Associate Systems Engineer Lab Systems & OT Security

Talent Software Services, Inc.

  • San Diego, CA
  • 8 days ago
  • $50–$51 Per Hour

Highlights

Focus: Laboratory Systems, OT Security, Endpoint Security, Active Directory, Vulnerability Management, and IT Service Management. Support the security and modernization of laboratory and Operational Technology (OT) environments across global sites.

Numbers & Facts

LocationSan Diego, CA
Salary$50–$51 Per Hour

Description

Job Overview

  • Location: San Diego, CA
  • Duration: 6 months
  • GBaMS ReqID: 10949088
  • Role: Associate Systems Engineer – Lab Systems & OT Security
  • Experience Required: 4–6 years preferred
  • Education: Bachelor’s degree in Computer Science, IT, Cybersecurity, or related field, or equivalent experience
  • Focus: Laboratory Systems, OT Security, Endpoint Security, Active Directory, Vulnerability Management, and IT Service Management

Role Summary

  • Support the security and modernization of laboratory and Operational Technology (OT) environments across global sites.
  • Work within the Lab Solutions team on active security initiatives.
  • Execute security workstreams including:
    • Non-Attributable Account (NAA) remediation
    • Software download restrictions
    • Vulnerability remediation
    • USB/data transfer controls
    • Endpoint security improvements
  • Help align lab OT security posture with enterprise security standards.
  • Work across both IT and OT environments.
  • Collaborate with:
    • Business System Owners
    • Lab scientists
    • Vendors
    • InfoSec teams
    • Active Directory teams
    • Global site partners

Key Responsibilities

1. NAA / Non-Attributable Account Remediation

  • Support design, testing, and execution of the NAA remediation program.
  • Work with both:
    • RC4-dependent accounts
    • Non-RC4-dependent accounts
  • Build and maintain Active Directory host allow/deny lists within the Lab OU.
  • Coordinate with InfoSec and AD teams on password reset activities.
  • Validate remediation results during pilot and full rollout phases.
  • Work with Business System Owners and lab staff to:
    • Identify NAA usage
    • Understand active engagements
    • Transition shared accounts to properly managed service accounts
  • Support deployment/configuration of:
    • Transparent Screen Lock (TSL)
    • BeyondTrust
  • Replace NAA-dependent workflows with secure authentication and privileged-access solutions.

2. Software Governance & Controls

  • Help define and implement software allowlisting policies.
  • Apply policies to:
    • Lab workstations
    • Instrument PCs
    • Lab OU endpoints
  • Identify unauthorized, unlicensed, or non-approved software.
  • Support remediation planning for non-compliant software.
  • Develop and maintain a formal software exception process.
  • Support legitimate scientific software deployment requirements.

3. Vulnerability Management

  • Support CrowdStrike Falcon/EDR sensor deployment.
  • Identify and close endpoint security gaps.
  • Coordinate remediation activities with InfoSec and site teams.
  • Identify and remediate insecure or improperly configured file shares.
  • Reduce risks related to:
    • Lateral movement
    • Data exfiltration
    • Unauthorized access
  • Support OS patching and compliance tracking.
  • Identify End-of-Life (EOL) operating systems.
  • Develop remediation or isolation strategies for legacy systems.
  • Assist with server vulnerability triage and remediation.

4. USB & Data Transfer Controls

  • Assess USB usage across laboratory sites.
  • Understand USB requirements for scientific instruments and workflows.
  • Help implement a tiered USB security policy:
    • Block
    • Monitor
    • Allow by exception
  • Balance security requirements with legitimate laboratory workflows.
  • Manage USB exception requests, particularly for vendor-supported activities.

5. Cross-Site & Operational Support

  • Provide hands-on technical support to global lab locations.
  • Support sites including:
    • Boston / US East Coast
    • Oxford / UK
    • Other global laboratory locations
  • Maintain documentation for:
    • System configurations
    • AD allow/deny lists
    • Service accounts
    • Security workstreams
    • Remediation progress
  • Support ServiceNow demand intake and request management.
  • Manage requests related to:
    • Service accounts
    • Access
    • Security remediation
  • Participate in post-change hypercare.
  • Troubleshoot connectivity and authentication issues following major changes.
  • Communicate technical information effectively to both technical and non-technical stakeholders.

Required Qualifications

Education

  • Bachelor’s degree in:
    • Computer Science
    • Information Technology
    • Cybersecurity
    • Related technical field
  • Equivalent professional experience may be considered.

Professional Experience

  • 2–5+ years of relevant experience, with 4–6 years preferred.
  • Experience in:
    • IT/OT systems engineering
    • Endpoint security
    • Lab systems support
    • Infrastructure/security engineering
  • Hands-on Active Directory administration experience.
  • Experience with:
    • Organizational Units (OUs)
    • Group Policy Objects (GPOs)
    • User accounts
    • Service accounts
    • Authentication
  • Experience supporting:
    • Laboratory environments
    • Manufacturing environments
    • Operational Technology environments
  • Experience executing security remediation activities such as:
    • OS patching
    • Endpoint agent deployment
    • Access control changes
    • Vulnerability remediation
  • Experience with endpoint security/EDR platforms.
  • CrowdStrike experience preferred.
  • Experience or familiarity with BeyondTrust or similar PAM/password management solutions.
  • Familiarity with Endpoint Management (EPM) tools.

