Lead Engineering Manufacturing Security
Danaher
- Location
- Pune Maharashtra India
- Work model
- On-Site
- Level
- Senior
- H-1B history
- 1 approvals (FY2023)
- Posted
- 19h ago
Skills
About this role
Bring more to life. At Danaher, our work saves lives. And each of us plays a part. Fueled by our culture of continuous improvement, we turn ideas into impact – innovating at the speed of life. Our 60,000+ associates work across the globe at more than 15 unique businesses within life sciences, diagnostics, and biotechnology. Are you ready to accelerate your potential and make a real difference? At Danaher, you can build an incredible career at a leading science and technology company, where we’re committed to hiring and developing from within. You’ll thrive in a culture of belonging where you and your unique viewpoint matter. Learn about the Danaher Business System which makes everything possible. The Lead Engineer, Manufacturing Security is responsible for executing operational technology (OT) Zero –Trust remote access security program and supporting network segmentation implementations at Danaher manufacturing sites as part of the DIS OT Security Center of Excellence. This role works closely with the OT Security Architects to deploy approved solutions for OT remote access controls, retire legacy VPN and vendor direct-connect solutions, and remediate uncontrolled third-party access across the global manufacturing portfolio. This position offers a unique opportunity to lead the operational execution of a strategic zero-trust remote access transformation across one of the most complex OT environments in the life sciences and diagnostics industry. This position is part of the Corporate Information Security and will be l ocated as Pune / Bangalore Office . In this role, you will have the opportunity to: Support the deployment and site-level configuration of a Zero Trust Remote Access Architecture for OT environments at Danaher manufacturing sites — working under the direction of the Remote Access Lead to operationalize OT remote access, retire legacy VPN solutions, and establish approved, monitored access methods for employees, contractors, and OT OEMs Conduct OT vendor remote access assessments at assigned manufacturing sites — identifying unauthorized or uncontrolled remote connections (legacy modems, consumer-grade remote tools, direct vendor links, unknown cellular connections) and coordinating remediation or replacement with DIS-approved solutions without disrupting production operations Implement site-level OT network segmentation changes with a specific focus on remote access zones, vendor access DMZs, and internet egress controls — working in coordination with the P4 Lead Engineers, OpCo Site Engineers, and the DIS network team during change window execution Manage the vendor remote access on-boarding process at assigned sites — ensuring all third-party connections to OT environments are submitted through the approved DIS process, properly documented, time-limited, monitored , and authorized before use Maintain accurate documentation of remote access architecture configurations, active vendor access records, and site-level deviations from standard design . The essential requirements of the job include: Hands-on experience deploying and managing ZTNA or SASE remote access solutions (Zscaler Private Access, Palo Alto Prisma Access, or equivalent) — including configuration of connectors, access policies, integration with identity providers, and split-tunneling for OT environments Working knowledge of OT/ICS vendor remote access patterns — including jump servers, remote desktop gateways, vendor-managed remote tools (TeamViewer, VNC, Putty, SSH, RDP ) , and industrial cellular modems — and the specific cybersecurity risks each access method introduces in a manufacturing environment Demonstrated ability to assess and remediate unauthorized or uncontrolled remote access in operational