Staff Senior Systems Engineer, OT

Lila Sciences

Cambridge (MA)

On-site

USD 163,000 - 218,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision
Life and disability insurance
Flexible time off
Parental leave
Educational assistance
Commuter benefits
Lunch program

Job summary

Lila Sciences seeks a Staff Senior Systems Engineer, OT to design, build, and maintain OT and Lab IT infrastructure across multiple sites. You will own hands-on engineering, ensure secure, reliable operations, and collaborate with OT security, IT, and lab leadership.

Expect autonomous work within an established architecture, setting patterns, standards, and acting as the senior technical authority on OT systems, with on-site duties and periodic travel to other Lila sites.

Qualifications

  • Hands-on experience designing and operating enterprise compute, storage, and network infrastructure for OT or lab environments.
  • Experience deploying virtualization platforms and managing lifecycle, clustering, and high availability.
  • Strong Windows and Linux system administration with AD, DNS, DHCP, and group policy basics.
  • Automation and IaC experience with Terraform, PowerShell, Python, and APIs.

Responsibilities

  • Design, administer, commission, and maintain on-premises OT and Lab IT infrastructure across sites.
  • Own commissioning and sign-off for new automation platforms and lab buildouts.
  • Develop infrastructure-as-code and automation to ensure repeatable deployments.
  • Maintain backup, disaster recovery, and business continuity for OT systems.
  • Lead patching, vulnerability remediation, and lifecycle planning within change windows.
  • Mentor engineers and produce runbooks, SOPs, and documentation.

Skills

Proxmox VE
VMware vSphere
Hyper-V
Windows Server
Linux admin
Terraform
PowerShell
Python

Tools

Proxmox VE
VMware vSphere
Hyper-V
Terraform
PowerShell
Python

Job description

Your Impact at LILA

Lila Sciences is seeking a Staff Senior Systems Engineer, OT to design, build, commission, and maintain the compute, storage, network, and virtualization infrastructure that underpins Lila’s Operational Technology environment across instruments, automation platforms, lab compute, and building automation systems. This role owns hands‑on systems engineering for OT and Lab IT infrastructure and turns OT network and IT/OT convergence architecture into commissioned, reliable, secure systems that scientists and automation depend on every day.

This is a senior individual contributor role reporting to the Senior Director, OT Operations & Security, working in close partnership with OT security architecture, corporate IT, controls and automation, the SOC, and laboratory operations leadership. Architectural intent — network topology, segmentation and conduit boundaries, storage tiering, host build standards — is set collaboratively; this role owns taking that intent from design into commissioned, validated, documented systems and keeping them running. The right person operates with high autonomy inside an established architecture, sets technical direction for implementation patterns, engineering standards, and operational practice, and serves as the senior technical authority for how OT infrastructure is built, commissioned, and maintained across Lila’s OT estate.

This is a foundational hire for Lila’s OT program. Lila is building autonomous laboratories where reliability and security are designed into laboratory platforms before they ship, and our governing survivability standard is simple: if the WAN drops for 72 hours, science continues — on‑premises first, locally survivable, with cloud as an extension rather than a dependency. The work spans new buildouts and standardization across active lab sites, so bringing existing environments up to a common standard is as much of this role as building what comes next.

