Principal Architect, Manufacturing Security

Posted Aug 21

This is a fully remote position, open to applicants in Denmark.

📋 Description

• Take ownership and enhance Danaher's enterprise OT security architecture framework across its worldwide manufacturing portfolio.

• Establish standards for network segmentation, tiered ISA-95/Purdue security zones, IT/OT boundary controls, DMZ configurations, and BMS isolation strategies.

• Spearhead the organization-wide implementation of secure remote access architecture, phasing out outdated VPN and direct-vendor connections.

• Expand zero-trust network access to OT OEMs, contractors, and remote support vendors.

• Collaborate with Manufacturing Security and information security leadership on OT cybersecurity policies, governance standards for architecture, and control frameworks.

• Convert governance standards into implementation plans at the OpCo level.

• Facilitate the Architecture Review Board process for OT security capabilities, including micro-segmentation, remote access OT expansion, OT monitoring tools, and industrial firewall platforms.

• Assess technical designs prior to deployment and uphold architectural standards throughout the portfolio.

• Counsel OpCo CIOs, site IT leaders, and plant engineers regarding OT security architecture.

• Offer architectural consultation for high-risk sites and supervise the segmentation remediation program.

• Provide guidelines and standards that support the secure enablement of digital manufacturing.


⛳️ Requirements

• Profound expertise in OT/ICS network architecture, encompassing Purdue Model/ISA-95 zone segmentation, industrial DMZ design, OT protocol firewall policies (Modbus, Profinet, EtherNet/IP, OPC-UA, BACnet), and secure remote access architecture.

• Practical experience in designing and validating network segmentation within complex, multi-site OT environments, including PLCs, DCS, SCADA, BMS, HMI, and historian systems.

• Background in life sciences, pharmaceuticals, or similarly regulated manufacturing sectors.

• Strong knowledge of IEC 62443, NIST SP 800-82, CIS Controls for ICS, and CISA/NSA OT security guidelines.

• Proven experience applying OT cybersecurity standards within a federated, multi-OpCo enterprise.

• Familiarity with ZTNA and SASE architectures, including Zscaler or equivalent, in OT environments.

• Experience in integrating industrial remote access protocols, vendor management workflows, and identity governance.

• Over 12 years of experience in OT/ICS security, network architecture, or industrial cybersecurity.

• A minimum of 5 years in a principal architect, distinguished engineer, or similar senior individual-contributor role within a complex multi-site manufacturing environment.


🏝️ Benefits

• Opportunities for career development and internal hiring.

• A culture that fosters belonging.

• Approximately 10% regional and international travel.

People also viewed

GitLab16 hours ago

Staff Security Researcher

US flagUnited States, +2 more countriesFull-timeCybersecurity / Security Engineer$168k – $238k/year
ApplyView job
GitLab16 hours ago

Principal Security Researcher

US flagUnited States, +2 more countriesFull-timeCybersecurity / Security Engineer$203.2k – $275k/year
ApplyView job
Cisco16 hours ago

Software Security Lead

US flagNorth Carolina OnlyFull-timeCybersecurity / Security Engineer$151.6k – $222.4k/year
ApplyView job
Lovesac16 hours ago

Senior Engineer, Information Security Architect

US flagConnecticut OnlyFull-timeCybersecurity / Security Engineer$95k – $125k/year
ApplyView job
General Dynamics Information Technology23 hours ago

Cybersecurity Architect

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$149.5k – $184k/year
ApplyView job
PGTEK1 day ago

Senior Security Agent / AI Red Team Engineer

US flagVirginia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers