Mike Lombardo

Vice President — Integrated Quality, Information Security, Data Privacy, GRC, AI Governance & GxP Compliance Executive | Regulated SaaS & Life Sciences

United States

About

At the helm of Dotmatics' Quality Management, my recent tenure is marked by a dedication to elevating both the Information Security and Quality Management Systems, including the critical development of policies and procedures that enhance data integrity and patient safety. Our team's efforts in process improvements and system implementations have solidified a robust QMS and ISMS infrastructure, reflecting a steadfast commitment to product quality. Previously, as an Associate Director at Intercept Pharmaceuticals, I harnessed my GxP expertise to provide oversight and improvement activities for quality management systems. This role was instrumental in advocating for a culture of continuous improvement and compliance, which has been a cornerstone of my professional ethos. My leadership in GxP training and support underscores a tireless pursuit of excellence that permeates all facets of my work.

Experience

  • Dotmatics (4 yrs 4 mos)
    • VP, Information Security
      Oct 2025 - Present · 10 mos

    • Head of Quality Management
      Apr 2022 - Oct 2025 · 3 yrs 7 mos

      Solely responsible for the design, implementation, and ongoing leadership of the enterprise QMS and ISO 2700 ISMS for a global scientific software enterprise comprising 15 independently operated brands. Performed the work of multiple roles – from strategic planning to operational execution – without dedicated team support. ● End-to-end ownership of QMS and ISMS lifecycles; authored all policies/procedures, built frameworks, implemented systems, trained staff, conducted internal audits, managed external certification and regulatory inspections. ● Led enterprise-wide ISO 27001 certification efforts, developing all risk assessments, controls and evidence while leading all brand-level implementations. ● Designed and implemented an ISO 13485-compliant QMS for Class I SaMD, aligned with EU MDR and FDA expectations/regulations to ensure effective transition from 21 CFR part 820 by February 2026. ● Built and harmonized an enterprise GRC framework integration ISO 9001, ISO 27001, 13485, NIST 800-53, GxP and industry specific regulations. ● Led SaaS GxP validation readiness, including CSV/CSA frameworks, SDLC definition, and validation documentation. ● Delivered annual and role-specific training programs on ISO, GxP, GAMP 5, and Information Security across all Brands. ● Provided strategic AI/ML governance guidance aligned with ISO/IEC 42001 and global regulatory frameworks (FDA, GMLP, EU MDR, IMDRG, Health Canada). ● Acted as Quality Manager for three Brands, ensuring full compliance lifecycle from strategy through operations and audits. ● Deployed and configured enterprise Information Security and Quality Management Systems (Veeva), supporting consistent, audit ready operations across all Brands.

  • Founder and Principal Consultant at QSV Management Services LLC
    Sep 2024 - Present · 1 yr 11 mos

    Expert guidance and support in areas including, but not limited to, Quality and Security Management, Validation (CSV), SDLC, and AI/ML (alignment with GAMP 5 and ISO 42001 standards). Our services cater primarily to small and medium-sized XaaS companies seeking to enter the pharmaceutical and biotech sectors. QSV Management provides comprehensive risk-based solutions in these critical areas, helping clients navigate industry-specific regulatory and operational challenges. In process of becoming ISO 9001 certified. Additional services include: • QMS/ISMS Staff support and/or augmentation • QMS / ISMS / AIMS Framework and Roadmap Development • QMS, ISMS, AIMS planning, project management, Implementation and training

