Run a portfolio that can withstand an audit
Much of my career has been spent where an external party decides whether the control environment is adequate. I worked with FDA GxP and 21 CFR Part 11, ISO 27001 and SOX at Novo Nordisk, then with PCI DSS and provincial privacy requirements in a citizen-facing transit setting. I led a cross-portfolio security and compliance gap analysis across the organization's 55+ enterprise applications and owned the remediation program, the IT Security Standard and the evidence behind both. I did not own end-to-end application delivery for that estate; I strengthened the shared security, resilience and control layer that application owners had to operate.
The constraint I work to is external assurance, not a particular industry. At Novo Nordisk I separated platform qualification from application validation under a risk-based framework, reducing compliance overhead while strengthening the audit position.
See the evidence in Novo Nordisk ↗