20 sep
|
Novartis
|
Barcelona
20 sep
Novartis
Barcelona
Overview
Es esencial asegurarse de que cumple con los requisitos como solicitante para este puesto; por favor, lea atentamente la información a continuación.
You will own the enterprise SDLC governance model, turning policy into code and automated controls to speed secure software delivery. In this hands-on role, you influence engineers across the company while building reference architectures and governance tooling. You’ll work in a federated community to align security, compliance, and quality with AI-enabled software. This position offers the chance to shape how regulated software is developed at scale with modern automation and AI tooling.
Compensaciones / Incentivos
competitive base salary
performance-based bonus eligibility
insurance plans
retirement plans
wellbeing resources
flexible and hybrid working options
Responsabilidades
Own enterprise policy, standards and controls for software engineering (source control, branching, peer review, testing, release management, environment segregation, change control, documentation).
Rationalise GxP, SOX, privacy, security and IT-quality requirements into a single risk-based framework.
Retire non-risk-reducing controls and implement tooling to accelerate development, with AI tooling where applicable.
Implement policy as code and controls as code (branch protections, mandatory review, signed commits, segregation of duties, approvals, audit trails).
Build automated evidence pipelines and define control telemetry (coverage, drift, MTTR, effectiveness) prioritising agility and automation.
Maintain secure-by-default guardrails in pipelines/platforms,
aligning with NIST SSDF, ISO/IEC 27001, IEC 62304 where relevant.
Define AI governance controls (coding assistants, IP/licensing, provenance, attribution, human accountability).
Define AI product controls (model lifecycle, datasets, documentation, evaluation, drift monitoring, explainability, oversight).
Leverage AI to reduce compliance burden (risk drafting, control mapping, test generation) while supporting audits and certifications.
Lead a federated engineering/quality/security/compliance community and advise senior leaders on risk and trade-offs.
Requisitos principales
10+ years in software engineering, platform engineering, DevSecOps or engineering quality with ownership of delivery pipelines at scale.
Hands-on experience: writing production code, managing CI/CD, and reading/modifying pipeline configuration, IaC and policy code.
Experience designing and operating automated controls in regulated environments with measurable risk reduction.
Fluency in pharma/life sciences regulated software requirements (GxP, GAMP 5, CSA, 21 CFR Part 11, EU Annex 11, ALCOA+).
Security engineering depth: application security, software supply chain security, secrets/identity management, vulnerability management.
Credible judgment on AI in SDLC and governance implications.
Ability to influence across engineering, quality and business lines with senior stakeholders and auditors. xqbhyrx
Excellent written English.
Influencing without authority
Stakeholder management
Strategic leadership
CI/CD pipelines
IaC and policy code
Policy engines (OPA/Rego or equivalent)
📌 Head DDIT ISC Software Development Governance, Integrity & Secure Software Development Life Cycle (S (Barcelona)
🏢 Novartis
📍 Barcelona