Principal Architect, Manufacturing Security
Bring more to life.
At Danaher , our work saves lives. And each of us plays a part. Fueled by our culture of continuous improvement, we turn ideas into impact – innovating at the speed of life.
Our 60,000+ associates work across the globe at more than 15 unique businesses within life sciences, diagnostics, and biotechnology.
Are you ready to accelerate your potential and make a real difference? At Danaher , you can build an incredible career at a leading science and technology company, where we’re committed to hiring and developing from within. You’ll thrive in a culture of belonging where you and your unique viewpoint matter.
Learn about the Danaher Business System which makes everything possible.
The Principal Architect,Manufacturing Security isresponsible for defining and owning Danaher 's enterprise OT security architecture across its global manufacturing, lab, and R&D portfolio. This role sets the technical direction for network segmentation, IT/OT boundary design, DMZ architecture, andsecureremote access across 15+ operating companies and 160+ sites worldwide. This position offers a rare opportunity to shape the cybersecurity posture of one of the most complex multi-OpCoindustrial environments in the global life sciences and diagnostics industry.
This position is part of theCorporate Information Security and will belocatedasRemote in Europe.
In this role, you will have the opportunity to:
-
Own and evolve the enterprise OT security architecture blueprint for Danaher 's global manufacturing portfolio — including network segmentation standards, tiered security zone frameworks (ISA-95/Purdue), IT/OT boundary controls, DMZ patterns, and BMS isolation strategy across 15+ operating companies
-
Lead the design and portfolio-wide adoption of secure remote access architecture aligned to theremote accessplatform — retiring legacy VPN and direct-vendor connections, and extending zero-trust network access to OT OEMs, contractors, and remote support vendors across all operating companies
-
Partner with the Manufacturing Security Lead andinformation securityleadership to develop OT cybersecurity policies, architecture governance standards, and control frameworks that translate intoOpCo-level implementation plans — ensuring consistency acrosscriticalsitesand the broader portfolio
-
Drive the Architecture Review Board (ARB) process for OT security capabilities including micro-segmentation,Remote AccessOT extension, OT monitoring tools, and industrialfirewallplatforms —validatingtechnical designs before deployment and enforcing architectural standards across the portfolio
-
Provide expert OT security advisory toOpCoCIOs, site IT leads, and plant engineers — including architecture consultation for high-risksites andarchitectural oversight for the segmentation remediation program
-
Provide guidelines and standards to align to good securitycontrols inthe enablement of digital manufacturing to
The essential requirements of the job include:
-
Deepexpertisein OT/ICS network architecture including Purdue Model/ISA-95 zone segmentation, industrial DMZ design,firewallpolicy for OT protocols (Modbus,Profinet,EtherNet/IP, OPC-UA, BACnet), and secure remote access architecture for multi-site manufacturing environments
-
Hands-on experience designing and validating network segmentation implementations across complex, multi-site OT environments — including PLCs, DCS, SCADA, BMS, HMI, and historian systems — in life sciences, pharmaceutical, or similarly regulated manufacturing
-
Strong command of OT-specific cybersecurity frameworks including IEC 62443, NIST SP 800-82, CIS Controls for ICS, and CISA/NSA OT security guidance — withdemonstratedexperience applying these standards in a federated, multi-OpCoenterprise
-
Demonstrated experience with zero-trust network access (ZTNA) and SASE architectures (Zscaler or equivalent) in OT environments, including integration with industrial remote access pro