Technical Skills

Active Directory / IAM

  • Active Directory administration
  • OU structure and management
  • Group Policy / GPO
  • User and service account management
  • Service account lifecycle management
  • Privileged access management
  • Authentication protocols:
    • RC4
    • NTLM
    • Kerberos
  • AD allow/deny list enforcement
  • Enterprise Identity Management
  • SailPoint familiarity

Endpoint & OT Security

  • CrowdStrike Falcon / EDR
  • Endpoint security
  • OT security
  • Lab network security
  • Windows endpoint security
  • USB restriction policies
  • Software allowlisting
  • Vulnerability management
  • OS patching
  • EOL operating system remediation
  • File share security
  • Network exposure and segmentation
  • Network-level security controls

Lab / Instrument Environment

  • Understanding of laboratory instrument environments.
  • Knowledge of how lab instruments authenticate to networks.
  • Understanding of shared-account dependencies for scientific instruments.
  • Transparent Screen Lock (TSL) or similar technologies.
  • Familiarity with:
    • NuGenesis / SDMS
    • Waters Empower
    • Chromatography systems
    • Scientific data platforms
  • Awareness of biopharmaceutical laboratory environments.
  • Awareness of GxP and Information Security requirements.

Tools & Platforms

  • Active Directory
  • Microsoft Windows 10/11
  • Windows Server
  • Group Policy
  • CrowdStrike Falcon
  • BeyondTrust
  • ServiceNow
  • SailPoint
  • Endpoint Management tools
  • Network monitoring tools
  • Log analysis tools
  • PowerShell

IT Service Management

  • Understanding of ITIL / ITSM principles.
  • Experience with ServiceNow or equivalent ITSM platforms.
  • Experience managing:
    • Tickets
    • Demand intake
    • Access requests
    • Service account requests
    • Change activities
    • Incident/hypercare support

Soft Skills

  • Strong analytical and problem-solving skills.
  • High attention to detail.
  • Comfortable working with large datasets such as:
    • Login logs
    • AD exports
    • Host inventories
    • Endpoint data
  • Strong written and verbal communication.
  • Ability to explain technical concepts to lab scientists and business stakeholders.
  • Highly organized and execution-oriented.
  • Ability to manage multiple concurrent workstreams.
  • Comfortable working in ambiguous and fast-changing environments.
  • Strong collaboration and stakeholder-management skills.
  • Service-oriented approach to supporting laboratory operations.

Global / Operational Requirements

  • Ability to work with global laboratory organizations.
  • Ability to collaborate across US and UK sites.
  • Comfortable working with distributed teams and stakeholders.
  • Willingness to participate in hypercare periods.
  • Ability to provide out-of-hours support during major security/change activations when required.
  • Ability to build trust with:
    • Lab scientists
    • Business System Owners
    • Vendors
    • Technical teams
    • Senior leadership

Preferred / Desirable Skills

  • IT Service Management Consulting
  • 4–6 years of relevant experience
  • Active Directory
  • Group Policy
  • Service account management
  • CrowdStrike
  • BeyondTrust
  • SailPoint
  • PowerShell
  • ServiceNow
  • Endpoint Management
  • OT Security
  • Lab Systems
  • Vulnerability Management
  • USB Security
  • Software Allowlisting
  • GxP / regulated environments
  • Biopharma laboratory experience
  • NuGenesis / SDMS
  • Waters Empower
  • Transparent Screen Lock (TSL)

Key Keywords for Resume / ATS

  • Active Directory
  • AD Administration
  • Organizational Units (OU)
  • Group Policy (GPO)
  • Service Accounts
  • Privileged Access Management
  • PAM
  • RC4
  • NTLM
  • Kerberos
  • CrowdStrike Falcon
  • EDR
  • Endpoint Security
  • OT Security
  • Lab Systems
  • Laboratory IT
  • Instrument PCs
  • Vulnerability Management
  • OS Patching
  • EOL Remediation
  • File Share Remediation
  • USB Security
  • USB Restrictions
  • Software Allowlisting
  • BeyondTrust
  • SailPoint
  • ServiceNow
  • ITIL
  • ITSM
  • PowerShell
  • Windows 10/11
  • Windows Server
  • Network Segmentation
  • Network Monitoring
  • Log Analysis
  • Transparent Screen Lock
  • NuGenesis
  • Waters Empower
  • GxP
  • Biopharma
  • Information Security
  • Security Remediation
  • IT Service Management Consulting

Similar Jobs

See more jobs