-on role, you influence engineers across the company while building reference architectures and governance tooling. You’ll work in a federated community to align security, compliance, and quality with AI-enabled software. This position offers the chance to shape how regulated software is developed at scale with modern automation and AI tooling.
Compensaciones / Beneficios
- competitive base salary
- performance-based bonus eligibility
- insurance plans
- retirement plans
- wellbeing resources
- versátil and hybrid working options
Responsabilidades
- Own enterprise policy, standards and controls for software engineering (source control, branching, peer review, testing, release management, environment segregation, change control, documentation).
- Rationalise GxP, SOX, privacy, security and IT-quality requirements into a single risk-based framework.
- Retire non-risk-reducing controls and implement tooling to accelerate development, with AI tooling where applicable.
- Implement policy as code and controls as code (branch protections, mandatory review, signed commits, segregation of duties, approvals, audit trails).
- Build automated evidence pipelines and define control telemetry (coverage, drift, MTTR, effectiveness) prioritising agility and automation.
- Maintain secure-by-default guardrails in pipelines/platforms,
aligning with NIST SSDF, ISO/IEC 27001, IEC 62304 where relevant.
- Define AI governance controls (coding assistants, IP/licensing, provenance, attribution, human accountability).
- Define AI product controls (model lifecycle, datasets, documentation, evaluation, drift monitoring, explainability, oversight).
- Leverage AI to reduce compliance burden (risk drafting, control mapping, test generation) while supporting audits and certifications.
- Lead a federated engineering/quality/security/compliance community and advise senior leaders on risk and trade-offs.
Requisitos principales
- 10+ years in software engineering, platform engineering, DevSecOps or engineering quality with ownership of delivery pipelines at scale.
- Hands-on experience: writing production code, managing CI/CD, and reading/modifying pipeline configuration, IaC and policy code.
- Experience designing and operating automated controls in regulated environments with measurable risk reduction.
- Fluency in pharma/life sciences regulated software requirements (GxP, GAMP 5, CSA, 21 CFR Part 11, EU Annex 11, ALCOA+).
- Security engineering depth: application security, software supply chain security, secrets/identity management, vulnerability management.
- Credible judgment on AI in SDLC and governance implications.
- Ability to influence across engineering, quality and business lines with senior stakeholders and auditors. xkdbapo
- Excellent written English.
- Influencing without authority
- Stakeholder management
- Strategic leadership
- CI/CD pipelines
- IaC and policy code
- Policy engines (OPA/Rego or equivalent)
📌 Head DDIT ISC Software Development Governance, Integrity & Secure Software Development Life Cycle (SDLC) - Novartis (Barcelona)
🏢 Jobrapido
📍 Barcelona