
Staff Engineer, OT Security
Job description
About the role
Lila Sciences is seeking a Staff OT Security Engineer to own hands-on security engineering for Lila's Operational Technology environment across instruments, automation platforms, lab compute, and building automation systems. This role translates OT security architecture into operational controls across segmentation, identity, privileged access, vendor access, detection, response, and lifecycle management. The hire will operate with high autonomy, setting technical direction within their domain while serving as the senior technical voice for OT security architecture and engineering decisions. This is a foundational hire for Lila's OT security program as the company builds autonomous laboratories where security is designed into laboratory platforms before they ship.
Key facts
What you'll do
Translate OT security architecture into operational controls across segmentation, identity, privileged access, detection, response, and vendor access.
Design and validate zone-and-conduit segmentation aligned to IEC 62443, including security level targets and compensating controls where needed.
Develop OT-specific threat models for instruments, automation platforms, and lab buildouts, then translate findings into design and rollout decisions.
Own security review and technical sign-off for new automation platforms, vendor integrations, and laboratory deployments.
Design and operate machine identity, certificate lifecycle, privileged access, and secure vendor remote-access patterns for OT environments.
Operate and tune OT monitoring and visibility capabilities, including sensor coverage, behavioral baselines, and telemetry integration with central security operations.
Partner with SOC and detection engineering teams to build OT-specific detection content, runbooks, escalation paths, and incident response exercises.
Lead OT vulnerability and lifecycle management, including patch strategy, compensating controls, supplier security review, and residual risk documentation.
Pair with OT engineering, controls, automation, IT, and lab operations teams on segmentation, identity, network interactions, post-cutover stabilization, and incident response.
Mentor engineers, contractors, and managed-service partners as the OT function scales within Lila's growing laboratory footprint.
Contribute to secure-by-design principles for Lila's autonomous laboratory platforms, influencing product and infrastructure decisions from the outset.
Drive measurable improvements in OT security posture through metrics, reporting, and continuous refinement of controls and processes.
Act as a subject matter expert for internal and external stakeholders, aligning security initiatives with laboratory operations and business objectives.
Requirements
Significant hands-on experience in cybersecurity, infrastructure engineering, systems integration, or OT security engineering in operationally constrained environments.
Experience designing and implementing security controls in OT, industrial control systems, laboratory automation, manufacturing, infrastructure, or similarly constrained environments.
Strong working knowledge of segmentation, identity, access control, compensating controls, and secure remote access patterns.
Hands-on experience with one or more core OT security domains: machine identity, PKI, privileged access management, OT monitoring, detection engineering, vulnerability management, or incident response.
Solid networking and segmentation fundamentals, including VLANs, firewall policy, TCP/IP, DNS, DHCP, and packet analysis.
Ability to translate architecture into operating controls, runbooks, risk decisions, and repeatable engineering standards.
Strong written and verbal communication skills, including the ability to explain technical decisions to engineers, scientists, security leaders, and executives.
Willingness to work on-site at Lila laboratory locations on a regular basis, including participation in on-call rotation and scheduled maintenance or incident response coverage.
Nice to have
Experience in life sciences, biotechnology, pharmaceutical, laboratory automation, manufacturing, or high-throughput research environments.
Familiarity with IEC 62443, NIST SP 800-82, and other relevant frameworks for OT security.
Experience with security orchestration, automation, and response (SOAR) in OT contexts.
Knowledge of laboratory data flows, electronic lab notebook integrations, and instrument connectivity models.
Experience with cloud-connected devices and hybrid architectures that span on-premises and cloud environments.
Practical notes
This role requires on-site presence at Lila laboratory locations in Cambridge, Massachusetts.
Regular participation in on-call rotation is required to support operations and respond to security incidents.
Travel may be required to other Lila laboratory or client sites as needed.
Applicants must be authorized to work in the United States without sponsorship for this position.