- Location
- IND - Pune - Pall India Pvt Ltd · Bangalore, Karnataka, India
- Type
- Full-time
- Department
- Engineering
- Seniority
- Lead
- Experience
- 7+ years
- Source
- Workday
Description
Bring more to life.
At Danaher, our work saves lives. And each of us plays a part. Fueled by our culture of continuous improvement, we turn ideas into impact – innovating at the speed of life.
Our 60,000+ associates work across the globe at more than 15 unique businesses within life sciences, diagnostics, and biotechnology.
Are you ready to accelerate your potential and make a real difference? At Danaher, you can build an incredible career at a leading science and technology company, where we’re committed to hiring and developing from within. You’ll thrive in a culture of belonging where you and your unique viewpoint matter.
Learn about the Danaher Business System which makes everything possible.
The Lead Engineer, Manufacturing Security is responsible for executing operational technology (OT) Zero –Trust remote access security program and supporting network segmentation implementations at Danaher manufacturing sites as part of the DIS OT Security Center of Excellence. This role works closely with the OT Security Architects to deploy approved solutions for OT remote access controls, retire legacy VPN and vendor direct-connect solutions, and remediate uncontrolled third-party access across the global manufacturing portfolio. This position offers a unique opportunity to lead the operational execution of a strategic zero-trust remote access transformation across one of the most complex OT environments in the life sciences and diagnostics industry.
This position is part of the Corporate Information Security and will be located as Pune / Bangalore Office.
In this role, you will have the opportunity to:
Support the deployment and site-level configuration of a Zero Trust Remote Access Architecture for OT environments at Danaher manufacturing sites — working under the direction of the Remote Access Lead to operationalize OT remote access, retire legacy VPN solutions, and establish approved, monitored access methods for employees, contractors, and OT OEMs
Conduct OT vendor remote access assessments at assigned manufacturing sites — identifying unauthorized or uncontrolled remote connections (legacy modems, consumer-grade remote tools, direct vendor links, unknown cellular connections) and coordinating remediation or replacement with DIS-approved solutions without disrupting production operations
Implement site-level OT network segmentation changes with a specific focus on remote access zones, vendor access DMZs, and internet egress controls — working in coordination with the P4 Lead Engineers, OpCo Site Engineers, and the DIS network team during change window execution
Manage the vendor remote access on-boarding process at assigned sites — ensuring all third-party connections to OT environments are submitted through the approved DIS process, properly documented, time-limited, monitored, and authorized before use
Maintain accurate documentation of remote access architecture configurations, active vendor access records, and site-level deviations from standard design .
The essential requirements of the job include:
Hands-on experience deploying and managing ZTNA or SASE remote access solutions (Zscaler Private Access, Palo Alto Prisma Access, or equivalent) — including configuration of connectors, access policies, integration with identity providers, and split-tunneling for OT environments
Working knowledge of OT/ICS vendor remote access patterns — including jump servers, remote desktop gateways, vendor-managed remote tools (TeamViewer, VNC, Putty, SSH, RDP ), and industrial cellular modems — and the specific cybersecurity risks each access method introduces in a manufacturing environment
Demonstrated ability to assess and remediate unauthorized or uncontrolled remote access in operational technology environments — including discovering unknown connections, engaging vendors on remediation, and transitioning to approved access methods without causing production disruption
Familiarity with OT network architecture principles (Purdue Model, ISA-95 zone segmentation, DMZ patterns) and the specific remote access controls required at each network boundary, including firewall policy, NAT, logging, and session monitoring requirements
7+ years of experience in OT security, network security, or remote access engineering, with hands-on experience in vendor connectivity management, third-party access governance, or OT network security in industrial or manufacturing environments
It would be a plus if you also possess previous experience in:
Experience integrating OT remote access solutions— including vendor on-boarding workflows, periodic access review cycles, and deprovisioning procedures that close the loop between IT security, procurement, and plant operations.
Familiarity with privileged access management (PAM) solutions as applied to OT remote sessions, and experience with OT-specific network monitoring tools that provide real-time visibility into active remote connections and anomalous access behavior.
Join our winning team today. Together, we’ll accelerate the real-life impact of tomorrow’s science and technology. We partner with customers across the globe to help them solve their most complex challenges, architecting solutions that bring the power of science to life.
For more information, visit www.danaher.com.