Welcome to Haleon. We're a purpose-driven, world-class consumer company putting everyday health in the hands of millions. In just three years since our launch, we've grown, evolved and are now entering an exciting new chapter - one filled with bold ambitions and enormous opportunity.
About the Role:
The Standards & Control Framework Development Lead is responsible for developing, evolving, and maintaining Haleon's Digital & Technology Written Standards and the enterprise Technology Control Framework across IT and OT environments. This role ensures that standards are clear, actionable, adoptable, and aligned with global regulatory, cybersecurity, privacy, SOx, GxP, and broader compliance requirements. It partners with domain experts, risk teams, control owners, architects, and engineering groups to translate regulatory obligations and risk expectations into practical, modern, and scalable standards and control requirements. The role governs the lifecycle of standards and supports their adoption across D&T through effective communication, alignment with tooling, and integration into the Digital & Technology Management System (DTMS). It also drives simplification, consolidation, and continuous improvement of the control framework, ensuring that controls are efficient, non-duplicative, and aligned to a unified methodology. The role acts as a key point of integration between Written Standards, control design, regulatory requirements, and the enterprise GRC platform, ensuring that master controls are well-designed, up-to-date, accurately mapped, and operationally embedded.
Roles & Responsibilities:
- Develop, define, and maintain D&T Written Standards that incorporate regulatory, cybersecurity, privacy, SOx, GxP, and industry best-practice requirements, ensuring alignment with Haleon's technology and risk strategy.
- Design, maintain, and continuously enhance the D&T Control Framework, ensuring controls are risk-based, clear, efficient, non-duplicative, and aligned to Written Standards and regulatory obligations.
- Govern the lifecycle of standards and controls within the Digital & Technology Management System (DTMS), ensuring version control, ownership, review cycles, and change governance are effectively managed.
- Translate regulatory and compliance requirements (e.g., SOx, GxP, GDPR, cybersecurity regulations, AI regulations, ESG, ABAC, sanctions) into actionable, scalable standards and control requirements.
- Collaborate with risk, tooling, advisory, and assurance teams to ensure Written Standards and Control Framework updates flow consistently into GRC tooling, risk assessments, project assurance, and BAU operating processes.
- Drive simplification and continuous improvement, eliminating outdated standards, redesigning complex requirements, rationalising controls, and ensuring new technologies and ways of working (e.g., cloud, DevSecOps) are reflected in standards and controls.
Business Experties:
- Deep understanding of regulatory requirements (SOx, GxP, GDPR, cybersecurity frameworks, AI & ESG regulations) and ability to translate them into streamlined, actionable standards.
- Strong working knowledge of Information Security and Risk Management principles, including ISO 27001, NIST, and ITGC expectations.
- Expertise in control framework design, configuration of GRC platforms, and mapping of master controls across domains.
- Solid understanding of D&T operating models, including engineering, architecture, and product-centric delivery, to ensure standards are practical and adoptable.
- Awareness of technology, healthcare, and consumer-health industry trends, enabling proactive updates and alignment to emerging regulations and compliance risks.
- Excellent ability to distil complex regulations into simplified standards that enable operational efficiency, business agility, and robust compliance.
- Strong relationship-building and influencing skills, able to gain alignment across senior stakeholders and drive standard adoption across diverse teams.
- Regularly addresses complex regulatory interpretation challenges, ensuring that evolving global requirements are integrated into standards and controls without adding unnecessary operational complexity.
- Balances competing priorities across D&T, designing standards that satisfy assurance and regulatory demands while remaining realistic for product and engineering teams.