Head DDIT ISC Software Development Governance, Integrity & Secure Software Development Life Cycle (SDLC)

ES06 (FCRS = ES006) Novartis Farmacéutica, S.A.

Barcelona

Híbrido

EUR 93.000 - 172.000

Jornada completa

Hace 2 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Destaca para este puesto: genera un currículum y una carta de presentación adaptados en cuestión de un minuto.

Supera los filtros ATS

Descripción de la vacante

Novartis in Barcelona, Spain is seeking an experienced software governance leader to own the enterprise SDLC controls and policy framework. You will guide a federated community across engineering, quality, and security to accelerate compliant software delivery at scale.

You will define controls for AI-assisted engineering and AI-containing products, balancing speed with risk reduction, while collaborating with senior stakeholders and auditors.

Formación

  • 10+ years in software engineering, platform engineering, DevSecOps or engineering quality, including senior technical ownership of delivery pipelines at scale.
  • Hands-on software engineering experience: you have written production code, owned CI/CD pipelines, and can read/modify pipeline configuration, IaC and policy code today, unaided.
  • Working fluency in regulated-software requirements relevant to pharma/life sciences: GxP, GAMP 5 (2nd Ed.), CSA, 21 CFR Part 11, EU Annex 11 and data integrity/ALCOA+.
  • Security engineering depth: application security, software supply chain security, secrets and identity management, vulnerability management.
  • Credible technical judgement on AI in the SDLC — governance implications.
  • Ability to influence without authority across engineering, quality and business lines, and hold positions with senior stakeholders and auditors.
  • Excellent written English.

Responsabilidades

  • Own the enterprise policy, standards and controls for software engineering, including source control, branching, peer review, testing, release management, environment segregation, change control, configuration and release documentation.
  • Rationalise overlapping GxP, SOX, privacy, security and IT-quality requirements into one coherent framework, ensuring low-risk tools are not over-governed.
  • Retire SDLC controls that do not reduce risk and enable tooling to accelerate secure development at scale, leveraging AI tooling.
  • Implement policy as code and controls as code, including branch protections, mandatory review, signed commits and immutable audit trails.
  • Build automated, continuous evidence pipelines and define control telemetry (coverage, exceptions, drift, MTTR, effectiveness).
  • Own secure-by-default guardrails in pipelines and platforms, aligning with NIST SSDF, ISO 27001 and IEC 62304 where applicable.
  • Define controls for AI-assisted engineering, including licensing, provenance, and human oversight for review/approval.
  • Define controls for AI-containing products, including model lifecycle, data docs, evaluation, drift, explainability and regulatory readiness.
  • Use AI to reduce compliance burden via automated risk drafting, control mapping and test generation; act as technical authority for audits and SDLC remediation.
  • Lead a federated community of engineering, quality, security and compliance practitioners and guide senior leaders on risk.

Conocimientos

Hands-on software Eng
CI/CD pipelines
Policy as code
GxP compliance
Security engineering
AI governance
Influence without authority
English proficiency

Herramientas

Container orchestration
Cloud
IaC
Policy engines (e.g. OPA/Rego)

Descripción del empleo

Salary Range: €92,600.00 - €172,000.00

Job Description Summary

We build and buy software that touches clinical trials, patient safety, manufacturing, quality systems and commercial operations. It now ships weekly rather than yearly, is increasingly AI-assisted, and increasingly contains AI. Our control framework was built for a slower world. This role makes secure, compliant, audit-ready software delivery the fastest path for engineers — not a gate they route around. You will own the enterprise SDLC governance model and build much of it yourself: policy as code, automated evidence capture, pipeline controls and reference architectures. This is a hands-on, individual-contributor leadership role. You will set enterprise direction, influence hundreds of engineers and lead through a federated community — but you will not have a large direct team, and you will spend meaningful time in repositories, pipelines and control code. Candidates seeking pure oversight or people management should not apply.

