2010 - 2016 · Bangalore, India → Copenhagen, Denmark

Novo Nordisk

Application Owner → Solution Centre Lead → Corporate Platform & Security Governance

I earned two promotions over six years. The first moved me from managing two regulated enterprise applications to leading the Finance, Legal, IT and HR Solution Centre. The second, larger promotion moved me from Bangalore Global Business Services into a direct headquarters role in Copenhagen, reporting to a Corporate Vice President and leading cross-portfolio application-security posture, platform resilience, compliance and transition programs for the shared control layer across Novo Nordisk's 55+ enterprise applications.

Nilanjan Maity during the Novo Nordisk chapter

The operating context

Novo Nordisk had about 42,000 employees in 2016. The solution centre delivered regulated enterprise applications to Finance, Legal, IT and HR. This was my first role combining direct people management with annual budgeting and ongoing financial control, alongside responsibility for the full service stack, vendors and SLAs. The move to Copenhagen made me Novo Nordisk's first reverse expatriate, moving from Global Business Services into headquarters rather than following the usual headquarters-to-affiliate route. There I worked as an empowered cross-functional program lead for the shared security, resilience, continuity and platform-control layer across the corporate IT portfolio of 55+ enterprise applications. The application-management organization retained overall delivery ownership; my mandate was to assess alignment with the corporate IT Security Standard, coordinate remediation and strengthen the controls and evidence that had to work across the portfolio. Depending on the workstream, I could mobilize 5 to 60 people across application teams, infrastructure, IT Security, Quality, the PMO and suppliers without owning every resource through the organization chart.

Selected projects & programs

01

Enterprise security compliance assessment & standards correction

Novo Nordisk's corporate IT Security Standard, aligned with ISO 27001, applied across the application portfolio, but the portfolio had not been tested against it. I owned that assessment end to end. This was a portfolio-level internal assurance assessment, not end-to-end application delivery. I decomposed the standard and the minimum requirements for outsourced services into 136 assessable controls, designed the assessment instrument, held the budget and ran competitive supplier selection with the CVP. We engaged an independent firm with enough knowledge of the portfolio to make the findings defensible to Quality and audit.

I carried the assessment across the application-management organization through workshops, written guidance and structured interviews with application owners and architects. The assessment method, instrument, communications and interviews were designed and led in-house, with the external firm providing independent assurance. The 55+ application portfolio was assessed against all 136 controls, producing a traceable compliance matrix and more than 25 severity-rated observations.

I adjudicated findings with owners and architects, negotiated documented closure arrangements and reported to the Global Applications Board at CVP/VP level. The evidence also identified defects in the standard itself, so I authored formal changes to clarify accountability, separate conflated responsibilities and re-scope requirements that could not be operated as written.

What this demonstrates +

Change delivered across the full technical breadth of an organization, mobilizing architects, application owners, department managers, executives and suppliers without line authority. It also demonstrates the ability to design and lead in-house work often bought as a consulting engagement, including the control framework, assessment instrument, organizational communication, training and stakeholder interviews.

Domains
Control framework designSecurity standards decompositionAssessment instrument authorshipBudget authority and supplier selectionIndependent assurance designOrganizational change and enablementInfluence without line authorityCorporate standards amendment
02

Finance, Legal, IT & HR Solution Centre

Held direct people and budget accountability for a 20-person team of Application Managers, Business Analysts, and Change and Release Managers and a US$11M OPEX/CAPEX budget. Owned annual cost-centre budgeting, rolling forecasts, accruals and burn-rate management; budget performance was a formal management appraisal target. Owned the full talent lifecycle: designed roles and job descriptions against a structured job-sizing framework; designed and ran structured competency-based interviews; and hired and coached team members. Formally trained in MBTI, I used it as a core management framework to help staff understand their profiles and to shape team composition, coaching, individual and team development plans, performance conversations and succession planning. Managed performance through to separation where required.

Built Bangalore GBS's first team to reach 30% women representation, with diversity targets included in hiring and succession planning. Contributed manager-level talent and structure input to an organizational review run by executive management. Designed the shared-services model for seven regulated enterprise applications, including the service catalogue, SLAs, OLAs, cost model and chargeback approach, and managed the main service and product vendors.

What this demonstrates +

Department and cost-centre leadership combining annual planning and in-year reforecasting, supplier, licence and capacity commitments, and variance management with Finance, alongside hiring, performance management, development and succession.

Domains
People and budget accountabilityAnnual budgeting and reforecastingSupplier, licence and capacity commitmentsRole design and job evaluationPerformance and succession managementDiversity leadershipService operating model
03

Enterprise security remediation & standards program

Coordinated related security work across application, database, server and network layers. Workstreams included risk review, dispensations and compensating controls for nine operational applications using unsupported database versions; an enterprise patching workstream covering configuration-item reconciliation, supplier SOWs and budget planning; prioritized white-hat security assessments; service-account password resets; and a global intrusion-defence rollout with application whitelisting, an SLA, a Quality Plan and change communications.

