Jobs · Information Technology · Massachusetts

Staff Engineer, OT Security

Lila Sciences · Cambridge, MA · 1 mo ago
On-siteInformation Technology$140k/yrFull-time

About the role

The Staff OT Security Engineer will translate OT security architecture into operational controls across segmentation, identity, privileged access, detection, response, and vendor access. This role will also develop OT-specific threat models, design and validate zone-and-conduit segmentation aligned to IEC 62443, and partner with various teams to ensure robust security operations.

Responsibilities

  • Translate OT security architecture into operational controls across segmentation, identity, privileged access, detection, response, and vendor access.
  • Develop OT-specific threat models for instruments, automation platforms, and lab buildouts, then translate findings into design and rollout decisions.
  • Own security review and technical sign-off for new automation platforms, vendor integrations, and laboratory deployments.
  • Design and operate machine identity, certificate lifecycle, privileged access, and secure vendor remote-access patterns for OT environments.
  • Operate and tune OT monitoring and visibility capabilities, including sensor coverage, behavioral baselines, and telemetry integration with central security operations.
  • Partner with SOC and detection engineering teams to build OT-specific detection content, runbooks, escalation paths, and incident response exercises.
  • Lead OT vulnerability and lifecycle management, including patch strategy, compensating controls, supplier security review, and residual risk documentation.
  • Pair with OT engineering, controls, automation, IT, and lab operations teams on segmentation, identity, network interactions, post-cutover stabilization, and incident response.
  • Mentor engineers, contractors, and managed-service partners as the OT function scales.

Requirements

  • Significant hands-on experience in cybersecurity, infrastructure engineering, systems integration, or OT security engineering in operationally constrained environments.
  • Experience designing and implementing security controls in OT, industrial control systems, laboratory automation, manufacturing, infrastructure, or similarly constrained environments.
  • Strong working knowledge of segmentation, identity, access control, compensating controls, and secure remote access patterns.
  • Hands-on experience with one or more core OT security domains: machine identity, PKI, privileged access management, OT monitoring, detection engineering, vulnerability management, or incident response.
  • Solid networking and segmentation fundamentals, including VLANs, firewall policy, TCP/IP, DNS, DHCP, and packet analysis.
  • Ability to translate architecture into operating controls, runbooks, risk decisions, and repeatable engineering standards.
  • Strong written and verbal communication skills, including the ability to explain technical decisions to engineers, scientists, security leaders, and executives.
  • Willingness to work on-site at Lila laboratory locations on a regular basis, including participation in on-call rotation and scheduled maintenance or incident response coverage.

Qualifications

  • Education: Bachelor's degree in Computer Science, Electrical Engineering, Information Security, or related field.
  • Experience: Minimum 5 years of relevant experience in cybersecurity, OT security, or related fields.
  • Technical Certifications: Relevant certifications such as GICSP, IEC 62443 Cybersecurity Expert, GIAC GRID, GCIH, CISSP, or similar.

Skills

  • Experience with IEC 62443, NIST SP 800-82, NIST CSF, GxP, 21 CFR Part 11, ISO 9001, or comparable quality and security frameworks.
  • Familiarity with OT visibility platforms such as Claroty, Tenable OT, Dragos, Nozomi Networks, or comparable tools.
  • Experience with PKI, TLS/mTLS, TPM-bound credentials, certificate lifecycle management, or modern machine identity patterns.
  • Experience with privileged access management platforms such as CyberArk, Delinea, HashiCorp Vault, or comparable tools.
  • Background in product security, embedded security, IoT security, secure-at-ship programs, or shift-left security practices.
  • Practical scripting or automation experience with Python, PowerShell, APIs, or infrastructure-as-code tooling.

Benefits

We offer competitive base compensation with bonus potential and generous early-stage equity. U.S. employees receive a comprehensive benefits program including medical, dental, and vision coverage; employer-paid life and disability insurance; flexible time off with generous company wide holidays; paid parental leave; an educational assistance program; commuter benefits, including bike share memberships for office based employees; and a company subsidized lunch program.

Similar jobs

Staff Engineer, Security

Grow TherapyUnited States· 1 mo ago
RemoteInformation Technology$217k–$288k/yrapply on jobs.ashbyhq.com

Staff Engineer, Security

Grow TherapySan Francisco, CA· 1 mo ago
Information Technology$217k–$288k/yrapply on jobs.ashbyhq.com

Staff Engineer, Security

Grow TherapyNew York, NY· 1 mo ago
Information Technology$217k–$288k/yrapply on jobs.ashbyhq.com

Staff Security Engineer

Compass Real Estate - PeninsulaManhattan, NY· 1 mo ago
Information Technologyapply on compass.com