Key responsibilities:
A. IT Project Governance
- Establish and maintain an effective IT Project Governance framework.
- Define minimum governance requirements applicable to IT projects based on project size, complexity, risk and
criticality.
- Ensure projects follow the defined project lifecycle from initiation through closure.
- Establish project governance checkpoints and quality gates.
- Review project governance compliance at defined stages of the project lifecycle.
- Ensure appropriate project initiation, planning, execution, monitoring and closure practices are followed.
- Ensure Project Charters / Project Initiation Documents are prepared and approved where applicable.
- Ensure project scope, objectives, deliverables, timelines, resources and responsibilities are clearly defined.
- Ensure appropriate governance forums and review mechanisms are established for major projects.
- Review project status, risks, issues, dependencies and escalations from a governance perspective.
- Ensure significant project deviations are appropriately documented, approved and escalated.
- Monitor compliance with defined project management methodologies and organisational standards.
B. Project Planning & Management Process Compliance
- Ensure project teams follow defined project management processes and templates.
- Review adequacy of project plans, milestones, deliverables and dependencies.
- Ensure appropriate resource planning and responsibility allocation.
- Monitor compliance with project review and reporting requirements.
- Ensure project risks and issues are identified, assessed, tracked and mitigated.
- Ensure appropriate change control mechanisms are followed for scope, timeline, cost, resources and technical
changes.
- Monitor project baseline changes and ensure appropriate approvals are obtained.
- Ensure project decisions and key actions are documented and tracked to closure.
- Ensure appropriate stakeholder communication and escalation mechanisms are followed.
C. Project Quality Assurance & Audits
- Develop and implement a Project Quality Assurance framework.
- Conduct periodic project quality reviews and governance audits.
- Assess project compliance against defined project management and SDLC processes.
- Conduct stage-wise quality assessments at appropriate project milestones.
- Identify process gaps, non-conformities and governance weaknesses.
Issue quality audit observations and track corrective actions to closure.
- Conduct follow-up audits to verify effectiveness of corrective actions.
- Identify recurring project governance issues and recommend systemic improvements.
- Maintain audit evidence and ensure projects remain audit-ready.
- Support internal and external audits relating to IT projects, software development and information security.
- Provide independent quality assessments to management on project health and compliance.
D. Software SDLC Governance
- Establish and maintain the organisation's Software Development Life Cycle (SDLC) framework.
- Ensure adherence to defined SDLC processes across all application development projects.
- Define appropriate quality gates covering:
- Business requirements
- Requirement analysis
- Solution / technical design
- Development
- Code review
- Testing
- Security assessment
- UAT
- Deployment
- Release
- Post-production review
• Ensure appropriate documentation and evidence are maintained at each SDLC stage.
- Conduct periodic SDLC compliance assessments.
- Drive corrective and preventive actions for SDLC deviations.
- Establish appropriate approval and sign-off mechanisms for critical SDLC stages.
E. Software Quality Assurance
- Develop and implement Software Quality Assurance practices for application development.
- Establish software quality standards, procedures, guidelines and checklists.
- Define and monitor software quality KPIs and project-level quality metrics.
- Review development processes to identify quality risks and improvement opportunities.
- Conduct project/process quality reviews.
- Ensure defects, quality issues and process deviations are recorded, analysed and closed.
- Drive Root Cause Analysis for significant software quality issues.
- Establish lessons-learned mechanisms and ensure recurring issues are addressed.
- Promote quality-by-design rather than relying solely on testing to identify defects.
F. Application Security & Secure SDLC
- Integrate Information Security requirements into the Software Development Life Cycle.
- Establish and monitor Secure SDLC practices in coordination with Information Security.
- Ensure appropriate security requirements are defined during requirements and design stages.
- Ensure Secure Code Review is performed as applicable.
- Ensure Vulnerability Assessment & Penetration Testing (VAPT) is conducted at appropriate stages before production deployment.
- Ensure identified vulnerabilities are risk-rated, tracked and remediated within defined timelines.
- Monitor closure of Critical and High security vulnerabilities.
- Ensure security exceptions are formally documented, risk-assessed and approved.
- Coordinate application security assessments with the Information Security team.
- Promote secure coding practices and security awareness within development teams.
- Support implementation of DevSecOps practices wherever applicable.
G. Software Testing & Defect Governance
- Define and govern the overall software testing framework in collaboration with development and testing teams.
- Ensure appropriate testing based on application risk and complexity.
- Ensure appropriate functional, integration, regression, performance, security and UAT activities are performed.
- Establish testing entry and exit criteria.
- Monitor defect trends and defect leakage.
- Analyse production defects and identify systemic causes.
- Ensure appropriate test evidence and approvals are maintained.
- Drive improvement in testing effectiveness and automation.
H. Change, Release & Deployment Governance
POSITION /
- Establish and monitor governance requirements for application changes and releases.
- Ensure appropriate Change Management processes are followed.
- Ensure changes are assessed for business, technical, security and operational impact.
- Ensure appropriate testing and approvals are obtained before production implementation.
- Establish release readiness criteria.
- Ensure mandatory quality and security gates are completed before Go-Live.
- Review release exceptions and ensure appropriate risk acceptance.
- Monitor emergency changes and post-implementation reviews.
- Analyse production incidents attributable to inadequate release/change governance.
I. Project Risk & Issue Governance
- Establish appropriate project risk management practices.
- Review project risks periodically and assess adequacy of mitigation plans.
- Ensure critical risks are escalated to appropriate governance forums.
- Monitor ageing and closure of project issues.
- Identify cross-project risks, dependencies and systemic issues.
- Escalate significant risks that may impact project scope, timeline, quality, security or business outcomes.
- Ensure risk acceptance and exception management processes are followed.
J. Project Metrics, Dashboards & Management Reporting
- Establish project governance and quality KPIs.
- Develop management dashboards covering project health, quality, SDLC compliance and security.
- Track metrics such as:
- Project milestone adherence
- SDLC compliance
- Project governance compliance
- Open project risks/issues
- Defect trends
- Production defect leakage
- Security vulnerabilities
- VAPT compliance
- Change/release compliance
- Audit observations
- Corrective action closure
• Provide periodic project quality and governance reports to senior management.
- Identify trends and emerging risks through data analysis.
- Provide recommendations for management intervention where required.
📌 Software Quality Manager (Mumbai)
🏢 Writer
📍 Mumbai