Technology Standards & Control Framework Development Lead

Haleon

Bengaluru

On-site

INR 3,500,000 - 7,000,000

Full time

29 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Haleon seeks a Standards & Control Framework Development Lead to develop and maintain their Digital & Technology Written Standards and enterprise control framework across IT and OT environments.

You will translate regulatory obligations into practical standards, govern the DTMS lifecycle, and collaborate with risk, security, and assurance teams to enable scalable compliance across Haleon.

Qualifications

  • Bachelor’s degree in information systems, technology, risk management, engineering or equivalent.
  • 10+ years of experience in developing and governing technology standards and control frameworks.
  • Experience translating complex regulatory requirements into operational standards.

Responsibilities

  • Develop, define, and maintain D&T Written Standards incorporating regulatory, cybersecurity, privacy, SOx, GxP, and industry best-practice requirements.
  • Design, maintain, and enhance the D&T Control Framework with risk-based, clear, efficient controls.
  • Govern the lifecycle of standards and controls within the Digital & Technology Management System (DTMS).
  • Translate regulatory and compliance requirements into actionable, scalable standards and control requirements.
  • Collaborate with risk, tooling, advisory, and assurance teams to ensure updates flow into GRC tooling and risk assessments.
  • Drive simplification, removal of outdated standards, and automation-friendly controls.

Skills

Regulatory compliance
Information Security
Risk management
GRC tooling
Stakeholder management
Regulatory translation

Education

Bachelor’s degree in information systems, technology, risk management, engineering or equivalent
ISACA / IRM / GARP / PMI certifications preferred

Tools

GRC platforms

Job description

Welcome to Haleon. We’re a purpose-driven, world-class consumer company putting everyday health in the hands of millions. In just three years since our launch, we’ve grown, evolved and are now entering an exciting new chapter – one filled with bold ambitions and enormous opportunity.

Our trusted portfolio of brands – including Sensodyne®, Panadol®, Advil®, Voltaren®, Theraflu®, Otrivin®, and Centrum® – lead in resilient and growing categories. What sets us apart is our unique blend of deep human understanding and trusted science.

Now it’s time to fully realise the full potential of our business and our people. We do this through our Win as One strategy. It puts our purpose – to deliver better everyday health with humanity – at the heart of everything we do. It unites us, inspires us, and challenges us to be better every day, driven by our agile, performance-focused culture.

About the Role:

The Standards & Control Framework Development Lead is responsible for developing, evolving, and maintaining Haleon’s Digital & Technology Written Standards and the enterprise Technology Control Framework across IT and OT environments. This role ensures that standards are clear, actionable, adoptable, and aligned with global regulatory, cybersecurity, privacy, SOx, GxP, and broader compliance requirements. It partners with domain experts, risk teams, control owners, architects, and engineering groups to translate regulatory obligations and risk expectations into practical, modern, and scalable standards and control requirements. The role governs the lifecycle of standards and supports their adoption across D&T through effective communication, alignment with tooling, and integration into the Digital & Technology Management System (DTMS). It also drives simplification, consolidation, and continuous improvement of the control framework, ensuring that controls are efficient, non‑duplicative, and aligned to a unified methodology. The role acts as a key point of integration between Written Standards, control design, regulatory requirements, and the enterprise GRC platform, ensuring that master controls are well-designed, up-to-date, accurately mapped, and operationally embedded.

Roles & Responsibilities:
  • Develop, define, and maintain D&T Written Standards that incorporate regulatory, cybersecurity, privacy, SOx, GxP, and industry
  • best‑practice requirements, ensuring alignment with Haleon’s technology and risk strategy.
  • Design, maintain, and continuously enhance the D&T Control Framework, ensuring controls are risk‑based, clear, efficient,
  • non‑duplicative, and aligned to Written Standards and regulatory obligations.
  • Govern the lifecycle of standards and controls within the Digital & Technology Management System (DTMS), ensuring version
  • control, ownership, review cycles, and change governance are effectively managed.
  • Translate regulatory and compliance requirements (e.g., SOx, GxP, GDPR, cybersecurity regulations, AI regulations, ESG, ABAC,
  • sanctions) into actionable, scalable standards and control requirements.
  • Collaborate with risk, tooling, advisory, and assurance teams to ensure Written Standards and Control Framework updates flow
  • consistently into GRC tooling, risk assessments, project assurance, and BAU operating processes.
  • Drive simplification and continuous improvement, eliminating outdated standards, redesigning complex requirements, rationalising
  • controls, and ensuring new technologies and ways of working (e.g., cloud, DevSecOps) are reflected in standards and controls.
Business Experties:
  • Deep understanding of regulatory requirements (SOx, GxP, GDPR, cybersecurity frameworks, AI & ESG regulations) and ability
  • to translate them into streamlined, actionable standards.
  • Strong working knowledge of Information Security and Risk Management principles, including ISO 27001, NIST, and ITGC
  • expectations.
  • Expertise in control framework design, configuration of GRC platforms, and mapping of master controls across domains.
  • Solid understanding of D&T operating models, including engineering, architecture, and product‑centric delivery, to ensure
  • standards are practical and adoptable.
  • Awareness of technology, healthcare, and consumer‑health industry trends, enabling proactive updates and alignment to
  • emerging regulations and compliance risks.
  • Excellent ability to distil complex regulations into simplified standards that enable operational efficiency, business agility, and
  • robust compliance.
  • Strong relationship‑building and influencing skills, able to gain alignment across senior stakeholders and drive standard adoption
  • across diverse teams.
  • Regularly addresses complex regulatory interpretation challenges, ensuring that evolving global requirements are integrated into
  • standards and controls without adding unnecessary operational complexity.
  • Balances competing priorities across D&T, designing standards that satisfy assurance and regulatory demands while remaining
  • realistic for product and engineering teams.
  • Requires innovative thinking to simplify and streamline standards, remove redundant requirements, and redesign controls to be
  • more automated, preventative, or integrated into technology processes.
  • Tackles cross‑functional misalignments and integrates multiple frameworks (SOx, GxP, cybersecurity, privacy) into a harmonised
  • D&T‑wide standard set.
  • Navigates a dynamic landscape of regulatory updates, emerging technologies, and evolving risk exposure, requiring proactive and strategic updates to standards and frameworks.
  • Enterprise‑wide impact across Haleon’s Digital & Technology organisation, as Written Standards and the Control Framework drive how compliance and risk governance are operationalised globally.
  • Ensures the business can maintain regulatory adherence, meet external audit expectations, and avoid compliance breaches or operational disruptions.
  • Influences how technology teams design, deliver, and operate digital solutions by embedding high‑quality, consistent standards.
  • Supports the broader risk and compliance strategy, ensuring effective control governance and alignment across multiple assurance and oversight functions.
  • Impacts strategic decision‑making related to technology design, cloud adoption, engineering approaches, and enterprise controls.
  • Engages with auditors and regulators to demonstrate robust risk governance and compliance readiness.
Interactions / Interpersonal Skills:
  • Extensive interaction with architects, engineering teams, security, privacy, quality, internal audit, and risk & compliance stakeholders.
  • Collaborates closely with: Risk Oversight & Management teams to ensure risks inform standards and the control framework,
  • Control Assurance & Advisory teams to ensure controls derived from standards are testable, efficient, and aligned, Risk &
  • Compliance Tooling teams to ensure master controls and mappings are maintained and accurately reflected in GRC tooling, and
  • Security & Training teams to cascade standards and drive adoption.
  • Strong communication, negotiation, and influence required to drive alignment and adoption across global, multidisciplinary teams.
  • Must be able to simplify complex concepts and achieve consensus despite competing priorities.
Minimum Education:

