Staff Senior Systems Engineer, OT

Lilasciences

Cambridge

On-site

GBP 110,000 - 190,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Equity (early-stage)

Job summary

Lila Sciences is seeking a Staff Senior Systems Engineer, OT to design, build, commission, and maintain the compute, storage, network, and virtualization infrastructure that underpins Lila’s OT environment across instruments, automation platforms, lab compute, and building automation systems. You will own hands‑on systems engineering for OT and Lab IT infrastructure in a senior role.

The position reports to the Senior Director, OT Operations & Security, and involves working with OT security

Qualifications

  • Significant hands-on experience designing, deploying, commissioning, and operating enterprise compute, storage, and network infrastructure — in OT, laboratory, industrial control systems, manufacturing, infrastructure, or similarly operationally constrained environments.
  • Hands-on virtualization experience — design, deploy, and operate. Proxmox VE is our platform; deep VMware vSphere or Hyper-V experience transfers.
  • Deep systems administration across Windows Server and Windows client, and Linux where applicable: Active Directory, Group Policy, DNS, DHCP, and failover clustering.
  • Strong networking and segmentation fundamentals: VLANs, firewall policy, TCP/IP, routing, DNS, DHCP, and packet analysis, plus a working understanding of how on‑premises infrastructure connects to cloud.
  • Experience taking infrastructure from procurement and design through cutover and stabilization — commissioning systems end to end, not just configuring them in isolation.
  • Infrastructure‑as‑code and scripting experience (Terraform, PowerShell, Python, APIs), and the instinct to automate a task rather than repeat it.
  • Experience designing and operating backup, disaster recovery, and business continuity solutions where local survivability, not cloud failover, is the requirement.
  • Comfort working in a brownfield estate — inherited vendor layouts, fixed mechanical constraints, equipment that cannot be replaced on your schedule — and the ability to execute against an architecture you did not author, with the judgment and candor to raise it when the floor contradicts the design.
  • Strong written and verbal communication skills, including the ability to explain technical decisions to engineers, scientists, security leaders, and executives, and to write documentation others can follow without you in the room.
  • Willingness to work on-site at Lila laboratory locations on a regular basis, with periodic travel to other Lila sites including international locations, and participation in on‑call rotation and scheduled maintenance or incident response coverage

Responsibilities

  • Design, administer, commission, and maintain on-premises compute, storage, and network infrastructure supporting OT and Lab IT — from instrument-attached PCs and edge compute to lab orchestration servers and lab-area network gear across multiple sites.
  • Build and operate virtualized environments (Proxmox VE today; VMware vSphere and Hyper‑V experience transfers), including host provisioning, resource allocation, high availability, clustering, patching, and lifecycle management.
  • Implement and validate OT network configurations — VLANs, routing, firewall policy, and zone‑and‑conduit segmentation aligned to IEC 62443 — within the established addressing standard and topology, and understand how on‑premises OT connects to SD‑WAN and cloud services without exposing scientific IP.
  • Own commissioning and technical sign‑off for new automation platforms, instrument deployments, and lab buildouts: rack‑and‑stack, network cutover, golden‑image and SKU standardization, validation, and post‑cutover stabilization.
  • Operate and extend a signed, Git‑backed provisioning model with hardware‑rooted host identity, and build the infrastructure‑as‑code and automation (Terraform, PowerShell, Python, APIs) that makes provisioning, configuration, and lifecycle management repeatable and auditable.
  • Maintain the instrument host golden image stance on Windows IoT Enterprise LTSC across defined build classes, including application allowlisting, kernel‑mode code integrity and Secure Boot posture.
  • Administer core infrastructure services for OT and Lab IT — Active Directory, Group Policy, DNS, DHCP, failover clustering, and certificate and machine identity — and own IP address management and addressing standards.
  • Design and operate backup, disaster recovery, and business continuity for OT‑critical systems, balancing on‑premises image backups, device configuration backups, a self‑hosted Git forge, and tiered storage.
  • Lead patch strategy, vulnerability remediation, and lifecycle and end‑of‑life planning within OT change‑control windows, with vendor attestations and long lead times as constraints.
  • Partner with OT security engineering on segmentation enforcement, machine identity, secure vendor and remote access, and monitoring and sensor coverage.
  • Serve as the senior technical escalation point for complex compute, storage, network, and virtualization issues across the lab perimeter with root cause analysis.

