Responsibilities
- Translate OT security architecture into operational controls across segmentation, identity, privileged access, detection, response, and vendor access.
- Design and validate zone-and-conduit segmentation aligned to IEC 62443, including security level targets and compensating controls where needed.
- Develop OT-specific threat models for instruments, automation platforms, and lab buildouts, then translate findings into design and rollout decisions.
- Own security review and technical sign-off for new automation platforms, vendor integrations, and laboratory deployments.
- Design and operate machine identity, certificate lifecycle, privileged access, and secure vendor remote-access patterns for OT environments.
- Operate and tune OT monitoring and visibility capabilities, including sensor coverage, behavioral baselines, and telemetry integration with central security operations.
- Partner with SOC and detection engineering teams to build OT-specific detection content, runbooks, escalation paths, and incident response exercises.
- Lead OT vulnerability and lifecycle management, including patch strategy, compensating controls, supplier security review, and residual risk documentation.
- Pair with OT engineering, controls, automation, IT, and lab operations teams on segmentation, identity, network interactions, post-cutover stabilization, and incident response.
- Mentor engineers, contractors, and managed-service partners as the OT function scales.
Requirements
- Significant hands-on experience in cybersecurity, infrastructure engineering, systems integration, or OT security engineering in operationally constrained environments.
- Experience designing and implementing security controls in OT, industrial control systems, laboratory automation, manufacturing, infrastructure, or similarly constrained environments.
- Strong working knowledge of segmentation, identity, access control, compensating controls, and secure remote access patterns.
- Hands-on experience with one or more core OT security domains: machine identity, PKI, privileged access management, OT monitoring, detection engineering, vulnerability management, or incident response.
- Solid networking and segmentation fundamentals, including VLANs, firewall policy, TCP/IP, DNS, DHCP, and packet analysis.
- Ability to translate architecture into operating controls, runbooks, risk decisions, and repeatable engineering standards.
- Strong written and verbal communication skills, including the ability to explain technical decisions to engineers, scientists, security leaders, and executives.
- Willingness to work on-site at Lila laboratory locations on a regular basis, including participation in on-call rotation and scheduled maintenance or incident response coverage.
Nice to Have
- Experience in life sciences, biotechnology, pharmaceutical, laboratory automation, manufacturing, or high-throughput research environments.
- Familiarity with IEC 62443, NIST SP 800-82, NIST CSF, GxP, 21 CFR Part 11, ISO 9001, or comparable quality and security frameworks.
- Experience with OT visibility platforms such as Claroty, Tenable OT, Dragos, Nozomi Networks, or comparable tools.
- Experience with PKI, TLS/mTLS, TPM-bound credentials, certificate lifecycle management, or modern machine identity patterns.
- Experience with privileged access management platforms such as CyberArk, Delinea, HashiCorp Vault, or comparable tools.
- Background in product security, embedded security, IoT security, secure-at-ship programs, or shift-left security practices.
- Practical scripting or automation experience with Python, PowerShell, APIs, or infrastructure-as-code tooling.
- Relevant OT or security certifications such as GICSP, IEC 62443 Cybersecurity Expert, GIAC GRID, GCIH, CISSP, or similar credentials.
Work Arrangement
On-site — Lila laboratory locations
Team
Structure: Individual contributor role; partners with OT security architecture, Staff OT engineers, SOC and detection engineering teams, controls and automation, corporate IT, and laboratory operations leadership.. Reports to: Senior Director, OT Operations & Security
Additional Information
- On-site work required at Lila laboratory locations.
- Participation in on-call rotation required.
- Scheduled maintenance or incident response coverage required.