Role Overview:The role is for an Associate Systems Engineer - Lab Systems & OT Security, focused on supporting the security and modernization of laboratory and operational technology (OT) environments across global sites. This highly technical, execution-focused position involves working within the Lab Solutions team to manage active security workstreams, including Non-Attributable Account (NAA) remediation, software download restrictions, vulnerability remediation, and USB data transfer controls. The goal is to align lab OT posture with enterprise security standards, offering direct exposure to senior leadership and contributing significantly to strengthening lab and OT security capabilities at scale.
Key Responsibilities:- Support the design, testing, and execution of the Non-Attributable Account (NAA) remediation program.
- Assist in building, maintaining, and activating host allow/deny lists within the Lab Organizational Unit (OU) in Active Directory.
- Coordinate with InfoSec and AD teams to execute password reset mechanisms and validate outcomes.
- Assist in defining and implementing a policy-based software allowlist across lab workstations and instrument PCs.
- Identify currently installed unauthorized or unlicensed software and support remediation planning.
- Support CrowdStrike EDR sensor deployment and gap closure across lab endpoints.
- Contribute to OS patching cadence and compliance tracking for lab workstations and instrument PCs.
- Assess current USB usage patterns and assist in defining and implementing a tiered USB restriction policy.
- Serve as a hands-on technical resource for site partners across global lab locations.
- Maintain accurate documentation of system configurations, allow/deny lists, and service account inventories.
- Contribute to demand intake and ServiceNow-based request management.
Required Skills:- Proficiency in Active Directory administration: OU structure, Group Policy Objects (GPOs), user/service account management, and authentication protocols including RC4/NTLM/Kerberos.
- Understanding of allow/deny list enforcement mechanisms within AD and Lab OU environments.
- Experience with service account lifecycle management and privileged access controls.
- Working knowledge of endpoint detection and response (EDR) platforms, particularly CrowdStrike Falcon.
- Understanding of OT/lab network architecture, including isolated or semi-isolated lab network segments.
- Familiarity with USB restriction and software control policies on Windows endpoints.
- Knowledge of vulnerability management concepts: OS patching, EOL systems, open file shares.
- Familiarity with Transparent Screen Lock (TSL) or similar technologies for instrument session management.
- Proficiency in PowerShell preferred.
- Strong analytical skills and attention to detail.
- Clear written and verbal communication skills.
- Organized and execution-oriented, comfortable operating in a fast-moving, ambiguous environment.
- Collaborative and service-minded.
Qualifications:- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent experience).
- 2-5 years of relevant experience in IT/OT systems engineering, endpoint security, or lab systems support.
- Hands-on experience with Active Directory administration, including Organizational Unit (OU) management, Group Policy, and service account provisioning.
- Experience working in or supporting laboratory, manufacturing, or operational technology environments.
- Demonstrated experience executing security remediation activities such as patching, endpoint agent deployment, or access control changes.
- Experience working with endpoint security platforms (CrowdStrike or equivalent EDR tools preferred).
- Familiarity with privileged access management or password vault tools (BeyondTrust or equivalent).
- Familiarity with Endpoint Management (EPM) tools for computer fleet management.
Preferred Skills:- Understanding of enterprise Identity Management tools (Sailpoint).
- Awareness of lab data systems such as NuGenesis (SDMS), Empower (Waters), or similar scientific data platforms.
- Awareness of working in Biopharma Laboratory Environments.
- Awareness of GxP and Information Security compliance constraints.
- Familiarity with ITIL ITSM principles.
- Experience operating within or alongside regulated environments (life sciences, pharmaceutical, or similar).