02 Aug
|
Loreal India
|
Hyderabad
02 Aug
Loreal India
Hyderabad
SecOps Manager, NA SAPMENA Zone Hyderabad, India Hello, were LOral. Were not just building brands were shaping how the world experiences beauty. As a global Beauty Tech leader, we combine technology, data, creativity, and innovation to create meaningful consumer experiences at scale.
We are looking for a proactive and technically robust SecOps Manager to strengthen the cybersecurity posture of our server, virtual machine, cloud workload, and hybrid infrastructure environments. A Day in the Life Reporting to the CSD Zone Lead, the SecOps Manager will lead security operations, vulnerability remediation, audit-action tracking, cloud-security posture management, and resilience activities across on-premise and multi-cloud environments. You will work closely with Infrastructure, Cloud, Applications, IT Operations, Global Cyber Security, managed-service providers, and business stakeholders to ensure cybersecurity risks are identified, prioritised, remediated, and clearly reported.
Key Responsibilities Security Operations &
- Risk Mitigation Lead security operations for servers, virtual machines, cloud workloads, and associated infrastructure services. Oversee the effectiveness and coverage of security technologies such as Tanium, server EDR, anti-malware, CWPP, vulnerability-management, and security-monitoring tools. Drive the remediation of vulnerabilities, misconfigurations, unsupported technologies, and security-control gaps. Define and track SecOps KPIs and KRIs, including vulnerability ageing, patch compliance, workload-security coverage, remediation timelines, and risk exceptions.
Prepare operational dashboards and risk reports for cybersecurity governance and leadership teams. Vulnerability, Patch &
- Obsolescence Management Own the end-to-end vulnerability-management lifecycle for servers, VMs, infrastructure platforms, and cloud workloads. Coordinate vulnerability identification, triage, prioritisation, remediation planning, exception management, validation, and closure. Orchestrate lifecycle patching across on-premise, hybrid, and multi-cloud environments. Track and manage technology-obsolescence risks related to operating systems, middleware, databases, runtimes, virtualization platforms, and infrastructure components. Apply a risk-based approach considering severity, exploitability, asset criticality, business impact, and external exposure.
Cloud Security
Manage cloud-security posture and remediation activities across AliCloud ,Azure, GCP and AWS environments. Demonstrate hands-on experience with AliCloud technologies and security controls, including ECS, VPC, RAM, security groups, logging, monitoring, workload protection, and cloud-configuration security. Coordinate remediation of CSPM findings and cloud misconfigurations.
Partner with Cloud and Platform teams to improve identity controls, network segmentation, encryption, logging, monitoring,
security baselines, and workload hardening. Ensure server, VM, cloud workload, and security-relevant configuration information is complete and accurate in the CMDB.
Security Audit
Tracking &
- Mitigation Manage the tracking and remediation of findings from internal and external audits, cybersecurity assessments, penetration tests, cloud-security reviews, compliance reviews, and operational-risk assessments. Maintain a central audit-action tracker covering action owner, due date, remediation evidence, risk status, and escalation requirements. Validate evidence before closure and ensure actions address the root cause of the identified control gap. Report on open, overdue, high-risk, and recurring audit findings, highlighting trends and required management decisions. DRP &
- Resilience Management Own and maintain the annual Disaster Recovery Plan (DRP) calendar. Coordinate DRP exercises, recovery tests, failover tests, tabletop exercises, evidence collection, lessons learned, and remediation follow-up. Work with Infrastructure, Cloud, Application, and Business Continuity teams to improve recovery readiness, backup controls, resilience, and operational continuity. Ensure gaps identified during DRP tests are tracked, assigned, and closed within agreed timelines. On-Demand Cybersecurity Initiatives Lead or support targeted cybersecurity initiatives based on business, audit, technology, regulatory, or risk requirements. Typical initiatives may include Java compliance, cyber-process improvement, server harde .
📌 LOreal is Hiring For SecOps Lead/Manager (Hyderabad)
🏢 Loreal India
📍 Hyderabad