ironquill.tech/board

$ cat jobs/staff-engineer-ot-security-lila-sciences-93449d117f3d.json

Staff Engineer, OT Security

Lila Sciences·US·Cambridge, MA USA·senior
Apply on greenhouse → Get AI match score →
Your Impact at LILA Lila Sciences is seeking a Staff OT Security Engineer to own hands-on security engineering for Lila’s Operational Technology environment across instruments, automation platforms, lab compute, and building automation systems. This role translates OT security architecture into operational controls across segmentation, identity, privileged access, vendor access, detection, response, and lifecycle management. This is a senior individual contributor role reporting to the Senior Director, OT Operations & Security. The Staff OT Security Engineer partners closely with OT security architecture, Staff OT engineers, the SOC and detection engineering teams, controls and automation, corporate IT, and laboratory operations leadership. The right person operates with high autonomy, sets technical direction within their domain, and serves as the senior technical voice for OT security architecture and engineering decisions. This is a foundational hire for Lila’s OT security program. Lila is building autonomous laboratories where security is designed into laboratory platforms before they ship. This person will help turn that secure-at-ship model into durable operating controls, validated deployments, and day-to-day security operations across Lila’s active and expanding lab environments. What You'll Be Building Translate OT security architecture into operational controls across segmentation, identity, privileged access, detection, response, and vendor access. Design and validate zone-and-conduit segmentation aligned to IEC 62443, including security level targets and compensating controls where needed. Develop OT-specific threat models for instruments, automation platforms, and lab buildouts, then translate findings into design and rollout decisions. Own security review and technical sign-off for new automation platforms, vendor integrations, and laboratory deployments. Design and operate machine identity, certificate lifecycle, privileged access, and secure vendor r