Head DDIT ISC Software Development Governance, Integrity & Secure Software Development Life Cycle (SDLC) - barcelona
16 hours ago
Barcelona
Overview You will own the enterprise SDLC governance model, turning policy into code and automated controls to speed secure software delivery. In this hands-on role, you influence engineers across the company while building reference architectures and governance tooling. You’ll work in a federated community to align security, compliance, and quality with AI-enabled software. This position offers the chance to shape how regulated software is developed at scale with modern automation and AI tooling. Compensaciones / Beneficios • competitive base salary, • performance-based bonus eligibility, • insurance plans, • retirement plans, • wellbeing resources, • flexible and hybrid working options Responsabilidades, • Own enterprise policy, standards and controls for software engineering (source control, branching, peer review, testing, release management, environment segregation, change control, documentation)., • Rationalise GxP, SOX, privacy, security and IT-quality requirements into a single risk-based framework., • Retire non-risk-reducing controls and implement tooling to accelerate development, with AI tooling where applicable., • Implement policy as code and controls as code (branch protections, mandatory review, signed commits, segregation of duties, approvals, audit trails)., • Build automated evidence pipelines and define control telemetry (coverage, drift, MTTR, effectiveness) prioritising agility and automation., • Maintain secure-by-default guardrails in pipelines/platforms, aligning with NIST SSDF, ISO/IEC 27001, IEC 62304 where relevant., • Define AI governance controls (coding assistants, IP/licensing, provenance, attribution, human accountability)., • Define AI product controls (model lifecycle, datasets, documentation, evaluation, drift monitoring, explainability, oversight)., • Leverage AI to reduce compliance burden (risk drafting, control mapping, test generation) while supporting audits and certifications., • Lead a federated engineering/quality/security/compliance community and advise senior leaders on risk and trade-offs. Requisitos principales, • 10+ years in software engineering, platform engineering, DevSecOps or engineering quality with ownership of delivery pipelines at scale., • Hands-on experience: writing production code, managing CI/CD, and reading/modifying pipeline configuration, IaC and policy code., • Experience designing and operating automated controls in regulated environments with measurable risk reduction., • Fluency in pharma/life sciences regulated software requirements (GxP, GAMP 5, CSA, 21 CFR Part 11, EU Annex 11, ALCOA+)., • Security engineering depth: application security, software supply chain security, secrets/identity management, vulnerability management., • Credible judgment on AI in SDLC and governance implications., • Ability to influence across engineering, quality and business lines with senior stakeholders and auditors., • Excellent written English., • Influencing without authority, • Stakeholder management, • Strategic leadership, • CI/CD pipelines, • IaC and policy code, • Policy engines (OPA/Rego or equivalent)