Skills

Proxmox VE
VMware vSphere
Hyper-V
Windows Server
Linux
Networking fundamentals
Automation scripting
Terraform
PowerShell
Python
Git

Tools

Proxmox VE
VMware vSphere
Hyper-V
Terraform
PowerShell
Python
Git

Job description

Your Impact at LILA

Lila Sciences is seeking a Staff Senior Systems Engineer, OT to design, build, commission, and maintain the compute, storage, network, and virtualization infrastructure that underpins Lila’s Operational Technologyenvironment across instruments, automation platforms, lab compute, and building automation systems. Thisrole owns hands-on systems engineering for OT and Lab IT infrastructure and turns OT network and IT/OTconvergence architecture into commissioned, reliable, secure systems that scientists and automation depend onevery day.

This is a senior individual contributor role reporting to the Senior Director, OT Operations & Security, working inclose partnership with OT security architecture, corporate IT, controls and automation, the SOC, and laboratoryoperations leadership. Architectural intent — network topology, segmentation and conduit boundaries, storagetiering, host build standards — is set collaboratively; this role owns taking that intent from design intocommissioned, validated, documented systems and keeping them running. The right person operates with highautonomy inside an established architecture, sets technical direction for implementation patterns, engineeringstandards, and operational practice, and serves as the senior technical authority for how OT infrastructure isbuilt, commissioned, and maintained across Lila’s OT estate.

This is a foundational hire for Lila’s OT program. Lila is building autonomous laboratories where reliability andsecurity are designed into laboratory platforms before they ship, and our governing survivability standard issimple: if the WAN drops for 72 hours, science continues — on-premises first, locally survivable, with cloud as anextension rather than a dependency. The work spans new buildouts and standardization across active lab sites,so bringing existing environments up to a common standard is as much of this role as building what comes next.

