Staff Controls Engineer
This Senior Staff Engineer role is a hands-on leadership position focused on designing, implementing, and securing the network infrastructure that supports automated manufacturing equipment and production systems. You will partner with IT, cybersecurity teams, controls engineers, and equipment vendors to ensure manufacturing systems are reliable, scalable, compliant, and protected from cyber threats.
About the role
The Sr. Staff Engineer for Network and Cybersecurity will lead network design and implementation, and collaborate on cybersecurity mitigations for equipment used in Manufacturing. The role involves cross-functional leadership with Insulet IT, Global Controls Engineering, and equipment vendors. The team is responsible for providing automated manufacturing controls and product test processes that are capable, secure, scalable globally, cost-effective, reliable, documented, and validated. This role reports directly to Manufacturing and offers global responsibilities, including determining standards and processes for implementation across all manufacturing sites.
Responsibilities
- Design and configure VLANs, IP addressing schemes, and network segmentation between manufacturing zones and the enterprise network, consistent with ISA-95/IEC 62443.
- Drive the network and cybersecurity aspects of design, development, implementation, and analysis of plant-floor network infrastructure supporting automated high-speed manufacturing and test control systems, including servo drives, HMI, PLCs, equipment safety systems, robots, I/O systems, and data collection.
- Review network and security requirements in equipment specifications during vendor selection and verify vendor compliance at FAT/SAT before equipment ships or is released to production.
- Coordinate with IT to maintain infrastructure supporting manufacturing systems and documentation including network architecture documentation, IP schemas, and asset inventory.
- Enable appropriate need-based access to equipment systems for both onsite and remote users.
- Support incident investigation and recovery for manufacturing systems, serving as the OT technical resource to the Enterprise Cybersecurity team.
- Participate in disaster recovery and business continuity planning for manufacturing systems, including recovery time objectives for critical production equipment.
- Support ISO27001, SOC, HITRUST, and other audit activities for security operations, threat intelligence, and incident response.
- Collaborate with Corporate Cybersecurity team to analyze incident and alert trends to recognize threat groups, attack patterns, tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and attack vectors for a holistic understanding of the threat landscape.
- Support process verification, validation, and documentation.
Requirements
- Bachelor of Science in Electrical Engineering, Computer Science, Computer Engineering, Cybersecurity, or related field.
- 10+ years of hands-on network engineering and/or cybersecurity implementation, including network architecture, segmentation, remote access, and firewall administration, with demonstrated experience applying these in an industrial control system environment.
Skills
- Understanding of EtherNet/IP, Modbus TCP, OPC UA, or other industrial protocols.
- Experience in deploying and configuring industrial network switches such as Cisco IE series, Allen-Bradley Stratix, Moxa, etc.
- Working knowledge of core network services - IP address schema design, DHCP/DNS/NTP.
- Working knowledge of security standards such as IEC-62443 and NIST SP800.
- Working knowledge of Crowdstrike, SentinelOne, Microsoft Defender or similar EDR and Vulnerability Management (VM) solutions, Dragos / Claroty / Armis / Nozomi OT solutions, and runZero as dashboard.
- Cisco CCNA Routing and Switching and/or CCNA Wireless certification preferred.
- Palo Alto Networks PCNSE certification preferred.
- Understanding of the cyber-attack kill chain, MITRE ATT&CK Framework, and Zero Trust EDR in manufacturing; SIEM/SOAR awareness to partner with Enterprise Cybersecurity team.
- Cybersecurity certifications such as GCFA, GCIH, GCTI, or GICSP preferred.
- Familiarity with plant-floor IT infrastructure - Windows Server, Active Directory, virtualization (VMware/Hyper-V), thin clients, and backup/recovery for equipment PCs, sufficient for system design and support in a medical device manufacturing environment.
- Appreciation for the engineering, design, and development of manufacturing equipment for high volume, high speed, high precision assembly operation and complex industrial systems.
- Experience with Rockwell Automation products preferred.
- Experience in a medical device or regulated environment with validated processes preferred.
- Familiarity with computer systems validation, 21 CFR Part 11, and change management.
- Basic understanding of ALCOA+.
- Strong project management, organizational, and documentation skills desired.
- Ability to work in a collaborative, safe, continuously improving, and dynamic team environment.
Schedule
- On-site role with approximately 20% domestic and international travel.
Pay
For U.S.-based positions, the annual base salary range for this role is $141,600.00 - $212,400.00. This position may also be eligible for incentive compensation.
Benefits
- Medical, dental, and vision insurance.
- 401(k) with company match.
- Paid time off (PTO).
- Additional employee wellness programs.