What You'll Be Building
  • Design, administer, commission, and maintain on‑premises compute, storage, and network infrastructure supporting OT and Lab IT — from instrument‑attached PCs and edge compute to lab orchestration servers and lab‑area network gear across multiple sites.
  • Build and operate virtualized environments (Proxmox VE today; VMware vSphere and Hyper‑V experience transfers), including host provisioning, resource allocation, high availability, clustering, patching, and lifecycle management.
  • Implement and validate OT network configurations — VLANs, routing, firewall policy, and zone‑and‑conduit segmentation aligned to IEC 62443 — within the established addressing standard and topology, and understand how on‑premises OT connects to SD‑WAN and cloud services without exposing scientific IP.
  • Own commissioning and technical sign‑off for new automation platforms, instrument deployments, and lab buildouts: rack‑and‑stack, network cutover, golden‑image and SKU standardization, validation, and post‑ cutover stabilization. Instruments integrate through serial‑to‑Ethernet and USB‑to‑Ethernet device servers rather than direct host passthrough, keeping virtual machines host‑agnostic and migration‑viable.
  • Operate and extend a signed, Git‑backed provisioning model with hardware‑rooted host identity, and build the infrastructure‑as‑code and automation (Terraform, PowerShell, Python, APIs) that makes provisioning,configuration, and lifecycle management repeatable and auditable.
  • Maintain the instrument host golden image standard on Windows IoT Enterprise LTSC across defined build classes, including application allowlisting, kernel‑mode code integrity and Secure Boot posture, and documented exceptions where vendor software constrains standard hardening.
  • Administer core infrastructure services for OT and Lab IT — Active Directory, Group Policy, DNS, DHCP, failover clustering, and certificate and machine identity — and own IP address management and addressing standards for the OT estate as it scales.
  • Design and operate backup, disaster recovery, and business continuity for OT‑critical systems, holding the distinction between layers: image‑level backup on dedicated hardware in its own fault domain, pull‑based device configuration backup for OT endpoints, a self‑hosted Git forge as source of record, and tiered storage from hot NVMe through NAS file services to object‑based cold archive.
  • Deploy, tune, and operate OT visibility and asset platforms, and maintain asset inventory as the system of record for the OT estate — sensor coverage, enrichment, inventory hygiene, and the tooling that keeps it accurate.
  • Lead patch strategy, vulnerability remediation, and lifecycle and end‑of‑life planning within OT change‑control windows, and specify and source hardware under real constraints: TAA compliance with no adversary‑nation ownership or origin is a hard requirement, written vendor attestation is required per quote, and enterprise lead times are a planning input.
  • Partner with OT security engineering on segmentation enforcement, machine identity, secure vendor and remote access, and monitoring and sensor coverage.
  • Serve as the senior technical escalation point for complex compute, storage, network, and virtualization issues across the lab perimeter, including root‑cause and problem management, within the defined IT/OT service ownership boundary.
  • Produce runbooks, engineering standards, SOPs, and as‑built documentation as engineering deliverables others execute from; direct and review contracted engineering and managed‑service partners under Lila change control; and mentor engineers as the OT function scales.
What You'll Need To Succeed
  • Significant hands‑on experience designing, deploying, commissioning, and operating enterprise compute, storage, and network infrastructure — in OT, laboratory, industrial control systems, manufacturing, infrastructure, or similarly operationally constrained environments.
  • Hands‑on virtualization experience — design, deploy, and operate. Proxmox VE is our platform; deep VMware vSphere or Hyper‑V experience transfers well.
  • Deep systems administration across Windows Server and Windows client, and Linux where applicable: Active Directory, Group Policy, DNS, DHCP, and failover clustering.
  • Strong networking and segmentation fundamentals: VLANs, firewall policy, TCP/IP, routing, DNS, DHCP, and packet analysis, plus a working understanding of how on‑premises infrastructure connects to cloud.
  • Experience taking infrastructure from procurement and design through cutover and stabilization — commissioning systems end to end, not just configuring them in isolation.
  • Infrastructure‑as‑code and scripting experience (Terraform, PowerShell, Python, APIs), and the instinct to automate a task rather than repeat it.
  • Experience designing and operating backup, disaster recovery, and business continuity solutions where local survivability, not cloud failover, is the requirement.
  • Comfort working in a brownfield estate — inherited vendor layouts, fixed mechanical constraints, equipment that cannot be replaced on your schedule — and the ability to execute against an architecture you did not author, with the judgment and candor to raise it when the floor contradicts the design.
  • Strong written and verbal communication skills, including the ability to explain technical decisions to engineers, scientists, security leaders, and executives, and to write documentation others can follow without you in the room.
  • Willingness to work on‑site at Lila laboratory locations on a regular basis, with periodic travel to other Lila sites including international locations, and participation in on‑call rotation and scheduled maintenance or incident response coverage.
Bonus Points For
  • Experience in life sciences, biotechnology, pharmaceutical, laboratory automation, manufacturing, or high‑throughput research environments.
  • Familiarity with IEC 62443, NIST SP 800‑82, NIST CSF, GxP, 21 CFR Part 11, ISO 9001, or comparable quality and security frameworks.
  • Production experience with Windows IoT Enterprise LTSC, WDAC or AppLocker allowlisting, or Secure Boot and HVCI on constrained instrument hosts.
  • Experience with OT visibility and asset platforms such as Claroty, Tenable OT, Dragos, or Nozomi Networks.
  • Experience with Proxmox VE and Proxmox Backup Server, ZFS or TrueNAS, enterprise storage (SAN/NAS), hyperconverged infrastructure, or S3‑compatible object storage.
  • Experience with enterprise campus switching (Juniper, Cisco, or comparable), enterprise firewalls (Palo Alto or comparable), and SD‑WAN or SASE platforms.
  • Cloud infrastructure experience (Azure, AWS, or GCP) and hybrid on‑prem‑to‑cloud connectivity patterns.
  • Experience with PKI, certificate lifecycle management, TLS/mTLS, TPM‑bound credentials, or modern machine‑identity patterns.
  • Experience with device configuration backup tooling (Octoplant or comparable), self‑hosted Git forges, IPAM (NetBox or comparable), or ITSM platforms (Freshservice or comparable).
  • Relevant certifications such as Microsoft (Windows Server Hybrid Administrator, MCSE), VMware VCP, HashiCorp Terraform Associate, Azure or AWS, Cisco (CCNP), Juniper, GICSP, IEC 62443 Cybersecurity Expert, or CISSP.