What You'll Be Building
  • Design, administer, commission, and maintain on-premises compute, storage, and network infrastructure supporting OT and Lab IT — from instrument-attached PCs and edge compute to lab orchestration serversand lab-area network gear across multiple sites.
  • Build and operate virtualized environments (Proxmox VE today; VMware vSphere and Hyper‑V experience transfers), including host provisioning, resource allocation, high availability, clustering, patching, and lifecycle management.
  • Implement and validate OT network configurations — VLANs, routing, firewall policy, and zone-and‑conduit segmentation aligned to IEC 62443 — within the established addressing standard and topology, andunderstand how on‑premises OT connects to SD‑WAN and cloud services without exposing scientific IP.
  • Own commissioning and technical sign‑off for new automation platforms, instrument deployments, and labbuildouts: rack‑and‑stack, network cutover, golden‑image and SKU standardization, validation, and post‑cutover stabilization. Instruments integrate through serial‑to‑Ethernet and USB‑to‑Ethernet device serversrather than direct host passthrough, keeping virtual machines host‑agnostic and migration‑viable.
  • Operate and extend a signed, Git‑backed provisioning model with hardware‑rooted host identity, and buildthe infrastructure‑as‑code and automation (Terraform, PowerShell, Python, APIs) that makes provisioning,configuration, and lifecycle management repeatable and auditable.
  • Maintain the instrument host golden image standard on Windows IoT Enterprise LTSC across defined buildclasses, including application allowlisting, kernel‑mode code integrity and Secure Boot posture, anddocumented exceptions where vendor software constrains standard hardening.
  • Administer core infrastructure services for OT and Lab IT — Active Directory, Group Policy, DNS, DHCP,failover clustering, and certificate and machine identity — and own IP address management and addressingstandards for the OT estate as it scales.
  • Design and operate backup, disaster recovery, and business continuity for OT‑critical systems, holding the distinction between layers: image‑level backup on dedicated hardware in its own fault domain, pull‑baseddevice configuration backup for OT endpoints, a self‑hosted Git forge as source of record, and tieredstorage from hot NVMe through NAS file services to object‑based cold archive.
  • Deploy, tune, and operate OT visibility and asset platforms, and maintain asset inventory as the system ofrecord for the OT estate — sensor coverage, enrichment, inventory hygiene, and the tooling that keeps itaccurate.
  • Lead patch strategy, vulnerability remediation, and lifecycle and end‑of‑life planning within OT change‑control windows, and specify and source hardware under real constraints: TAA compliance with noadversary‑nation ownership or origin is a hard requirement, written vendor attestation is required perquote, and enterprise lead times are a planning input.
  • Partner with OT security engineering on segmentation enforcement, machine identity, secure vendor andremote access, and monitoring and sensor coverage.
  • Serve as the senior technical escalation point for complex compute, storage, network, and virtualizationissues across the lab perimeter, including root‑cause and problem management, within the defined IT/OTservice ownership boundary.
  • Produce runbooks, engineering standards, SOPs, and as‑built documentation as engineering deliverablesothers execute from; direct and review contracted engineering and managed‑service partners under Lilachange control; and mentor engineers as the OT function scales.
What You'll Need to Succeed
  • Significant hands‑on experience designing, deploying, commissioning, and operating enterprise compute,storage, and network infrastructure — in OT, laboratory, industrial control systems, manufacturing,infrastructure, or similarly operationally constrained environments.
  • Hands‑on virtualization experience — design, deploy, and operate. Proxmox VE is our platform; deepVMware vSphere or Hyper‑V experience transfers well.
  • Deep systems administration across Windows Server and Windows client, and Linux where applicable: Active Directory, Group Policy, DNS, DHCP, and failover clustering.
  • Strong networking and segmentation fundamentals: VLANs, firewall policy, TCP/IP, routing, DNS, DHCP, and packet analysis, plus a working understanding of how on‑premises infrastructure connects to cloud.
  • Experience taking infrastructure from procurement and design through cutover and stabilization — commissioning systems end to end, not just configuring them in isolation.
  • Infrastructure‑as‑code and scripting experience (Terraform, PowerShell, Python, APIs), and the instinct toautomate a task rather than repeat it.
  • Experience designing and operating backup, disaster recovery, and business continuity solutions wherelocal survivability, not cloud failover, is the requirement.
  • Comfort working in a brownfield estate — inherited vendor layouts, fixed mechanical constraints,equipment that cannot be replaced on your schedule — and the ability to execute against an architectureyou did not author, with the judgment and candor to raise it when the floor contradicts the design.
  • Strong written and verbal communication skills, including the ability to explain technical decisions to engineers, scientists, security leaders, and executives, and to write documentation others can followwithout you in the room.
  • Willingness to work on‑site at Lila laboratory locations on a regular basis, with periodic travel to other Lilasites including international locations, and participation in on‑call rotation and scheduled maintenance orincident response coverage
Bonus Points For
  • Experience in life sciences, biotechnology, pharmaceutical, laboratory automation, manufacturing, or high‑throughput research environments.
  • Familiarity with IEC 62443, NIST SP 800‑82, NIST CSF, GxP, 21 CFR Part 11, ISO 9001, or comparable qualityand security frameworks.
  • Production experience with Windows IoT Enterprise LTSC, WDAC or AppLocker allowlisting, or Secure Bootand HVCI on constrained instrument hosts.
  • Experience with OT visibility and asset platforms such as Claroty, Tenable OT, Dragos, or Nozomi Networks.
  • Experience with Proxmox VE and Proxmox Backup Server, ZFS or TrueNAS, enterprise storage (SAN/NAS),hyperconverged infrastructure, or S3‑compatible object storage.
  • Experience with enterprise campus switching (Juniper, Cisco, or comparable), enterprise firewalls (Palo Altoor comparable), and SD‑WAN or SASE platforms.
  • Cloud infrastructure experience (Azure, AWS, or GCP) and hybrid on‑prem‑to‑cloud connectivity patterns.
  • Experience with PKI, certificate lifecycle management, TLS/mTLS, TPM‑bound credentials, or modernmachine‑identity patterns.
  • Experience with device configuration backup tooling (Octoplant or comparable), self‑hosted Git forges,IPAM (NetBox or comparable), or ITSM platforms (Freshservice or comparable).
  • Relevant certifications such as Microsoft (Windows Server Hybrid Administrator, MCSE), VMware VCP,HashiCorp Terraform Associate, Azure or AWS, Cisco (CCNP), Juniper, GICSP, IEC 62443 CybersecurityExpert, or CISSP
Compensation

We offer competitive base compensation with bonus potential and generous early‑stage equity. Your final offer will reflect your background, expertise, and expected impact.

