Hiring.Camp

Technology Standards & Control Framework Development Lead

Gsknch

·

Today

Location
Bengaluru Campus 31, India
Type
Full-time
Department
IT
Seniority
Lead
Closing date
Today
Source
Workday

Description

Welcome to Haleon. We’re a purpose-driven, world-class consumer company putting everyday health in the hands of millions. In just three years since our launch, we’ve grown, evolved and are now entering an exciting new chapter – one filled with bold ambitions and enormous opportunity.

Our trusted portfolio of brands – including Sensodyne®, Panadol®, Advil®, Voltaren®, Theraflu®, Otrivin®, and Centrum® – lead in resilient and growing categories. What sets us apart is our unique blend of deep human understanding and trusted science.

Now it’s time to fully realise the full potential of our business and our people. We do this through our Win as One strategy. It puts our purpose – to deliver better everyday health with humanity – at the heart of everything we do. It unites us, inspires us, and challenges us to be better every day, driven by our agile, performance-focused culture.

About the Role:

The Standards & Control Framework Development Lead is responsible for developing, evolving, and maintaining Haleon’s Digital & Technology Written Standards and the enterprise Technology Control Framework across IT and OT environments. This role ensures that standards are clear, actionable, adoptable, and aligned with global regulatory, cybersecurity, privacy, SOx, GxP, and broader compliance requirements. It partners with domain experts, risk teams, control owners, architects, and engineering groups to translate regulatory obligations and risk expectations into practical, modern, and scalable standards and control requirements. The role governs the lifecycle of standards and supports their adoption across D&T through effective communication, alignment with tooling, and integration into the Digital & Technology Management System (DTMS). It also drives simplification, consolidation, and continuous improvement of the control framework, ensuring that controls are efficient, non‑duplicative, and aligned to a unified methodology. The role acts as a key point of integration between Written Standards, control design, regulatory requirements, and the enterprise GRC platform, ensuring that master controls are well-designed, up-to-date, accurately mapped, and operationally embedded.

Roles & Responsibilities:

  • Develop, define, and maintain D&T Written Standards that incorporate regulatory, cybersecurity, privacy, SOx, GxP, and industry

  • best‑practice requirements, ensuring alignment with Haleon’s technology and risk strategy.

  • Design, maintain, and continuously enhance the D&T Control Framework, ensuring controls are risk‑based, clear, efficient,

  • non‑duplicative, and aligned to Written Standards and regulatory obligations.

  • Govern the lifecycle of standards and controls within the Digital & Technology Management System (DTMS), ensuring version

  • control, ownership, review cycles, and change governance are effectively managed.

  • Translate regulatory and compliance requirements (e.g., SOx, GxP, GDPR, cybersecurity regulations, AI regulations, ESG, ABAC,

  • sanctions) into actionable, scalable standards and control requirements.

  • Collaborate with risk, tooling, advisory, and assurance teams to ensure Written Standards and Control Framework updates flow

  • consistently into GRC tooling, risk assessments, project assurance, and BAU operating processes.

  • Drive simplification and continuous improvement, eliminating outdated standards, redesigning complex requirements, rationalising

  • controls, and ensuring new technologies and ways of working (e.g., cloud, DevSecOps) are reflected in standards and controls.

Business Experties:

  • Deep understanding of regulatory requirements (SOx, GxP, GDPR, cybersecurity frameworks, AI & ESG regulations) and ability

  • to translate them into streamlined, actionable standards.

  • Strong working knowledge of Information Security and Risk Management principles, including ISO 27001, NIST, and ITGC

  • expectations.

  • Expertise in control framework design, configuration of GRC platforms, and mapping of master controls across domains.

  • Solid understanding of D&T operating models, including engineering, architecture, and product‑centric delivery, to ensure

  • standards are practical and adoptable.

  • Awareness of technology, healthcare, and consumer‑health industry trends, enabling proactive updates and alignment to

  • emerging regulations and compliance risks.

  • Excellent ability to distil complex regulations into simplified standards that enable operational efficiency, business agility, and

  • robust compliance.

  • Strong relationship‑building and influencing skills, able to gain alignment across senior stakeholders and drive standard adoption

  • across diverse teams.

  • Regularly addresses complex regulatory interpretation challenges, ensuring that evolving global requirements are integrated into

  • standards and controls without adding unnecessary operational complexity.

  • Balances competing priorities across D&T, designing standards that satisfy assurance and regulatory demands while remaining

  • realistic for product and engineering teams.

  • Requires innovative thinking to simplify and streamline standards, remove redundant requirements, and redesign controls to be

  • more automated, preventative, or integrated into technology processes.