Job Description #LI-Hybrid Location: Barcelona, Spain

Key Responsibilities
  • Own the enterprise policy, standards and controls for software engineering, including source control, branching, peer review, testing, release management, environment segregation, change control, configuration and release documentation.
  • Rationalise overlapping GxP, SOX, privacy, security and IT-quality requirements into one coherent, risk-based framework, ensuring low-risk internal tools are not governed like regulated clinical systems.
  • Retire SDLC controls that do not reduce risk and ensure tooling is implemented to securely speed up software development at Novartis at the highest scale, leveraging and creating AI tooling for the enterprise.
  • Implement policy as code and controls as code, including branch protections, mandatory review, signed commits, segregation of duties, deployment approvals and immutable audit trails.
  • Build automated, continuous evidence pipelines and define control telemetry including coverage, exceptions, drift, mean time to remediate and control effectiveness, with a focus on agility, automation and speed.
  • Own secure-by-default guardrails in golden pipelines and paved-road platforms, aligning with recognized frameworks including NIST SSDF, ISO/IEC 27001 and IEC 62304 where applicable.
  • Define controls for AI-assisted engineering, including acceptable use of coding assistants, agentic tooling, IP and licence exposure, provenance, attribution and human accountability for review and approval.
  • Define controls for AI-containing products, including model lifecycle, dataset and model documentation, evaluation, drift monitoring, explainability, human oversight and readiness for evolving regulatory requirements.
  • Use AI to reduce compliance burden through automated risk assessment drafting, control mapping, test generation, deviation triage and documentation synthesis, while serving as technical authority for inspections, audits, certifications and SDLC remediation.
  • Lead a federated community of engineering, quality, security and compliance practitioners, publish practical guidance, advise senior leaders on risk and trade-offs, and partner with software developers across the enterprise to enable efficient delivery of compliant and secure products.
Essential Requirement
  • You are a practitioner.
  • You have substantial hands-on software engineering experience: you have written production code, owned CI/CD pipelines, and can read and modify pipeline configuration, IaC and policy code today, unaided.
  • Expect a technical assessment.
  • 10+ years in software engineering, platform engineering, DevSecOps or engineering quality, including senior technical ownership of delivery pipelines at scale.
  • Experience designing and operating automated controls in regulated environments — with evidence of replacing manual compliance work with software.
  • Working fluency in regulated-software requirements relevant to pharma/life sciences: GxP, GAMP 5 (2nd Ed.), CSA, 21 CFR Part 11, EU Annex 11 and data integrity/ALCOA+.
  • Security engineering depth: application security, software supply chain security, secrets and identity management, vulnerability management.
  • Credible technical judgement on AI in the SDLC — both the tooling and its governance implications.
  • Ability to influence without authority across engineering, quality and business lines, and hold positions with senior stakeholders and auditors.
  • Excellent written English.
Desirable Requirement
  • Experience in pharma, biotech, medical devices or another regulated industry (finance, aviation, nuclear), with real inspection or audit exposure.
  • Experience with SOX ITGC in engineering contexts, IEC 62304 / SaMD, and privacy-by-design under GDPR.
  • Hands-on with modern stacks: Git-based platforms and policy/protection features, container orchestration, cloud, IaC, policy engines (e.g. OPA/Rego or equivalent), test automation frameworks, SBOM and signing tooling.
Benefits & Rewards

At Novartis, we’re committed to reimagining medicine together - and rewarding the people who make it happen. Expected Annual Base Salary Range for role: 92,600.00 - 172,000.00 EUR. The base salary offered is determined based on gender-neutral objectives, such as relevant skills, competencies and experience in accordance with the Novartis pay setting policy and upon joining Novartis will be reviewed periodically. In addition to your base salary, you may be eligible for a performance-based bonus depending on certain performance parameters. The rewards of being part of our team go far beyond base pay and incentives. We also offer a variety of competitive benefits in kind to help you thrive personally and professionally, such as insurance plans, retirement plans, wellbeing resources and global recognition programs. In addition, we provide flexible and hybrid working options, where possible, and minimum 14 weeks paid parental leave. Pay equity is a fundamental principle of our employment policy and reflects our commitment to create a diverse, equitable and inclusive environment that treats all employees with dignity and respect, as outlined in our Code of Ethics. Read our brochure to learn more about our global total rewards offering: https://www.novartis.com/sites/novartis_com/files/novartis-life-handbook.pdf