U.S. Benefits.

Full‑time U.S. employees receive a comprehensive benefits program including medical, dental, and vision coverage; employer‑paid life and disability insurance; flexible time off with generous company wide holidays; paid parental leave; an educational assistance program; commuter benefits, including bike share memberships for office based employees; and a company subsidized lunch program.

International Benefits.

Full‑time employees outside the U.S. receive a comprehensive benefits program tailored to their region. USD salary ranges apply only to U.S.-based positions; international salaries are set to local market.

Expected Base Salary Range

$163,400 — $217,866 USD

About LILA

Lila Sciences is building Scientific Superintelligence to solve humankind's greatest challenges. We believe science is the most inspiring frontier for AI. Rather than hard‑coding expert knowledge into tools, LILA builds systems that can learn for themselves.

LILA combines advanced AI models with proprietary AI Science Factory instruments into an operating system for science that executes the entire scientific method autonomously, accelerating discovery at unprecedented speed, scale, and impact across medicine, materials, and energy. Learn more at www.lila.ai.

Guided by our core values of truth, trust, curiosity, grit, and velocity, we move with startup speed while tackling problems of historic importance. If this sounds like an environment you'd love to work in, even if you don't meet every qualification listed above, we encourage you to apply.

We’re All In

Lila Sciences iscommitted to equal employment opportunityregardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status.

Information you provide during your application process will be handled in accordance with our Candidate Privacy Policy.

A Note to Agencies

Lila Sciences does not accept unsolicited resumes from any source other than candidates. The submission of unsolicited resumes by recruitment or staffing agencies to Lila Sciences or its employees is strictly prohibited unless contacted directly by Lila Science’s internal Talent Acquisition team. Any resume submitted by an agency in the absence of a signed agreement will automatically become the property of Lila Sciences, and Lila Sciences will not owe any referral or other fees with respect thereto.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Associate Director, App
Associate Director, App

Lilasciences • Cambridge

On-site
GBP 151,000 - 226,000
Data Scientist II / Senior Data Scientist, Life Sciences
Data Scientist II / Senior Data Scientist, Life Sciences

Lilasciences • Cambridge

On-site
GBP 104,000 - 161,000
Competitive base salary with equity
Equity compensation
Comprehensive benefits
Operations and Quality Engineer, Sustaining Engineering
Operations and Quality Engineer, Sustaining Engineering

Lilasciences • Cambridge

On-site
GBP 70,000 - 118,000
Bonus potential
Equity
Sr Principal/ Principal Software Engineer, AI Lab Execution System
Sr Principal/ Principal Software Engineer, AI Lab Execution System

Lilasciences • Cambridge

Hybrid
GBP 152,798 - 260,655
Competitive base compensation
Bonus potential
Generous early-stage equity
Scientist II/Senior Scientist, Computational Biophysics
Scientist II/Senior Scientist, Computational Biophysics

Lilasciences • Greater London

On-site
GBP 105,000 - 162,000
Equity
Comprehensive benefits
Generous holidays and leave
Senior Product Designer II / Staff Product Designer
Senior Product Designer II / Staff Product Designer

lilasciences • Cambridge

On-site
GBP 133,000 - 190,000
Senior Manager, Scientific Discovery Capacity Planning
Senior Manager, Scientific Discovery Capacity Planning

Lilasciences • Cambridge

Hybrid
GBP 77,000 - 129,000
Medical, dental, and vision coverage
Life and disability insurance
Flexible time off and holidays
Robotics Operations Engineer I, First Shift
Robotics Operations Engineer I, First Shift

Lilasciences • Cambridge

On-site
GBP 56,000 - 81,000
Equity
Staff IT Systems Engineer, Identity
Staff IT Systems Engineer, Identity

Lilasciences • Cambridge

On-site
GBP 122,000 - 149,000
Microfabrication Scientist I/II
Microfabrication Scientist I/II

Lilasciences • Cambridge

On-site
GBP 80,000 - 127,000
Equity
Bonus potential
Educational assistance
+2