Owned the annual review and update of the IT Security Standard and built a roadmap across governance, people, process and technology, with clear owners and executive follow-up. Secured PMO agreement to introduce a mandatory security review gate into project delivery, then worked with security and architecture experts to define review criteria for solution selection, architecture decisions and supplier contracts alongside the existing cloud review.

What this demonstrates +

Program leadership across control remediation, enterprise security standards, project governance and organizational change, coordinating application teams, infrastructure, Quality, Security, the PMO and suppliers.

Domains
Program governanceSecurity remediationSecurity standards lifecycleCompensating controlsProject security reviewSupplier SOWs and contract securityBudget forecastingExecutive reporting
04

Application portfolio governance

Ran portfolio governance for seven commercial off-the-shelf (COTS) applications supporting recruitment, learning, expenses, contracts, project portfolio management and IT service management. Each application followed a yearly governance calendar covering strategy and roadmap updates, investment and budget planning, application Change Advisory Boards, business-led application governance boards (SABs), SLA and KPI reviews, risk, licensing, access, continuity, audit readiness and super-user summits. Oversaw maintenance of user requirements (URS), functional and technical design specifications (FDS/TDS), validation plans and status reports, configuration records and the controlled application dossier known internally as the red binder.

Consolidated GxP and SOX risk and compliance reporting across the portfolio and managed suppliers through service catalogues, statements of work, performance commitments and escalation paths. Worked across super-user communities, business owners, application boards, Quality, Finance, IT leadership and vendors so decisions and required actions remained visible.

What this demonstrates +

Regulated application-lifecycle governance from requirements, design and validation records through user communities, change and investment boards, executive stakeholders and suppliers.

Domains
Regulated lifecycle governanceValidation and audit readinessChange and investment board governance (CAB/SAB)Investment planningExecutive stakeholder engagementSLA and KPI managementSupplier governance
05

Business Impact Assessment (BIA) and disaster recovery (DSS04)

As CobiT DSS04 process owner, led the assessment of critical infrastructure services and their dependent applications. Mapped business impact, service dependencies and recovery tiers, and established RTO/RPO inputs. The results set the disaster-recovery strategy for the global application portfolio and became the basis for renegotiating NNIT's global infrastructure SLAs, reducing SLA cost by 14%.

Under Quality Assurance oversight, each application owner had to update and file an application-specific DR strategy, with 11 representative applications selected for QA-witnessed recovery testing.

What this demonstrates +

Turned business impact and technical dependencies into a global DR strategy, application-level recovery plans, QA-witnessed testing and renegotiated supplier SLA commitments that reduced SLA cost by 14%.

Domains
Business continuity ownership (COBIT DSS04)Business impact analysisDR strategyRTO and RPO negotiationSupplier SLA renegotiationRecovery testing assuranceFinancial impact (14% SLA cost reduction)
06

Risk-based IT surveillance & monitoring

Designed monitoring points from each application's Threat, Vulnerability and Controls Assessment (TVCA), business data, business processes and Business Impact Assessment. Identified what had to be monitored across application, middleware, database and infrastructure layers; defined Splunk agent and collector patterns for centralized ingestion and correlation; and optimized log flow and events per second (EPS) because EPS drove platform sizing and cost.

Led scoping, proof of concept, Quality Plan and onboarding. The service closed an enterprise-wide corporate non-conformity and met IT Security and 21 CFR Part 11 requirements described as essential to license to operate.

What this demonstrates +

Converted application risk and business-impact analysis into an enterprise monitoring model that satisfied 21 CFR Part 11 and closed a global non-conformity, with platform selection and sizing governed on cost.

Domains
Risk-based monitoring strategyBusiness impact analysisRegulatory compliance (21 CFR Part 11)Enterprise monitoring platform selectionQuality planningNon-conformity closure
07

Application-management maturity and global transition program

Helped define the future-state maturity and competency model for enterprise application management and institutionalized it through an application-management centre of excellence. Set role expectations, governance forums, required artifacts, service standards, training and professional-development needs. As headquarters Transition Manager reporting directly to the CVP of ITS, was accountable for planning and managing the transition of seven highly business-critical applications from headquarters during 2014-2016, together with an annual intake of two to six applications from lines of business or projects.

Defined the global governance and end-to-end transition process, managed the assigned transition budget, and set quality gates, organizational-change and evaluation requirements. Plans and governance moved through VP, CVP and SVP management forums. After moving to Copenhagen, I was also given direct management responsibility for two participants in Novo Nordisk's selective two-year graduate leadership program, built around three eight-month rotations to prepare future leaders. The three-layer, five-phase transition method transferred application-management capability and accountability from Denmark and the United States to India.

What this demonstrates +

A headquarters mandate combining direct management of graduate-program talent with CVP reporting, budget authority and matrix leadership of a global transition method approved through VP-to-SVP governance.

