
Principal Architect, Manufacturing Security
Posted Aug 21

Posted Aug 21
This is a fully remote position, open to applicants in Denmark.
• Take ownership and enhance Danaher's enterprise OT security architecture framework across its worldwide manufacturing portfolio.
• Establish standards for network segmentation, tiered ISA-95/Purdue security zones, IT/OT boundary controls, DMZ configurations, and BMS isolation strategies.
• Spearhead the organization-wide implementation of secure remote access architecture, phasing out outdated VPN and direct-vendor connections.
• Expand zero-trust network access to OT OEMs, contractors, and remote support vendors.
• Collaborate with Manufacturing Security and information security leadership on OT cybersecurity policies, governance standards for architecture, and control frameworks.
• Convert governance standards into implementation plans at the OpCo level.
• Facilitate the Architecture Review Board process for OT security capabilities, including micro-segmentation, remote access OT expansion, OT monitoring tools, and industrial firewall platforms.
• Assess technical designs prior to deployment and uphold architectural standards throughout the portfolio.
• Counsel OpCo CIOs, site IT leaders, and plant engineers regarding OT security architecture.
• Offer architectural consultation for high-risk sites and supervise the segmentation remediation program.
• Provide guidelines and standards that support the secure enablement of digital manufacturing.
• Profound expertise in OT/ICS network architecture, encompassing Purdue Model/ISA-95 zone segmentation, industrial DMZ design, OT protocol firewall policies (Modbus, Profinet, EtherNet/IP, OPC-UA, BACnet), and secure remote access architecture.
• Practical experience in designing and validating network segmentation within complex, multi-site OT environments, including PLCs, DCS, SCADA, BMS, HMI, and historian systems.
• Background in life sciences, pharmaceuticals, or similarly regulated manufacturing sectors.
• Strong knowledge of IEC 62443, NIST SP 800-82, CIS Controls for ICS, and CISA/NSA OT security guidelines.
• Proven experience applying OT cybersecurity standards within a federated, multi-OpCo enterprise.
• Familiarity with ZTNA and SASE architectures, including Zscaler or equivalent, in OT environments.
• Experience in integrating industrial remote access protocols, vendor management workflows, and identity governance.
• Over 12 years of experience in OT/ICS security, network architecture, or industrial cybersecurity.
• A minimum of 5 years in a principal architect, distinguished engineer, or similar senior individual-contributor role within a complex multi-site manufacturing environment.
• Opportunities for career development and internal hiring.
• A culture that fosters belonging.
• Approximately 10% regional and international travel.
GitLab
GitLab
Cisco
Lovesac
Get handpicked remote jobs straight to your inbox weekly.