Bachelor’s degree in information systems, Technology, Risk Management, Engineering, Cybersecurity or equivalent experience.

Preferred Education:

Certifications from top accredited risk management bodies (ISACA, IRM, GARP,PMI).

Minimum Experience:
  • 10 years Significant experience in developing and governing technology standards and control frameworks.
  • Experience translating complex regulatory requirements into operational standards.
  • Expertise in designing IT control frameworks (e.g., SOx, GxP, cybersecurity, privacy).
  • Experience managing the lifecycle of standards and controls within large organizations.
  • Demonstrated experience working with GRC tooling and master control frameworks.
Preferred Experience:
  • 12+ years in Risk, Compliance, Security, or Technology Governance roles.
  • Experience in global or highly regulated environments (healthcare, consumer health, pharmaceuticals).
  • Experience leading simplification, harmonisation, and transformation of control and standards frameworks.
Required Licenses/Certifications:

Preferred: CISA, CRISC, CISSP, ISO 27001 Lead Implementer, ITIL, CGEIT or equivalent.

Job Posting End Date:

2026-09-19

Equal Opportunities:

Haleon are committed to mobilising our purpose in a way that represents the diverse consumers and communities who rely on our brands every day. It guides us in creating an inclusive culture, where different backgrounds and views are valued and respected – all in support of understanding and best serving the needs of our consumers and unleashing the full potential of our people. It’s important to us that Haleon is a place where all our employees feel they truly belong.

During the application process, we may ask you to share some personal information, which is entirely voluntary. This information ensures we meet certain regulatory and reporting obligations and supports the development, refinement, and execution of our inclusion and belonging programmes that are open to all Haleon employees.

The personal information you provide will be kept confidential, used only for legitimate business purposes, and will never be used in making any employment decisions, including hiring decisions.

Adjustment or Accommodations Request:

If you require a reasonable adjustment or accommodation or other assistance to apply for a job at Haleon at any stage of the application process, please let your recruiter know by providing them with a description of specific adjustments you are requesting. We’ll provide all reasonable adjustments to support you throughout the recruitment process and treat all information you provide us in confidence.

Note to candidates:

The Haleon recruitment team will contact you using a Haleon email account (@haleon.com). If you are not sure whether the email you received is from Haleon, please get in touch.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Standards & Control Framework Analyst
IT Standards & Control Framework Analyst

Haleon • Bengaluru

On-site
INR 1,200,000 - 2,100,000
D&T Head of Legal
D&T Head of Legal

Haleon • Bengaluru

On-site
INR 4,000,000 - 6,500,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Haleon • India

On-site
INR 1,800,000 - 3,000,000
Third Party Security Risk Analyst
Third Party Security Risk Analyst

Haleon plc. • Bengaluru

On-site
INR 1,400,000 - 2,000,000
Operations and Documentation Associate
Operations and Documentation Associate

Haleon • Hyderabad

On-site
INR 700,000 - 1,200,000
D&T Project Manager (Delivery)
D&T Project Manager (Delivery)

Haleon • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Scrum Master
Scrum Master

Haleon • Bengaluru

On-site
INR 1,200,000 - 1,800,000
GxP (GCP, GLP, GVP) Quality Assurance Associate Director
GxP (GCP, GLP, GVP) Quality Assurance Associate Director

Haleon • Hyderabad

Hybrid
INR 3,500,000 - 5,500,000
Product Expert – Safety & Medical
Product Expert – Safety & Medical

Haleon • Bengaluru

On-site
INR 3,200,000 - 5,200,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Haleon • Bengaluru

On-site
INR 2,400,000 - 4,200,000