CompensationWe offer competitive base compensation with bonus potential and generous early‑stage equity. Your final offer will reflect your background, expertise, and expected impact.

U.S. Benefits
  • Full‑time U.S. employees receive a comprehensive benefits program including medical, dental, and vision coverage
  • employer‑paid life and disability insurance
  • flexible time off with generous company wide holidays
  • paid parental leave
  • an educational assistance program
  • commuter benefits, including bike share memberships for office based employees
  • and a company subsidized lunch program
International Benefits
  • Full‑time employees outside the U.S. receive a comprehensive benefits program tailored to their region

Expected Base Salary Range: $163,400 USD - $217,866 USD

USD salary ranges apply only to U.S.-based positions; international salaries are set to local market.

About LILA

Lila Sciences is building Scientific Superintelligence™ to solve humankind's greatest challenges. We believe science is the most inspiring frontier for AI. Rather than hard‑coding expert knowledge into tools, LILA builds systems that can learn for themselves.

LILA combines advanced AI models with proprietary AI Science Factory™ instruments into an operating system for science that executes the entire scientific method autonomously, accelerating discovery at unprecedented speed, scale, and impact across medicine, materials, and energy. Learn more at www.lila.ai.

We’re All In

Lila Sciences is committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status.

Information you provide during your application process will be handled in accordance with our Candidate Privacy Policy.

A Note to Agencies

Lila Sciences does not accept unsolicited resumes from any source other than candidates. The submission of unsolicited resumes by recruitment or staffing agencies to Lila Sciences or its employees is strictly prohibited unless contacted directly by Lila Science’s internal Talent Acquisition team. Any resume submitted by an agency in the absence of a signed agreement will automatically become the property of Lila Sciences, and Lila Sciences will not owe any referral or other fees with respect thereto.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Software Engineer II, Enterprise Auth Platform
Senior Software Engineer II, Enterprise Auth Platform

Lilasciences • San Francisco (CA)

On-site
USD 180,000 - 256,000
Medical, dental, vision benefits
Life and disability insurance
Flexible time off and holidays
+4
Staff Engineer, Enterprise Externalization
Staff Engineer, Enterprise Externalization

Lilasciences • San Francisco (CA)

On-site
USD 192,000 - 272,000
Medical, dental, and vision coverage
Life and disability insurance
Flexible time off
+4
Senior Director, Software Development, Test Automation
Senior Director, Software Development, Test Automation

Lila Sciences • San Francisco (CA)

On-site
USD 260,000 - 390,000
Equity program
Comprehensive benefits
Shift Supervisor, Research Operations
Shift Supervisor, Research Operations

Lila Sciences • Cambridge (MA)

On-site
USD 119,000 - 182,000
Senior Software Engineer, Operations Research
Senior Software Engineer, Operations Research

Lila Sciences • Cambridge (MA)

On-site
USD 180,000 - 256,000
Medical, dental, and vision coverage
Life and disability insurance
Generous paid time off
+4
Senior Software Engineer, Scientific System of Record
Senior Software Engineer, Scientific System of Record

Lila Sciences • Cambridge (MA)

On-site
USD 144,000 - 240,000
Medical, dental, and vision coverage
Flexible time off
Educational assistance program
+2
Sr Principal/ Principal Software Engineer, Scientific System of Record
Sr Principal/ Principal Software Engineer, Scientific System of Record

Lila Sciences • San Francisco (CA), Cambridge (MA)

On-site
USD 204,000 - 348,000
Bonus potential
Equity
Comprehensive benefits
Senior Software Engineer I/II, Back-end/Data, Robotics
Senior Software Engineer I/II, Back-end/Data, Robotics

Lila Sciences • Cambridge (MA)

On-site
USD 163,000 - 240,000
Equity
Comprehensive benefits
Flexible time off
Senior Engineer I/II, Drug Discovery Platform
Senior Engineer I/II, Drug Discovery Platform

Lila Sciences • Cambridge (MA)

On-site
USD 148,000 - 240,000
Commuter benefits
Lunch program
Educational assistance
+1
Staff Engineer, Enterprise Externalization
Staff Engineer, Enterprise Externalization

Lila Sciences • San Francisco (CA)

On-site
USD 192,000 - 272,000
Equity
Bonus potential
Comprehensive benefits