SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Engineer, OT Security

Lila - Cambridge, MA, United States - Hybrid - posted 2026-07-28

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Lila Sciences is seeking a Staff OT Security Engineer to own hands-on security engineering for the company's Operational Technology environment across instruments, automation platforms, lab compute, and building automation systems. This is a senior individual contributor role reporting to the Senior Director, OT Operations & Security, with high autonomy to set technical direction within the OT security domain. Key responsibilities include translating OT security architecture into operational controls across segmentation, identity, privileged access, vendor access, detection, response, and lifecycle management. You will design and validate zone-and-conduit segmentation aligned to IEC 62443 standards, develop OT-specific threat models for instruments and automation platforms, and own security review and technical sign-off for new automation platforms, vendor integrations, and laboratory deployments. You will design and operate machine identity, certificate lifecycle, privileged access, and secure vendor remote-access patterns for OT environments. The role includes operating and tuning OT monitoring and visibility capabilities, partnering with SOC and detection engineering teams to build OT-specific detection content and incident response exercises, and leading OT vulnerability and lifecycle management including patch strategy and supplier security review. You will pair closely with OT engineering, controls, automation, IT, and lab operations teams on segmentation, identity, network interactions, post-cutover stabilization, and incident response. As the OT function scales, you will mentor engineers, contractors, and managed-service partners. Required qualifications include significant hands-on experience in cybersecurity, infrastructure engineering, systems integration, or OT security engineering in operationally constrained environments. You need experience designing and implementing security controls in OT, industrial control systems, laboratory automation, manufacturing, or similarly constrained environments. Strong working knowledge of segmentation, identity, access control, compensating controls, and secure remote access patterns is essential. Hands-on experience with core OT security domains such as machine identity, PKI, privileged access management, OT monitoring, detection engineering, vulnerability management, or incident response is required. You must have solid networking and segmentation fundamentals including VLANs, firewall policy, TCP/IP, DNS, DHCP, and packet analysis. The ability to translate architecture into operating controls, runbooks, risk decisions, and repeatable engineering standards is critical. Strong written and verbal communication skills are necessary to explain technical decisions to engineers, scientists, security leaders, and executives. Willingness to work on-site at Lila laboratory locations on a regular basis, including participation in on-call rotation and scheduled maintenance or incident response coverage, is required. Bonus qualifications include experience in life sciences, biotechnology, pharmaceutical, laboratory automation, manufacturing, or high-throughput research environments; familiarity with IEC 62443, NIST SP 800-82, NIST CSF, GxP, 21 CFR Part 11, or comparable frameworks; experience with OT visibility platforms such as Claroty, Tenable OT, Dragos, or Nozomi Networks; experience with PKI, TLS/mTLS, TPM-bound credentials, or modern machine identity patterns; experience with privileged access management platforms such as CyberArk, Delinea, or HashiCorp Vault; background in product security, embedded security, IoT security, or secure-at-ship programs; practical scripting or automation experience with Python, PowerShell, APIs, or infrastructure-as-code tooling; and relevant OT or security certifications such as GICSP, IEC 62443 Cybersecurity Expert, GIAC GRID, GCIH, or CISSP.

Similar roles