Lead Engineer Manufacturing Security
Job Summary
Bring more to life.
At Danaher our work saves lives. And each of us plays a part. Fueled by our culture of continuous improvement we turn ideas into impact innovating at the speed of life.
Our 60000 associates work across the globe at more than 15 unique businesses within life sciences diagnostics and biotechnology.
Are you ready to accelerate your potential and make a real difference At Danaher you can build an incredible career at a leading science and technology company where were committed to hiring and developing from within. Youll thrive in a culture of belonging where you and your unique viewpoint matter.
Learn about the Danaher Business System which makes everything possible.
TheLead Engineer Manufacturing SecurityisresponsibleforexecutingOT network security implementations at Danaher manufacturing sites under the direction of the Principal Architect and Lead Engineers. This role focuses on translating detailed OT architecture specifications into deployed network configurations working hands-on at the site level to implementfirewallpolicy VLAN segmentation and DMZ architecture in coordination withOpCoSite Engineers and the DIS network team. This position offers the opportunity to build deep operationalexpertisein industrial cybersecurity delivery across a truly global multi-OpComanufacturing environment.
This position is part of theCorporate Information Securityand will belocatedasPuneOffice.
In this role you will have the opportunity to:
Execute OT network segmentation implementations at assigned Danaher manufacturing sitesin accordance witharchitecture specifications from the DIS OTCoE configuring firewalls deploying VLANs implementing DMZ architectures and enforcing zone-based access controls in coordination with the DIS andOpConetwork teams
Partner withOpCoOT Site Engineers during site visits and change windows serving as the DIS technical presence to ensure implementation accuracy flag production risk in real time and adapt to site-specific constraints within the bounds of approved architecture
Validate OT segmentation implementations against architecture specifications post-deployment conducting connectivity validationfirewallrule audits zone boundary verification and compensating control checks to confirm designs have been correctly and completely executed
Document site-specific implementation findings as-built network configurations approved deviations and compensating controls maintainingaccuraterecords that feed into the enterprise OT asset inventory site risk register and DIS engineering knowledge base
Support knowledge transfer to the MSP Operations Team during transition from project delivery to steady-state operations developing runbooks escalation procedures and operational playbooks for each deployed site so the run team canmaintainsegmentation effectively
The essential requirements of the job include:
Hands-on experience configuring industrial firewalls implementing VLAN-based network segmentation and building DMZ architectures in OT or industrial environments withdemonstratedability to execute network changes safely in active production settings
Working knowledge of OT/ICS components and their network connectivity requirements including PLCs SCADA HMI historian and BMS systems sufficient to assess connectivity dependencies and implement segmentation without disrupting operational processes
Familiarity with OT cybersecurity frameworks (IEC 62443 NIST SP 800-82) and their application to network segmentation and access control with the ability to implement to specification and flag deviations for escalation to the Principal Architect or Lead Engineer
Experience executing network changes in regulated manufacturing environments (life sciences pharmaceutical medical device chemical or similar) with an understanding of the operational andGxPconstraints on change management in production-active facilities
7 years of experience in OT security engineering industrial network engineering or IT/OT integration with direct hands-on experience implementing network changes and segmentation configurations in active manufacturing environments
It would be a plus if you alsopossesspreviousexperience in:
Exposure to OT asset discovery platforms (Claroty Nozomi Networks Dragos or Armis) and experiencemaintainingOT asset inventories or contributing to site-level OT risk registers.
Familiarity withGxP-governed change management processes in life sciences manufacturing and experience working with production operations teams to schedule and execute network changes within validated system change control frameworks.
Join our winning team today. Together well accelerate the real-life impact of tomorrows science and technology. We partner with customers across the globe to help them solve their most complex challenges architecting solutions that bring the power of science to life.
For more information visit .
Required Experience:
Senior IC
About Company
WHO WE ARE We are a global science and technology innovator committed to helping customers solve complex challenges and improving quality of life around the world. These are the moments that make a difference. Performing a delicate operation on an unborn baby. Minimizing waste at ever ... View more