19 sep
|
Novartis
|
Barcelona
19 sep
Novartis
Barcelona
Overview You will own the enterprise SDLC governance model, turning policy into code and automated controls to speed secure software delivery. In this hands-on role, you influence engineers across the company while building reference architectures and governance tooling. You’ll work in a federated community to align security, compliance, and quality with AI-enabled software. This position offers the chance to shape how regulated software is developed at scale with modern automation and AI tooling. Compensaciones / Incentivos * competitive base salary * performance-based bonus eligibility * insurance plans * retirement plans * wellbeing resources * flexible and hybrid working options Responsabilidades * Own enterprise policy, standards and controls for software engineering (source control, branching, peer review, testing, release management, environment segregation, change control, documentation). * Rationalise GxP, SOX, privacy, security and IT-quality requirements into a single risk-based framework. * Retire non-risk-reducing controls and implement tooling to accelerate development, with AI tooling where applicable. * Implement policy as code and controls as code (branch protections, mandatory review, signed commits, segregation of duties, approvals, audit trails). * Build automated evidence pipelines and define control telemetry (coverage, drift, MTTR, effectiveness) prioritising agility and automation. * Maintain secure-by-default guardrails in pipelines/platforms, aligning with NIST SSDF, ISO/IEC 27001, IEC 62304 where relevant.
* Define AI governance controls (coding assistants, IP/licensing, provenance, attribution, human accountability). * Define AI product controls (model lifecycle, datasets, documentation, evaluation, drift monitoring, explainability, oversight). * Leverage AI to reduce compliance burden (risk drafting, control mapping, test generation) while supporting audits and certifications. * Lead a federated engineering/quality/security/compliance community and advise senior leaders on risk and trade-offs. Requisitos principales * 10+ years in software engineering, platform engineering, DevSecOps or engineering quality with ownership of delivery pipelines at scale. * Hands-on experience: writing production code, managing CI/CD, and reading/modifying pipeline configuration, IaC and policy code. * Experience designing and operating automated controls in regulated environments with measurable risk reduction. * Fluency in pharma/life sciences regulated software requirements (GxP, GAMP 5, CSA, 21 CFR Part 11, EU Annex 11, ALCOA+). * Security engineering depth: application security, software supply chain security, secrets/identity management, vulnerability management. * Credible judgment on AI in SDLC and governance implications. * Ability to influence across engineering, quality and business lines with senior stakeholders and auditors. * Excellent written English. * Influencing without authority * Stakeholder management * Strategic leadership * CI/CD pipelines * IaC and policy code * Policy engines (OPA/Rego or equivalent)
📌 Head DDIT ISC Software Development Governance, Integrity & Secure Software Development Life Cycle (SDLC) (Barcelona)
🏢 Novartis
📍 Barcelona