  • Tackles cross‑functional misalignments and integrates multiple frameworks (SOx, GxP, cybersecurity, privacy) into a harmonised

  • D&T‑wide standard set.

  • Navigates a dynamic landscape of regulatory updates, emerging technologies, and evolving risk exposure, requiring proactive and strategic updates to standards and frameworks.

  • Enterprise‑wide impact across Haleon’s Digital & Technology organisation, as Written Standards and the Control Framework drive how compliance and risk governance are operationalised globally.

  • Ensures the business can maintain regulatory adherence, meet external audit expectations, and avoid compliance breaches or operational disruptions.

  • Influences how technology teams design, deliver, and operate digital solutions by embedding high‑quality, consistent standards.

  • Supports the broader risk and compliance strategy, ensuring effective control governance and alignment across multiple assurance and oversight functions.

  • Impacts strategic decision‑making related to technology design, cloud adoption, engineering approaches, and enterprise controls.

  • Engages with auditors and regulators to demonstrate robust risk governance and compliance readiness.

Interactions / Interpersonal Skills: 

  • Extensive interaction with architects, engineering teams, security, privacy, quality, internal audit, and risk & compliance

  • stakeholders.

  • Collaborates closely with: Risk Oversight & Management teams to ensure risks inform standards and the control framework,

  • Control Assurance & Advisory teams to ensure controls derived from standards are testable, efficient, and aligned, Risk &

  • Compliance Tooling teams to ensure master controls and mappings are maintained and accurately reflected in GRC tooling, and

  • Security & Training teams to cascade standards and drive adoption.

  • Strong communication, negotiation, and influence required to drive alignment and adoption across global, multidisciplinary

  • teams.

  • Must be able to simplify complex concepts and achieve consensus despite competing priorities.

Minimum Education:

Bachelor’s degree in information systems, Technology, Risk Management, Engineering, Cybersecurity or equivalent experience.

Preferred Education:

Certifications from top accredited risk management bodies (ISACA, IRM, GARP,PMI).

Minimum Experience:

  • 10 years Significant experience in developing and governing technology standards and control frameworks.

  • Experience translating complex regulatory requirements into operational standards.

  • Expertise in designing IT control frameworks (e.g., SOx, GxP, cybersecurity, privacy).

  • Experience managing the lifecycle of standards and controls within large organizations.

  • Demonstrated experience working with GRC tooling and master control frameworks.

Preferred Experience:

  • 12+ years in Risk, Compliance, Security, or Technology Governance roles.

  • Experience in global or highly regulated environments (healthcare, consumer health, pharmaceuticals).

  • Experience leading simplification, harmonisation, and transformation of control and standards frameworks.

Required Licenses/Certifications: Preferred: CISA, CRISC, CISSP, ISO 27001 Lead Implementer, ITIL, CGEIT or equivalent.

 

 

 

 Job Posting End Date

 

 

2026-09-19

 

 

 

Equal Opportunities

Haleon are committed to mobilising our purpose in a way that represents the diverse consumers and communities who rely on our brands every day. It guides us in creating an inclusive culture, where different backgrounds and views are valued and respected – all in support of understanding and best serving the needs of our consumers and unleashing the full potential of our people. It’s important to us that Haleon is a place where all our employees feel they truly belong.

During the application process, we may ask you to share some personal information, which is entirely voluntary. This information ensures we meet certain regulatory and reporting obligations and supports the development, refinement, and execution of our inclusion and belonging programmes that are open to all Haleon employees. 

The personal information you provide will be kept confidential, used only for legitimate business purposes, and will never be used in making any employment decisions, including hiring decisions.

 

 

 

Adjustment or Accommodations Request

If you require a reasonable adjustment or accommodation or other assistance to apply for a job at Haleon at any stage of the application process, please let your recruiter know by providing them with a description of specific adjustments you are requesting. We’ll provide all reasonable adjustments to support you throughout the recruitment process and treat all information you provide us in confidence. 

 

 

 

Note to candidates

The Haleon recruitment team will contact you using a Haleon email account (@haleon.com). If you are not sure whether the email you received is from Haleon, please get in touch.

Skills

CybersecurityRisk ManagementComplianceNegotiationITILGDPRISO 27001CISSP

Similar Jobs

4

Director, Enterprise Technology Standards & Controls

Fmr · 2 Contra Way, Merrimack NH, United States of America +2

4 weeks ago

HRIS Representative II -III - HR Technology Standards & Services - Greensburg Corporate Center

First Energy Nuclear Operating · OH, United States, US · Onsite

1 month ago

Senior Research Specialist - Research & Innovation in Technology Standards

Nokia · France · Hybrid

3 months ago

Senior Manager, Partnering, Technology Standards

Nokia · Finland · Hybrid

3 months ago