Head DDIT ISC Software Development Governance Integrity & Secure Software Development Life Cycle (SDLC)

Novartis India

Hyderabad

On-site

INR 2,500,000 - 5,000,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Job summary

Novartis India seeks a senior technical leader to own the enterprise SDLC governance model. You will implement policy as code, automate evidence pipelines, and drive secure, compliant software delivery across engineering teams.

You will influence hundreds of engineers and work with auditors, regulators, and stakeholders to replace manual compliance with software-driven controls. Strong AI governance experience is required.

Qualifications

  • 10+ years in software engineering/platform engineering/DevSecOps with senior technical ownership.
  • Experience designing automated controls in regulated environments with software.
  • Fluent English communication and interaction with auditors and stakeholders.
  • Credible judgment on AI in the SDLC and governance implications.

Responsibilities

  • Own enterprise policy standards and controls for software engineering including source control, review, testing, release management.
  • Rationalise overlapping GxP, SOX, privacy, security, and IT-quality requirements into a risk-based framework.
  • Retire SDLC controls that do not reduce risk and enable secure, fast software delivery at scale.
  • Implement policy as code and controls as code with audit trails and enforcement.
  • Build automated evidence pipelines and telemetry on control effectiveness, drift, and MTTR.
  • Define guardrails aligning with NIST SSDF, ISO 27001, IEC 62304 where applicable.
  • Define AI-related controls for engineering and product lifecycle, including data provenance and oversight.
  • Lead a federated community of engineering quality, security, and compliance practitioners.

Skills

Hands-on software engineering
CI/CD pipelines
Policy as code
IaC (infrastructure as code)
DevSecOps
Engineering quality
AI governance

Tools

Git-based platforms
Policy engines (OPA/Rego)
SBOM & signing tooling
Container orchestration
Cloud IaC tooling

Job description

Choose everything that applies
You can update your choices anytime.

ROLE
– Rationalise overlapping GxP, SOX, privacy, security and IT-quality requirements into a coherent risk‑based framework, ensuring low‑risk internal tools are not over‑governed.
– Retire SDLC controls

Full job description

Job Description Summary

We build and buy software that touches clinical trials patient safety manufacturing quality systems and commercial operations. It now ships weekly rather than yearly is increasingly AI-assisted and increasingly contains AI. Our control framework was built for a slower world.
This role makes secure compliant audit-ready software delivery the fastest path for engineers — not a gate they route around. You will own the enterprise SDLC governance model and build much of it yourself: policy as code automated evidence capture pipeline controls and reference architectures.
This is a hands‑on individual‑contributor leadership role. You will set enterprise direction influence hundreds of engineers and lead through a federated community — but you will not have a large direct team and you will spend meaningful time in repositories pipelines and control code. Candidates seeking pure oversight or people management should not apply.

Job Description

Key Responsibilities:

Own the enterprise policy standards and controls for software engineering including source control branching peer review testing release management environment segregation change control configuration and release documentation.
Rationalise overlapping GxP SOX privacy security and IT-quality requirements into one coherent risk-based framework ensuring low-risk internal tools are not governed like regulated clinical systems.
Retire SDLC controls that do not reduce risk and ensure tooling is implemented to securely speed up software development at Novartis at the highest scale leveraging and creating AI tooling for the enterprise.
Implement policy as code and controls as code including branch protections mandatory review signed commits segregation of duties deployment approvals and immutable audit trails.
Build automated continuous evidence pipelines and define control telemetry including coverage exceptions drift mean time to remediate and control effectiveness with a focus on agility automation and speed.
Own secure-by-default guardrails in golden pipelines and paved-road platforms aligning with recognized frameworks including NIST SSDF ISO/IEC 27001 and IEC 62304 where applicable.
Define controls for AI-assisted engineering including acceptable use of coding assistants agentic tooling IP and licence exposure provenance attribution and human accountability for review and approval.
Define controls for AI-containing products including model lifecycle dataset and model documentation evaluation drift monitoring explainability human oversight and readiness for evolving regulatory requirements.
Use AI to reduce compliance burden through automated risk assessment drafting control mapping test generation deviation triage and documentation synthesis while serving as technical authority for inspections audits certifications and SDLC remediation.
Lead a federated community of engineering quality security and compliance practitioners publish practical guidance advise senior leaders on risk and trade-offs and partner with software developers across the enterprise to enable efficient delivery of compliant and secure products.

