| Location | Madison, Wisconsin |
| Industry | Healthcare Services |
| Company Size | 10,000 employees or more |
| Year Founded | 1910 |
| Website | http://www.abbott.com/ |
Working at Abbott
At Abbott, you can do work that matters, grow, and learn, care for yourself and your family, be your true self, and live a full life. You’ll also have access to:
The Opportunity
The Offensive Security Analyst supports Abbott’s Enterprise Cybersecurity Operations, Red Team Operations program by executing authorized penetration tests, supporting adversary emulation and purple team exercises, and validating vulnerabilities across internal and external assets. Working within defined methodologies, scope, and Rules of Engagement, the analyst develops hands on offensive security expertise while producing clear, actionable findings that measurably improve Abbott’s security posture. The role emphasizes technical execution, continuous skill development, and safe, ethical testing within a regulated healthcare environment.
This position reports to the Manager of Red Team Operations within Enterprise Cybersecurity and supports offensive security testing across Abbott’s enterprise technology environment. Responsibilities emphasize hands on execution and technical skill development under senior oversight, with exposure to purple team operations, vulnerability validation, cloud and identity attack paths, and emerging threat areas. The analyst is expected to grow toward performing standard assessments with increasing independence.
Abbott operates in a regulated healthcare and medical device environment, so testing may involve sensitive data, including PHI, and patient adjacent or clinical systems. The analyst is expected to minimize captured sensitive data, store evidence only in approved locations, coordinate testing windows to limit operational impact, and comply with all applicable authorization, privacy, and regulatory requirements.
What You’ll Do
Offensive testing and adversary emulation
The analyst plans and executes authorized penetration tests against Abbott owned assets, including web applications, APIs, network infrastructure, and cloud environments, within approved scope and Rules of Engagement. This includes supporting purple team adversary emulation exercises by assisting with scenario development, executing ATT&CK mapped tactics, techniques, and procedures, validating detection and response coverage alongside defensive teams, and documenting lessons learned. The analyst supports red team and objective based engagements under senior direction and contributes to specialized assessments.
Vulnerability validation
The analyst performs vulnerability validation and exploit feasibility assessments to confirm real-world risk and reduce false positives before remediation prioritization. Individual weaknesses are analyzed and chained into meaningful attack paths mapped to MITRE ATT&CK, OWASP, and CWE, and the analyst develops and safely tests proof of concept exploits within authorized environments.
Reporting and communication
The analyst produces clear, structured assessment reports and executive summaries with supporting evidence, CVSS based severity justification, business risk context, and actionable remediation guidance. The role supports post engagement readouts, knowledge transfer sessions, and remediation discussions with application owners and IT teams, and translates technical findings for both technical and non-technical audiences.
Collaboration and program contribution
The analyst collaborates with the Incident Response, Threat Intelligence, Vulnerability Management, Detection Engineering, and Cybersecurity Architecture teams, and contributes to service metrics and dashboards that track testing coverage, vulnerability trends, and detection effectiveness over time. The role also contributes to team methodology, tooling, playbooks, and documentation held in SharePoint, Git, and wiki resources.
Professional conduct and development
The analyst operates strictly within authorization, scope, Rules of Engagement, and legal and ethical boundaries, exercising discretion when handling highly sensitive data, including PHI, and patient-adjacent or clinical systems. Complex, novel, or high risk findings are escalated promptly with appropriate documentation. The analyst continuously develops offensive security skills through self-directed learning, labs, and research, maintaining growing proficiency with standard tooling such as Burp Suite, Nmap, BloodHound, and content-discovery tools.
Education and Experience You’ll Bring
Required Qualifications
Preferred Qualifications
The base pay for this position is
$61,300.00 – $122,700.00In specific locations, the pay range may vary from the range posted.
Abbott is an Equal Opportunity Employer of Minorities/Women/Individuals with Disabilities/Protected Veterans.
EEO is the Law link - English: http://webstorage.abbott.com/common/External/EEO_English.pdf
EEO is the Law link - Espanol: http://webstorage.abbott.com/common/External/EEO_Spanish.pdf
At Abbott, we are enthusiastic, energetic and committed to doing great work every day. Our employees are passionate about helping to translate science into lasting contributions to health care and the health of people worldwide. At the heart of our organization is our "Promise for Life"—a statement that embodies our company's commitment to employees, shareholders, local communities and the people who depend on our company and products to live healthier lives.
Vital to our promise is the speed in which we act, respond and deliver. As Abbott employees, we are ready to meet change and challenges head-on. As a result, we are a company that adapts quickly, and through our passion for innovation we are able to continually create a pipeline of products that help improve the length and quality of life around the world.
We are proud of our rich, more than 120-year history. We continue to be driven to advance leading-edge science and technologies, support diversity, focus on exceptional performance and earn the trust of those we serve.