Smith+Nephew
Healthcare
OffensiveSecurityEngineer
Neural analysis suggests this role is
optimal for Mid+ candidates.
“Offensive Security Engineer at Smith+Nephew. Skills: Offensive Security, Penetration testing, AI Security. Partner with Product Security. Partner with Security Architecture”
What You'll Achieve.
Increase insourcing over time; Drive higher quality outcomes; Improve efficiency through automation; Improve efficiency through AI; Improve capability of information security; Improve maturity of information security
Industry & Context.
Vulnerability identification; Remediation advice
UK Shift Timing, Hybrid work model
What They're Looking For.
Must Have
4+ years experience in penetration testing, Extensive experience with offensive security tools, Experience with at least one programming language, Full understanding of MITRE ATT&CK, Understanding of MITRE ATLAS, Understanding of OWASP for AI, Deep understanding of offensive security tools, Deep understanding of offensive security frameworks, Understanding of network protocols, Understanding of OS, Understanding of public cloud, Understanding of web applications, Effective report writing
Nice to Have
Bachelor's degree in Computer Science or related subject preferred, CEH or OSCP
What You'll Do.
Partner with Product Security
Partner with Security Architecture
Understand business requirements
Understand regulatory requirements
Match capabilities to requirements
Ensure cost efficient fulfilment
Ensure high-quality fulfilment
Increase insourcing over time
Scope penetration tests
Plan penetration tests
Execute penetration tests
Assess medical devices
Assess web applications
Write penetration testing reports
Provide prioritized findings
Provide identified vulnerabilities
Provide proof of compromise
Provide remediation advice
Provide subject matter expertise
Assess external penetration test reports
Assess bug bounty requests
Identify issues in completeness
Identify issues in accuracy
Assist stakeholders in interpreting findings
Assist stakeholders in validating remediation
Contribute to continuous service improvement
Develop work instructions
Develop methodologies
Drive higher quality outcomes
Improve efficiency through automation
Improve efficiency through AI
Ensure understanding of offensive security concepts
Provide technical subject matter expertise
Improve capability of information security
Improve maturity of information security
How You'll Work.
Team & Collaboration
Partnering with teams; Internal facing role; External interaction with partner organization
Communication Scope
Report writing; Written communication; Oral communication
Process & Methodology
Process development, Methodology development, Framework development
Full Job Description
**Role:****Offensive Security Engineer** Location: Kharadi,Pune. **Life Unlimited.** At Smith+Nephew, we design and manufacture technology that takes the limits off living. The Offensive Security Engineer will be part of developing and then delivering a modern AI augmented capability for penetration testing within the Cyber Defense function of Information Security. The role is part of a team responsible for delivering a program of security assessments, penetration testing and breach and attack simulation activities to support the security objectives of Smith & Nephew. The role reports to the Senior Offensive Security Engineer. **What will you be doing?** * The work includes partnering closely with Product Security, Security Architecture, R&D, IT and other teams to understand business and regulatory requirements for security testing and match it to capabilities to ensure cost efficient and high-quality fulfilment through the right channel, with the objective of increasing insourcing over time. * The role is primarily internal facing with a lower degree of external interaction with partner organization. * (70%) Scope, plan, and execute penetration tests and security assessments on a wide range of technologies, such as enterprise IT, medical devices, robotics, AI, API, applications, web applications, public cloud, containers, Wi-Fi, Bluetooth, RF etc. Write deliverables such as fully evidenced penetration testing reports showing prioritized findings with identified vulnerabilities, proof of compromise, and remediation advice. * (10%) Provide subject matter expertise to assess external penetration test reports or bug bounty requests. Identify any issues in completeness and accuracy, as well as assisting internal stakeholders in interpreting findings or validating remediation outcomes. * (10%) Contribute to continuous service improvement, developing processes, work instructions, methodologies and frameworks to drive higher quality outcomes or improve efficiency through a
Applying for this Offensive Security Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about Smith+Nephew?
Real rants from real employees. Read before you apply.