Lead Engineer, Manufacturing Security - USA Remote
Danaher
- Location
- USA - Remote
- Work model
- Remote
- Level
- Senior
- H-1B history
- 1 approvals (FY2023)
- Posted
- Sep 16, 2026
Skills
About this role
Bring more to life. At Danaher, our work saves lives. And each of us plays a part. Fueled by our culture of continuous improvement, we turn ideas into impact – innovating at the speed of life. Our 60,000+ associates work across the globe at more than 15 unique businesses within life sciences, diagnostics, and biotechnology. Are you ready to accelerate your potential and make a real difference? At Danaher, you can build an incredible career at a leading science and technology company, where we’re committed to hiring and developing from within. You’ll thrive in a culture of belonging where you and your unique viewpoint matter. Learn about the Danaher Business System which makes everything possible. The Lead Engineer, Manufacturing Security is responsible for leading the design and delivery of OT network security improvements across a defined platform portfolio of Danaher operating companies. This role translates enterprise OT architecture standards into site-specific implementation plans — driving network segmentation, firewall deployment, and DMZ build projects through to production cutover while serving as the senior technical resource for OT security delivery at the platform level. This position sits at the intersection of architecture, engineering, and operational execution in one of the most complex industrial cybersecurity programs in the global life sciences sector. This position is part of the Corporate Information Security and will be fully Remote. In this role, you will have the opportunity to: Serve as the senior OT security technical resource and primary DIS engineering point of contact for assigned platform operating companies — building trusted relationships with OpCo CIOs, IT leads, and plant engineers to translate DIS architecture standards into locally executable implementation plans Translate enterprise OT architecture blueprints from the Principal Architect into network-executable engineering designs including firewall policy, VLAN topology, DMZ architecture, access control rules, and compensating controls for EoL/legacy assets — ensuring designs are safe to implement in active manufacturing environments Partner with OpCo OT Site Engineers and network teams during change window execution — serving as the DIS technical lead on-site or on-call during cutover to ensure segmentation changes are implemented without disrupting production operations, batch processes, or automated manufacturing systems Contribute to the deployment of OT remote access controls at platform sites alongside the Remote Access Lead — replacing legacy VPN, direct-vendor connections, and consumer-grade remote tools with approved, monitored, and controlled access methods Build the engineering knowledge base for the OT Security — documenting site-specific architecture decisions, implementation playbooks, deviation rationales, and as-built network diagrams for use by the broader DIS manufacturing security team The essential requirements of the job include: Strong hands-on experience designing and implementing OT network segmentation in live industrial environments — including VLAN architecture, industrial firewall configuration (Fortinet, Palo Alto, Cisco, or equivalent), DMZ build, and zone-based access controls across multi-site manufacturing operations Demonstrated ability to lead OT network change projects in production-sensitive environments — including scheduling around production cycles, coordinating with plant operations and safety teams, and implementing compensating controls during transition periods without causing unplanned downtime Deep familiarity with OT/ICS components and their network dependencies — including PLCs, DCS, SCADA, HMI, historian, and BMS systems — and the OT protocols they rely on (Modbus, Profinet, EtherNet/IP, OPC-UA, BACnet) — sufficient to make correct firewall and segmentation decisions in the presence of vendor and OpCo constraints Working knowledge of IEC