Offensive Security Analyst
Abbott Laboratories
- Location
- United States > Madison : 1 Exact Lane
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 28 approvals (FY2023)
- Posted
- Sep 1, 2026
Skills
About this role
Abbott is a global healthcare leader that helps people live more fully at all stages of life. Our portfolio of life-changing technologies spans the spectrum of healthcare, with leading businesses and products in diagnostics, medical devices, nutritionals and branded generic medicines. Our 122,000 colleagues serve people in more than 160 countries.
JOB DESCRIPTION
Working at Abbott At Abbott, you can do work that matters, grow, and learn, care for yourself and your family, be your true self, and live a full life. You’ll also have access to: Career development with an international company where you can grow the career you dream of. Employees can qualify for free medical coverage in our Health Investment Plan (HIP) PPO medical plan in the next calendar year. An excellent retirement savings plan with a high employer contribution Tuition reimbursement, the Freedom 2 Save student debt program, and FreeU education benefit - an affordable and convenient path to getting a bachelor’s degree. A company recognized as a great place to work in dozens of countries worldwide and named one of the most admired companies in the world by Fortune. A company that is recognized as one of the best big companies to work for as well as the best place to work for diversity, working mothers, female executives, and scientists.
The Opportunity
The Offensive Security Analyst supports Abbott’s Enterprise Cybersecurity Operations, Red Team Operations program by executing authorized penetration tests, supporting adversary emulation and purple team exercises, and validating vulnerabilities across internal and external assets. Working within defined methodologies, scope, and Rules of Engagement, the analyst develops hands on offensive security expertise while producing clear, actionable findings that measurably improve Abbott’s security posture. The role emphasizes technical execution, continuous skill development, and safe, ethical testing within a regulated healthcare environment. This position reports to the Manager of Red Team Operations within Enterprise Cybersecurity and supports offensive security testing across Abbott’s enterprise technology environment. Responsibilities emphasize hands on execution and technical skill development under senior oversight, with exposure to purple team operations, vulnerability validation, cloud and identity attack paths, and emerging threat areas. The analyst is expected to grow toward performing standard assessments with increasing independence. Abbott operates in a regulated healthcare and medical device environment, so testing may involve sensitive data, including PHI, and patient adjacent or clinical systems. The analyst is expected to minimize captured sensitive data, store evidence only in approved locations, coordinate testing windows to limit operational impact, and comply with all applicable authorization, privacy, and regulatory requirements. What You’ll Do Offensive testing and adversary emulation The analyst plans and executes authorized penetration tests against Abbott owned assets, including web applications, APIs, network infrastructure, and cloud environments, within approved scope and Rules of Engagement. This includes supporting purple team adversary emulation exercises by assisting with scenario development, executing ATT&CK mapped tactics, techniques, and procedures, validating detection and response coverage alongside defensive teams, and documenting lessons learned. The analyst supports red team and objective based engagements under senior direction and contributes to specialized assessments. Vulnerability validation The analyst performs vulnerability validation and exploit feasibility assessments to confirm real-world risk and reduce false positives before remediation prioritization. Individual weaknesses are analyzed and chained into meaningful attack paths mapped to MITRE ATT&CK, OWASP, and CWE, and the analyst develops and safely tests proof of concept exploits within authorized