Offensive Security Analyst

AbbottMadison, WI
$61,300 - $122,700Onsite

About The Position

The Offensive Security Analyst supports Abbott’s Enterprise Cybersecurity Operations, Red Team Operations program by executing authorized penetration tests, supporting adversary emulation and purple team exercises, and validating vulnerabilities across internal and external assets. Working within defined methodologies, scope, and Rules of Engagement, the analyst develops hands-on offensive security expertise while producing clear, actionable findings that measurably improve Abbott’s security posture. The role emphasizes technical execution, continuous skill development, and safe, ethical testing within a regulated healthcare environment. This position reports to the Manager of Red Team Operations within Enterprise Cybersecurity and supports offensive security testing across Abbott’s enterprise technology environment. Responsibilities emphasize hands-on execution and technical skill development under senior oversight, with exposure to purple team operations, vulnerability validation, cloud and identity attack paths, and emerging threat areas. The analyst is expected to grow toward performing standard assessments with increasing independence. Abbott operates in a regulated healthcare and medical device environment, so testing may involve sensitive data, including PHI, and patient adjacent or clinical systems. The analyst is expected to minimize captured sensitive data, store evidence only in approved locations, coordinate testing windows to limit operational impact, and comply with all applicable authorization, privacy, and regulatory requirements.

Requirements

  • A bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field is expected, or equivalent practical experience and certifications.
  • One to three years of relevant cybersecurity experience, and internship, co-op, or applied academic and lab experience will be considered.
  • Working knowledge of Windows and Linux operating systems, networking fundamentals, and Active Directory concepts.
  • Familiarity with offensive security frameworks and standards such as MITRE ATT&CK, OWASP, PTES, CWE, and CVSS.
  • Exposure to scripting or automation such as Python, PowerShell, or Bash.

Nice To Haves

  • Foundational knowledge of web technologies, including HTTP and HTTPS, REST APIs, and authentication mechanisms, and of common vulnerability classes such as the OWASP Top 10.
  • Hands-on familiarity with core offensive security tooling such as Burp Suite, Nmap, Metasploit, and Kali Linux, or demonstrable applied lab proficiency and clear intent to develop these skills.
  • Preferred certifications, or those a candidate is working toward, include OSCP, GPEN, GWAPT, or GXPN; OSWE, CRTP, or CBBH; and a recognized cloud security or cloud penetration testing certification such as an AWS or Azure security credential.

Responsibilities

  • Plans and executes authorized penetration tests against Abbott owned assets, including web applications, APIs, network infrastructure, and cloud environments, within approved scope and Rules of Engagement.
  • Supports purple team adversary emulation exercises by assisting with scenario development, executing ATT&CK mapped tactics, techniques, and procedures, validating detection and response coverage alongside defensive teams, and documenting lessons learned.
  • Supports red team and objective based engagements under senior direction and contributes to specialized assessments.
  • Performs vulnerability validation and exploit feasibility assessments to confirm real-world risk and reduce false positives before remediation prioritization.
  • Analyzes individual weaknesses and chains them into meaningful attack paths mapped to MITRE ATT&CK, OWASP, and CWE.
  • Develops and safely tests proof of concept exploits within authorized environments.
  • Produces clear, structured assessment reports and executive summaries with supporting evidence, CVSS based severity justification, business risk context, and actionable remediation guidance.
  • Supports post engagement readouts, knowledge transfer sessions, and remediation discussions with application owners and IT teams.
  • Translates technical findings for both technical and non-technical audiences.
  • Collaborates with the Incident Response, Threat Intelligence, Vulnerability Management, Detection Engineering, and Cybersecurity Architecture teams.
  • Contributes to service metrics and dashboards that track testing coverage, vulnerability trends, and detection effectiveness over time.
  • Contributes to team methodology, tooling, playbooks, and documentation held in SharePoint, Git, and wiki resources.
  • Operates strictly within authorization, scope, Rules of Engagement, and legal and ethical boundaries, exercising discretion when handling highly sensitive data, including PHI, and patient-adjacent or clinical systems.
  • Escalates complex, novel, or high risk findings promptly with appropriate documentation.
  • Continuously develops offensive security skills through self-directed learning, labs, and research, maintaining growing proficiency with standard tooling such as Burp Suite, Nmap, BloodHound, and content-discovery tools.

Benefits

  • Employees can qualify for free medical coverage in our Health Investment Plan (HIP) PPO medical plan in the next calendar year.
  • An excellent retirement savings plan with a high employer contribution
  • Tuition reimbursement, the Freedom 2 Save student debt program, and FreeU education benefit - an affordable and convenient path to getting a bachelor’s degree.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service