Focus: Laboratory Systems, OT Security, Endpoint Security, Active Directory, Vulnerability Management, and IT Service Management. Support the security and modernization of laboratory and Operational Technology (OT) environments across global sites.
Numbers & Facts
Location
San Diego, CA
Salary
$50–$51 Per Hour
Description
Job Overview
Location: San Diego, CA
Duration: 6 months
GBaMS ReqID: 10949088
Role: Associate Systems Engineer – Lab Systems & OT Security
Experience Required: 4–6 years preferred
Education: Bachelor’s degree in Computer Science, IT, Cybersecurity, or related field, or equivalent experience
Focus: Laboratory Systems, OT Security, Endpoint Security, Active Directory, Vulnerability Management, and IT Service Management
Role Summary
Support the security and modernization of laboratory and Operational Technology (OT) environments across global sites.
Work within the Lab Solutions team on active security initiatives.
Execute security workstreams including:
Non-Attributable Account (NAA) remediation
Software download restrictions
Vulnerability remediation
USB/data transfer controls
Endpoint security improvements
Help align lab OT security posture with enterprise security standards.
Work across both IT and OT environments.
Collaborate with:
Business System Owners
Lab scientists
Vendors
InfoSec teams
Active Directory teams
Global site partners
Key Responsibilities
1. NAA / Non-Attributable Account Remediation
Support design, testing, and execution of the NAA remediation program.
Work with both:
RC4-dependent accounts
Non-RC4-dependent accounts
Build and maintain Active Directory host allow/deny lists within the Lab OU.
Coordinate with InfoSec and AD teams on password reset activities.
Validate remediation results during pilot and full rollout phases.
Work with Business System Owners and lab staff to:
Identify NAA usage
Understand active engagements
Transition shared accounts to properly managed service accounts
Support deployment/configuration of:
Transparent Screen Lock (TSL)
BeyondTrust
Replace NAA-dependent workflows with secure authentication and privileged-access solutions.
2. Software Governance & Controls
Help define and implement software allowlisting policies.
Apply policies to:
Lab workstations
Instrument PCs
Lab OU endpoints
Identify unauthorized, unlicensed, or non-approved software.
Support remediation planning for non-compliant software.
Develop and maintain a formal software exception process.
Support legitimate scientific software deployment requirements.
3. Vulnerability Management
Support CrowdStrike Falcon/EDR sensor deployment.
Identify and close endpoint security gaps.
Coordinate remediation activities with InfoSec and site teams.
Identify and remediate insecure or improperly configured file shares.
Reduce risks related to:
Lateral movement
Data exfiltration
Unauthorized access
Support OS patching and compliance tracking.
Identify End-of-Life (EOL) operating systems.
Develop remediation or isolation strategies for legacy systems.
Assist with server vulnerability triage and remediation.
4. USB & Data Transfer Controls
Assess USB usage across laboratory sites.
Understand USB requirements for scientific instruments and workflows.
Help implement a tiered USB security policy:
Block
Monitor
Allow by exception
Balance security requirements with legitimate laboratory workflows.
Manage USB exception requests, particularly for vendor-supported activities.
5. Cross-Site & Operational Support
Provide hands-on technical support to global lab locations.
Support sites including:
Boston / US East Coast
Oxford / UK
Other global laboratory locations
Maintain documentation for:
System configurations
AD allow/deny lists
Service accounts
Security workstreams
Remediation progress
Support ServiceNow demand intake and request management.
Manage requests related to:
Service accounts
Access
Security remediation
Participate in post-change hypercare.
Troubleshoot connectivity and authentication issues following major changes.
Communicate technical information effectively to both technical and non-technical stakeholders.
Required Qualifications
Education
Bachelor’s degree in:
Computer Science
Information Technology
Cybersecurity
Related technical field
Equivalent professional experience may be considered.
Professional Experience
2–5+ years of relevant experience, with 4–6 years preferred.
Experience in:
IT/OT systems engineering
Endpoint security
Lab systems support
Infrastructure/security engineering
Hands-on Active Directory administration experience.
Experience with:
Organizational Units (OUs)
Group Policy Objects (GPOs)
User accounts
Service accounts
Authentication
Experience supporting:
Laboratory environments
Manufacturing environments
Operational Technology environments
Experience executing security remediation activities such as:
OS patching
Endpoint agent deployment
Access control changes
Vulnerability remediation
Experience with endpoint security/EDR platforms.
CrowdStrike experience preferred.
Experience or familiarity with BeyondTrust or similar PAM/password management solutions.
Familiarity with Endpoint Management (EPM) tools.
Technical Skills
Active Directory / IAM
Active Directory administration
OU structure and management
Group Policy / GPO
User and service account management
Service account lifecycle management
Privileged access management
Authentication protocols:
RC4
NTLM
Kerberos
AD allow/deny list enforcement
Enterprise Identity Management
SailPoint familiarity
Endpoint & OT Security
CrowdStrike Falcon / EDR
Endpoint security
OT security
Lab network security
Windows endpoint security
USB restriction policies
Software allowlisting
Vulnerability management
OS patching
EOL operating system remediation
File share security
Network exposure and segmentation
Network-level security controls
Lab / Instrument Environment
Understanding of laboratory instrument environments.
Knowledge of how lab instruments authenticate to networks.
Understanding of shared-account dependencies for scientific instruments.
Transparent Screen Lock (TSL) or similar technologies.
Familiarity with:
NuGenesis / SDMS
Waters Empower
Chromatography systems
Scientific data platforms
Awareness of biopharmaceutical laboratory environments.
Awareness of GxP and Information Security requirements.
Tools & Platforms
Active Directory
Microsoft Windows 10/11
Windows Server
Group Policy
CrowdStrike Falcon
BeyondTrust
ServiceNow
SailPoint
Endpoint Management tools
Network monitoring tools
Log analysis tools
PowerShell
IT Service Management
Understanding of ITIL / ITSM principles.
Experience with ServiceNow or equivalent ITSM platforms.
Experience managing:
Tickets
Demand intake
Access requests
Service account requests
Change activities
Incident/hypercare support
Soft Skills
Strong analytical and problem-solving skills.
High attention to detail.
Comfortable working with large datasets such as:
Login logs
AD exports
Host inventories
Endpoint data
Strong written and verbal communication.
Ability to explain technical concepts to lab scientists and business stakeholders.
Highly organized and execution-oriented.
Ability to manage multiple concurrent workstreams.
Comfortable working in ambiguous and fast-changing environments.
Strong collaboration and stakeholder-management skills.
Service-oriented approach to supporting laboratory operations.
Global / Operational Requirements
Ability to work with global laboratory organizations.
Ability to collaborate across US and UK sites.
Comfortable working with distributed teams and stakeholders.
Willingness to participate in hypercare periods.
Ability to provide out-of-hours support during major security/change activations when required.