  • Consultant at Secratic
    Oct 2023 - Present · 2 yrs 10 mos

    Provide strategic and operational consulting in Quality, Security, Risk Management, and AI/ML governance for SaaS and regulated life sciences clients, including pharmaceuticals, biotechnology, and medical devices. Engage on both project- based and ongoing support models to design, implement, and optimize management systems aligned with global regulatory requirements. ● Quality & Compliance Systems – Designed and implemented fit-for-purpose Quality Management Systems (QMS) aligned with ISO 9001, ISO 13485, GAMP 5, and FDA regulations (21 CFR Parts 11, 58, 210, 211, 820). ● Information Security & Risk Management – Developed and enhanced Information Security Management Systems (ISMS) in accordance with ISO/IEC 27001:2022, NIST 800-53, HIPAA, and SOC 2 Type 2; integrated cloud-native monitoring tools including TrendMicro–AWS and Safebase. ● AI/ML Governance – Guided clients in establishing Artificial Intelligence Management Systems (AIMS) aligned to ISO/IEC 42001 and AI lifecycle control best practices, ensuring regulatory readiness. ● Validation & SDLC – Authored and reviewed system lifecycle deliverables and validation documentation under CSA/CSV principles, EU Annex 11, 21 CFR Part 11, and GAMP 5; operationalized SDLC and validation frameworks for cloud-native SaaS architectures. ● Audit & Assessment Leadership – Served as SME during SOC 2 Type 2 audits, penetration testing, vulnerability assessments, and customer audits, ensuring readiness and strong representation across quality and security domains. ● Governance, Risk & Compliance (GRC) – Developed risk-based frameworks, SOPs, and roadmaps; integrated GRC tools to align with ISO, NIST, and applicable health authority guidance. ● Internal Quality Leadership – Currently leading ISO 9001 certification initiative for QSV Management Services’ internal QMS.

  • Associate Director, Quality Systems at Intercept Pharmaceuticals
    Jun 2020 - Apr 2022 · 1 yr 11 mos

    Owned and maintained the Intercept Quality Management Systems for a global pharmaceutical company focused on treatments for non-viral liver diseases, with full lifecycle responsibility for document control, QE/CAPA management, change control, vendor management and product complaints. ● System ownership: Served as owner/administrator for MasterControl; scoped, gathered requirements and led implementation of Veeva QMS to replace MasterControl. ● Quality Planning: Developed and executed the annual Quality Plans and Quality Improvement Plans to drive compliance and continuous improvement. ● Documentation & Compliance: Authored and reviewed global policies and SOPs supporting QMS, Security management, and CSV/SDLC processes; refined SOPs and Work Instructions for Quality Events, CAPA, change control, documentation management and product complaints. Defined CSV requirements to reflect InfoSec expectations in alignment with NIST 800-53 / ISO 27001. ● Project Leadership: Acted as PMO/QMS SME for consultants on remediation projects including Document Management and Training programs. ● Leadership Support: Served as formal backup to the Executive Director, Quality Systems (reporting to the CQO) ● Operational Transitions: Lead QMS-related activities for site closures (NY and SD) including change controls, record identification/storage, and team assignments, leadership / oversight.

  • Global Quality, Regulatory, IT Manager at ProQuest
    Nov 2016 - Jul 2020 · 3 yrs 9 mos

    ● Solely responsible for the design, implementation, and operational leadership of the Quality Management System (QMS) and supporting platforms (eDMS, LMS) for a pharmacovigilance software provider serving global pharmaceutical companies. Delivered full lifecycle quality oversight – from governance and documentation to audits, training, and supplier management – ensuring compliance with ISO 9001, GAMP 5, and global pharmacovigilance regulations. ● QMS Development & Leadership: Built and maintained a centralized QMS aligned to pharmacovigilance regulatory requirements, integrating document management and learning management capabilities for global teams. ● Policy & Procedure Authoring: Drafted all QMS procedures, validation policies, and SDLC documentation to align with GAMP 5 and applicable regulatory frameworks. ● ISO 9001 Certification: Sourced, led, and implemented all requirements to achieve ISO 9001 certification in less than one year, including full documentation suites, internal audits and management reviews. ● Supplier Quality Management: Designed and implemented the Supplier Qualification Program, including risk-based assessments, onboarding, and ongoing evaluation; conducted supplier audits to ensure compliance with contractual and regulatory obligations. ● Security by Design: Defined and lead initiatives to implement “Security by Design” practices into SDLC. ● Audit Leadership: Facilitated multiple zero-observation customer GxP audits by preparing audit documentation, training staff and serving as the primary quality representative. ● Cross-Functional Collaboration: Partnered with IT, Regulatory, Information Security and Operational teams to ensure security, quality and validation requirements were embedded into product development and delivery. ● Training & Competency: Developed and delivered role-specific training on QMS, SDLC, and regulatory compliance to staff across multiple functions and geographies.