- Location
- IND - Pune - Pall India Pvt Ltd · Bangalore, Karnataka, India
- Type
- Full-time
- Department
- Engineering
- Seniority
- Lead
- Experience
- 7+ years
- Source
- Workday
Description
Bring more to life.
At Danaher, our work saves lives. And each of us plays a part. Fueled by our culture of continuous improvement, we turn ideas into impact – innovating at the speed of life.
Our 60,000+ associates work across the globe at more than 15 unique businesses within life sciences, diagnostics, and biotechnology.
Are you ready to accelerate your potential and make a real difference? At Danaher, you can build an incredible career at a leading science and technology company, where we’re committed to hiring and developing from within. You’ll thrive in a culture of belonging where you and your unique viewpoint matter.
Learn about the Danaher Business System which makes everything possible.
The Lead Engineer, Manufacturing Security is responsible for executing OT network security implementations at Danaher manufacturing sites under the direction of the Principal Architect and Lead Engineers. This role focuses on translating detailed OT architecture specifications into deployed network configurations — working hands-on at the site level to implement firewall policy, VLAN segmentation, and DMZ architecture in coordination with OpCo Site Engineers and the DIS network team. This position offers the opportunity to build deep operational expertise in industrial cybersecurity delivery across a truly global, multi-OpCo manufacturing environment.
This position is part of the Corporate Information Security and will be located as Pune Office.
In this role, you will have the opportunity to:
Execute OT network segmentation implementations at assigned Danaher manufacturing sites in accordance with architecture specifications from the DIS OT CoE — configuring firewalls, deploying VLANs, implementing DMZ architectures, and enforcing zone-based access controls in coordination with the DIS and OpCo network teams
Partner with OpCo OT Site Engineers during site visits and change windows — serving as the DIS technical presence to ensure implementation accuracy, flag production risk in real time, and adapt to site-specific constraints within the bounds of approved architecture
Validate OT segmentation implementations against architecture specifications post-deployment — conducting connectivity validation, firewall rule audits, zone boundary verification, and compensating control checks to confirm designs have been correctly and completely executed
Document site-specific implementation findings, as-built network configurations, approved deviations, and compensating controls — maintaining accurate records that feed into the enterprise OT asset inventory, site risk register, and DIS engineering knowledge base
Support knowledge transfer to the MSP Operations Team during transition from project delivery to steady-state operations — developing runbooks, escalation procedures, and operational playbooks for each deployed site so the run team can maintain segmentation effectively
The essential requirements of the job include:
Hands-on experience configuring industrial firewalls, implementing VLAN-based network segmentation, and building DMZ architectures in OT or industrial environments — with demonstrated ability to execute network changes safely in active production settings
Working knowledge of OT/ICS components and their network connectivity requirements — including PLCs, SCADA, HMI, historian, and BMS systems — sufficient to assess connectivity dependencies and implement segmentation without disrupting operational processes
Familiarity with OT cybersecurity frameworks (IEC 62443, NIST SP 800-82) and their application to network segmentation and access control — with the ability to implement to specification and flag deviations for escalation to the Principal Architect or Lead Engineer
Experience executing network changes in regulated manufacturing environments (life sciences, pharmaceutical, medical device, chemical, or similar) with an understanding of the operational and GxP constraints on change management in production-active facilities
7+ years of experience in OT security engineering, industrial network engineering, or IT/OT integration, with direct hands-on experience implementing network changes and segmentation configurations in active manufacturing environments
It would be a plus if you also possess previous experience in:
Exposure to OT asset discovery platforms (Claroty, Nozomi Networks, Dragos, or Armis) and experience maintaining OT asset inventories or contributing to site-level OT risk registers.
Familiarity with GxP-governed change management processes in life sciences manufacturing and experience working with production operations teams to schedule and execute network changes within validated system change control frameworks.
Join our winning team today. Together, we’ll accelerate the real-life impact of tomorrow’s science and technology. We partner with customers across the globe to help them solve their most complex challenges, architecting solutions that bring the power of science to life.
For more information, visit www.danaher.com.