Note: Benefits and compensation may vary by country and are subject to local legal requirements, including provisions of collective bargaining agreements where applicable. A full overview of your compensation package, including any relevant collective bargaining agreement details applicable to your role based on your employment location and Novartis employer entity, will be communicated separately to you during the application process.

Commitment to Diversity and Inclusion / EEO

Novartis is committed to building an outstanding, inclusive work environment and diverse teams’ representative of the patients and communities we serve. You’ll receive: You can find everything you need to know about our benefits and rewards in the Novartis Life Handbook. https://www.novartis.com/careers/benefits-rewards
Commitment to Diversity and Inclusion: Novartis is committed to building an outstanding, inclusive work environment and diverse teams' representative of the patients and communities we serve.

Skills Desired
  • Business Acumen
  • Influencing Skills
  • Information Security Risk Management
  • IT Governance
  • Stakeholder Management
  • Strategic Leadership
  • Talent Development

Improving the lives of people living with disease takes more than innovative science. It takes a focus on the needs of people and a community committed to meeting them. It takes a team of people like you. Working together. Learning together. Thriving together. Discover how you can join us in changing people’s lives.

In the context of China Cross-Border Data Transfer (CBDT) policy, if you need to apply for a position in China, please go to the local Recruiting System TaleNov .

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Global Medical Affairs Director, Oncology
Global Medical Affairs Director, Oncology

ES06 (FCRS = ES006) Novartis Farmacéutica, S.A. • Barcelona

Híbrido
EUR 94.000 - 174.000
Flexible/hybrid working
14 weeks parental leave
Equity awards
Agile Delivery Lead (Scrum & Kanban)
Agile Delivery Lead (Scrum & Kanban)

ES06 (FCRS = ES006) Novartis Farmacéutica, S.A. • Barcelona

Presencial
EUR 58.000 - 108.000
Insurance plans
Retirement plans
Wellbeing resources
+3
International Trade Analyst
International Trade Analyst

Novartis • Barcelona

Híbrido
EUR 30.000 - 56.000
Hybrid working options
Insurance plans
Retirement plans
+2
Senior Study Leader
Senior Study Leader

ES06 (FCRS = ES006) Novartis Farmacéutica, S.A. • Barcelona

Híbrido
EUR 64.000 - 118.000
Hybrid working options
Insurance plans
Parental leave
Global Good Clinical Practices / Pharmacovigilance Auditor
Global Good Clinical Practices / Pharmacovigilance Auditor

Novartis • Madrid

Presencial
EUR 45.000 - 84.000
Access Field Head
Access Field Head

Novartis • Madrid

Híbrido
EUR 110.000 - 204.000
Hybrid working options
Parental leave: 14 weeks
Company car or car allowance
+4
Access Field Head
Access Field Head

Novartis • Barcelona

Híbrido
EUR 110.000 - 204.000
Clinical Development Medical Director - Neuromuscular
Clinical Development Medical Director - Neuromuscular

Novartis Ag • Málaga

Presencial
EUR 85.000 - 158.000
Enterprise Security Architect – Data Security
Enterprise Security Architect – Data Security

ES06 (FCRS = ES006) Novartis Farmacéutica, S.A. • Barcelona

Híbrido
EUR 58.000 - 108.000
Associate Clinical Programmer - Clinical Study Data, Risk based Quality Management & Monitoring
Associate Clinical Programmer - Clinical Study Data, Risk based Quality Management & Monitoring

Novartis • Barcelona

Híbrido
EUR 29.000 - 52.000
Flexible/hybrid working