Smith+Nephew
Healthcare
SeniorOffensiveSecurityEngineer
Neural analysis suggests this role is
optimal for Senior candidates.
“Senior Offensive Security Engineer at Smith+Nephew. Skills: Offensive Security, Penetration testing, AI Security, MITRE ATT&CK. Develop AI augmented capability for penetration testing. Deliver AI augmented capability for penetration testing”
What You'll Achieve.
Increase insourcing over time; Drive higher quality outcomes; Improve efficiency through automation; Improve efficiency through AI augmentation; Improving capability and maturity
Industry & Context.
Root cause analysis
UK Shift Timing, Working from office
What They're Looking For.
Must Have
5 years of experience in penetration testing, Extensive experience with offensive security tools, Experience with at least one programming language, Full understanding of MITRE ATT&CK, Understanding of MITRE ATLAS, Understanding of OWASP for AI, Deep understanding of offensive security tools, Deep understanding of offensive security frameworks, Understanding of network protocols, Understanding of OS, Understanding of public cloud, Understanding of web applications, Effective report writing
Nice to Have
Bachelor's degree or equivalent experience in Computer Science or related subject preferred
What You'll Do.
Develop AI augmented capability for penetration testing
Deliver AI augmented capability for penetration testing
Manage offensive security team
Deliver security assessments program
Deliver penetration testing program
Deliver breach and attack simulation activities
Partner with Product Security
Partner with Security Architecture
Partner with Enterprise Technology
Understand business requirements
Understand regulatory requirements
Match capabilities to requirements
Ensure cost efficient fulfilment
Ensure high quality fulfilment
Increase insourcing over time
Scope penetration tests
Plan penetration tests
Execute penetration tests
Assess medical devices
Assess web applications
Write penetration testing reports
Provide prioritized findings
Provide identified vulnerabilities
Provide proof of compromise
Provide remediation advice
Assess external penetration test reports
Assess bug bounty requests
Contribute to continuous service improvement
Develop work instructions
Develop methodologies
Drive higher quality outcomes
Improve efficiency through automation
Improve efficiency through AI augmentation
Provide technical subject matter expertise
Improve capability of information security practices
Improve maturity of information security practices
How You'll Work.
Team & Collaboration
Product Security; Security Architecture; R&D; Enterprise Technology; Cyber Defense function
Communication Scope
Report writing; Written communication; Oral communication
Full Job Description
**Role:****Senior Offensive Security Engineer** Location: Kharadi,Pune. **Life Unlimited.** At Smith+Nephew, we design and manufacture technology that takes the limits off living. The Senior Offensive Security Engineer will develop and then deliver a modern AI augmented capability for penetration testing within the Cyber Defense function of Information Security. The role has people management responsibility for the offensive security team and is part of a larger team responsible for delivering a program of security assessments, penetration testing and breach and attack simulation activities to support the security objectives of Smith & Nephew. The role reports to the Director of Cyber Defense. **What will you be doing?** * The work includes partnering closely with Product Security, Security Architecture, R&D, Enterprise Technology, and other teams to understand business and regulatory requirements for security testing and match it to capabilities to ensure cost efficient and high-quality fulfilment through the right channel, with the objective of increasing insourcing over time. * The role is primarily internal facing with a lower degree of external interaction with partner organizations. * (60%) Scope, plan, and execute penetration tests and security assessments on a wide range of technologies, such as enterprise IT, medical devices, robotics, AI, API, applications, web applications, public cloud, containers, Wi-Fi, Bluetooth, RF etc. * Write deliverables such as fully evidenced penetration testing reports showing prioritized findings with identified vulnerabilities, proof of compromise, and remediation advice. * (10%) Provide subject matter expertise to assess external penetration test reports or bug bounty requests. * (10%) Contribute to continuous service improvement, developing processes, work instructions, methodologies and frameworks to drive higher quality outcomes or improve efficiency through automation or AI augmentation. * (15%) Manage, mentor and coach
Applying for this Senior Offensive Security Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about Smith+Nephew?
Real rants from real employees. Read before you apply.