Offensive Security Analyst

  • Abbott Laboratories
  • Madison, Wisconsin
  • 09/06/2026
Full time Information Technology Telecommunications

Job Description

Abbott Laboratories is seeking an Offensive Security Analyst to strengthen the security of our biotechnology and pharmaceutical platforms. In this role, you will perform penetration tests, red-team exercises, and adversary emulations against networks, applications, cloud, and medical-related systems to uncover and exploit vulnerabilities before attackers do. You will translate findings into clear remediation guidance, partner closely with engineering, IT, and compliance teams, and help shape secure designs for new products and technologies. You'll join an inclusive, mission-driven culture with robust development opportunities, global exposure, and strong benefits as you help protect life changing healthcare solutions worldwide.

Responsibilities

  • Conduct offensive security assessments, penetration tests, and red-team exercises on Abbott's biotech and pharmaceutical systems and applications
  • Identify, validate, and exploit vulnerabilities across networks, cloud, endpoints, and OT/Io
  • T medical environments
  • Develop detailed technical reports and executive summaries with clear remediation recommendations
  • Collaborate with security engineering, IT, product, and compliance teams to prioritize and mitigate findings
  • Support secure design reviews for new products, platforms, and third party integrations
  • Continuously research emerging threats, tools, and tactics relevant to healthcare and pharmaceutical environments
  • Help improve security testing methodologies, tooling, and automation pipelines
  • Assist incident response teams by providing attacker-perspective insights and attack path analysis
  • Contribute to security awareness and training by demonstrating offensive techniques and risks
  • Ensure offensive activities comply with regulatory, privacy, and safety requirements in healthcare

Required Skills

  • Penetration testing of web, mobile, APIs, and infrastructure
  • Red teaming and adversary emulation methodologies
  • Network and cloud security (AWS/Azure/GCP) assessment
  • Exploitation frameworks (e.g., Metasploit, Cobalt Strike, Empire)
  • Scripting and automation (Python, Power
  • Shell, Bash)
  • Vulnerability discovery and exploitation techniques
  • Secure code review and application security testing
  • Knowledge of healthcare/biotech regulatory and security standards
  • Threat modeling and attack surface analysis
  • Technical report writing and communication for technical and executive audiences