You are a practitioner. You have substantial hands‑on software engineering experience: you have written production code owned CI/CD pipelines and can read and modify pipeline configuration IaC and policy code today unaided. Expect a technical assessment.
10+ years in software engineering platform engineering DevSecOps or engineering quality including senior technical ownership of delivery pipelines at scale.
Experience designing and operating automated controls in regulated environments — with evidence of replacing manual compliance work with software.
Working fluency in regulated‑software requirements relevant to pharma/life sciences: GxP GAMP 5 (2nd Ed.) CSA 21 CFR Part 11 EU Annex 11 and data integrity/ALCOA+.
Security engineering depth: application security software supply chain security secrets and identity management vulnerability management.
Credible technical judgement on AI in the SDLC — both the tooling and its governance implications.
Ability to influence without authority across engineering quality and business lines and hold positions with senior stakeholders and auditors.
Excellent written English.

Experience in pharma biotech medical devices or another regulated industry (finance aviation nuclear) with real inspection or audit exposure.Experience with SOX ITGC in engineering contexts IEC 62304 / SaMD and privacy‑by‑design under GDPR.
Hands‑on with modern stacks: Git‑based platforms and policy/protection features container orchestration cloud IaC policy engines (e.g. OPA/Rego or equivalent) test automation frameworks SBOM and signing tooling.

You’ll receive: You can find everything you need to know about our benefits and rewards in the Novartis Life Handbook. https://www.novartis.com/careers/benefits-rewards

Commitment to Diversity and Inclusion:
Novartis is committed to building an outstanding inclusive work environment and diverse teams' representative of the patients and communities we serve.

Join our Novartis Network: If this role is not suitable to your experience or career goals but you wish to stay connected to hear more about Novartis and our career opportunities join the Novartis Network here:
https://talentnetwork.novartis.com/network

Business Acumen Influencing Skills Information Security Risk Management IT Governance Stakeholder Management Strategic Leadership Talent Development

September 16th, 2026

Working together, we can reimagine medicine to improve and extend people’s lives.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Head DDIT ISC Software Development Governance, Integrity & Secure Software Development Life Cycle (SDLC)
Head DDIT ISC Software Development Governance, Integrity & Secure Software Development Life Cycle (SDLC)

Novartis India • Hyderabad

On-site
INR 3,000,000 - 5,000,000
Associate Director, Governance & Operations
Associate Director, Governance & Operations

Novartis India • Hyderabad

On-site
INR 6,000,000 - 9,000,000
Associate Director DDIT ISC SecOps Access&Auth.
Associate Director DDIT ISC SecOps Access&Auth.

Novartis India • Hyderabad

On-site
INR 1,800,000 - 3,600,000
Director Data Products, Platform Innovation & Adoption
Director Data Products, Platform Innovation & Adoption

Novartis India • Hyderabad

On-site
INR 4,000,000 - 7,000,000
Associate Director DDIT ISC SecOps AccessandAuth
Associate Director DDIT ISC SecOps AccessandAuth

Novartis India • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Assoc Director- Platform And Data Engineer
Assoc Director- Platform And Data Engineer

Novartis India • Hyderabad

On-site
INR 4,000,000 - 7,000,000
Sr. Spec. DDIT IES CHS AWS Engg
Sr. Spec. DDIT IES CHS AWS Engg

Novartis India • Hyderabad

On-site
INR 3,600,000 - 7,200,000
Principal Clinical Data Scientist
Principal Clinical Data Scientist

Novartis India • Hyderabad

On-site
INR 2,400,000 - 3,600,000
Manager, Market Engagement & Governance
Manager, Market Engagement & Governance

Novartis India • Hyderabad

On-site
INR 400,000 - 850,000
Senior Expert, Science & Technology
Senior Expert, Science & Technology

Novartis India • Hyderabad

On-site
INR 1,800,000 - 3,400,000