Domains
Program governanceApplication-management maturityOperating-model designBudget authorityExecutive governance (VP-SVP)Organizational changeTransition gatesCross-cultural delivery
08

Operating at three altitudes: application, department, enterprise

Over six years at Novo Nordisk I operated at three distinct altitudes, and the organization promoted me twice.

I began with accountable ownership of two regulated enterprise applications, working inside GxP operations: change control, validation records, vendor coordination and day-to-day accountability for whether each application operated as documented.

I then led the Finance, Legal, IT and HR Solution Centre, delivering regulated enterprise applications to lines of business under SLAs, with a service catalogue, an OPEX/CAPEX budget and accountability for hiring, performance and succession. This was line leadership: permanent reports, cost-centre ownership and supplier performance.

The second and larger promotion moved me from Bangalore Global Business Services to a direct staff role at headquarters in Copenhagen, reporting to a CVP within a leadership group largely composed of VPs. I was assigned to board-sponsored mandates for the shared security, resilience, continuity and platform-control layer across 55+ corporate applications, not end-to-end delivery of those applications. The mandates had no standing delivery team, so I mobilized matrixed teams of five to sixty people for each one. Alongside this work, I retained direct line-management responsibility for two participants in Novo Nordisk's graduate leadership program.

What this demonstrates +

Capability at three levels inside one organization: direct accountability for regulated applications, line leadership of a department with people and budget, and enterprise mandates delivered through matrix authority while retaining formal line-management responsibility. The resulting governance was grounded in operating reality as well as executive intent.

Domains
Regulated application ownershipDepartment and cost-centre leadershipEnterprise mandate deliveryExecutive reporting (CVP)Matrixed team mobilizationCross-geography transitionGlobal portfolio governance
09

HR performance-management upgrade

Led an upgrade to an internally hosted performance-management application so it could support matrix reporting and project goals. Took the work through implementation while keeping the required regulated controls in place.

What this demonstrates +

Directed a change to a business-critical HR platform through requirements, controlled release and validation, connecting a functional change to matrix reporting accountability across the enterprise.

Domains
Enterprise HR platformMatrix reporting accountabilityRequirements governanceControlled releaseValidation controlsBenefits realization
10

Project & Portfolio Management platform

Led the early phases of a Clarity PPM upgrade or replacement. Defined the problem, aligned stakeholders, compared options and ran a proof of concept before an investment decision.

What this demonstrates +

Investment governance ahead of an enterprise platform decision: framed the business case, appraised options against enterprise fit and cost, and validated the preferred route through proof of concept before capital was committed.

Domains
Enterprise PPMInvestment governanceBusiness case developmentOptions appraisalProof of conceptExecutive stakeholder alignment

Collective impact

At Novo Nordisk, two promotions moved me from direct application ownership to department leadership and then to a global headquarters mandate. I helped establish how enterprise applications were governed, transitioned, secured, monitored and prepared for recovery across teams, countries and suppliers.

Capabilities demonstrated

Cross-functional program leadershipApplication portfolio leadershipOrganization-wide changeOperating-model designSecurity governanceGlobal transitionGxP governanceBusiness continuityVendor governanceExecutive alignment
LinkedIn recommendationsRanjit Prasad · Kunal Sen-Gupta · Ibrahim BolicRead recommendationsHide recommendations

I've known Neil from the time we hired him as the first person while staffing up the Global IT Shared Service Center in India at Novo Nordisk. Neil was promoted quickly and was also the first person from the Indian team to move to HQ in Copenhagen. What stands out to me about Neil is his very strong grasp of technology at all levels - be it infrastructure, security, compliance, application development or operations. Neil is also a very strong communicator, able to modulate his communication so that anyone gets the message - be it an engineer or a C-suite member. These two qualities make Neil, in my opinion, a really strong member to have in any organization.

Ranjit PrasadColleague involved in establishing Novo Nordisk's India shared-service centre

I have had the pleasure of knowing Nilanjan for nearly five years now and directly working with him for two of those years. I found his intellect and strategic thinking to be invaluable not only to me personally, but to the entire organization. He constantly brought his in depth knowledge of the business as well as IT operations to any project he got involved in and was able to articulate his vision of how to deliver value to the business in a way that got their support and sponsorship. He led by example and was a value creator in the truest sense. I consider him to be one of the brightest around and an asset to any management team.

Kunal Sen-GuptaSenior Manager leading Quality & Validation; mentor, Novo Nordisk

I have worked on a couple of IT projects with Nilanjan where qualification of IT Infrastructure and Security services, supporting GxP systems, was required. He has demonstrated the ability to translate business requirements into the technical requirements, and plan quality activities necessary to specific life cycle process and to scale extent of the related activities. Furthermore Nilanjan is good in finding pragmatic solutions balancing quality and management consideration, and in stakeholder management involving stakeholders with diverse interests, knowledge and personalities.

Ibrahim BolicSenior Lead Auditor, Device & IT Audits, Novo Nordisk