07 Aug
|
Loreal India
|
Hyderabad
07 Aug
Loreal India
Hyderabad
SecOps Manager, NA SAPMENA Zone Hyderabad, India
Hello, we’re L’Oral.
We’re not just building brands — we’re shaping how the world experiences beauty. As a global Beauty Tech leader, we combine technology, data, creativity, and innovation to create meaningful consumer experiences at scale.
We are looking for a proactive and technically strong SecOps Manager to strengthen the cybersecurity posture of our server, virtual machine, cloud workload, and hybrid infrastructure environments.
A Day in the Life
Reporting to the CSD Zone Lead, the SecOps Manager will lead security operations, vulnerability remediation, audit-action tracking, cloud-security posture management, and resilience activities across on-premise and multi-cloud environments.
You will work closely with Infrastructure, Cloud, Applications, IT Operations, Global Cyber Security, managed-service providers, and business stakeholders to ensure cybersecurity risks are identified, prioritised, remediated, and clearly reported.
Key Responsibilities
Security Operations & Risk Mitigation
- Lead security operations for servers, virtual machines, cloud workloads, and associated infrastructure services.
- Oversee the effectiveness and coverage of security technologies such as Tanium, server EDR, anti-malware, CWPP, vulnerability-management, and security-monitoring tools.
- Drive the remediation of vulnerabilities, misconfigurations, unsupported technologies, and security-control gaps.
- Define and track SecOps KPIs and KRIs, including vulnerability ageing, patch compliance, workload-security coverage, remediation timelines, and risk exceptions.
- Prepare operational dashboards and risk reports for cybersecurity governance and leadership teams.
Vulnerability, Patch & Obsolescence Management
- Own the end-to-end vulnerability-management lifecycle for servers, VMs, infrastructure platforms, and cloud workloads.
- Coordinate vulnerability identification, triage, prioritisation, remediation planning, exception management, validation, and closure.
- Orchestrate lifecycle patching across on-premise, hybrid, and multi-cloud environments.
- Track and manage technology-obsolescence risks related to operating systems, middleware, databases, runtimes, virtualization platforms, and infrastructure components.
- Apply a risk-based approach considering severity, exploitability, asset criticality, business impact, and external exposure.
Cloud Security
- Manage cloud-security posture and remediation activities across AliCloud ,Azure, GCP and AWS environments.
- Demonstrate hands-on experience with AliCloud technologies and security controls, including ECS, VPC, RAM, security groups, logging, monitoring, workload protection, and cloud-configuration security.
- Coordinate remediation of CSPM findings and cloud misconfigurations.
- Partner with Cloud and Platform teams to improve identity controls, network segmentation, encryption, logging, monitoring, security baselines, and workload hardening.
- Ensure server, VM, cloud workload, and security-relevant configuration information is complete and accurate in the CMDB.
Security Audit Tracking & Mitigation
- Manage the tracking and remediation of findings from internal and external audits, cybersecurity assessments, penetration tests, cloud-security reviews, compliance reviews, and operational-risk assessments.
- Maintain a central audit-action tracker covering action owner, due date, remediation evidence, risk status, and escalation requirements.
- Validate evidence before closure and ensure actions address the root cause of the identified control gap.
- Report on open, overdue, high-risk, and recurring audit findings, highlighting trends and required management decisions.
DRP & Resilience Management
- Own and maintain the annual Disaster Recovery Plan (DRP) calendar.
- Coordinate DRP exercises, recovery tests, failover tests, tabletop exercises, evidence collection, lessons learned, and remediation follow-up.
- Work with Infrastructure, Cloud, Application, and Business Continuity teams to improve recovery readiness, backup controls, resilience, and operational continuity.
- Ensure gaps identified during DRP tests are tracked, assigned, and closed within agreed timelines.
On-Demand Cybersecurity Initiatives
- Lead or support targeted cybersecurity initiatives based on business, audit, technology, regulatory, or risk requirements.
- Typical initiatives may include Java compliance, cyber-process improvement, server hardening, cloud-security remediation, security-tool onboarding, CMDB improvement, privileged-access remediation, audit remediation, and cloud-migration security assessments.
- Manage action plans, milestones, risks, dependencies, stakeholder communication, and delivery reporting.
AI, Automation & Infrastructure as Code (IaC)
- Experience applying automation and AI-enabled capabilities to improve cybersecurity operations, such as vulnerability prioritisation, alert enrichment, remediation tracking, audit-evidence collection, compliance reporting, and security-dashboard automation.
- Understanding of responsible use of AI in security operations, including validation of AI-generated outputs, data protection, access controls, traceability,
and human oversight for risk-based decisions.
- Practical experience with automation and orchestration tools, scripting, APIs, or workflow platforms to reduce manual operational activities and improve remediation speed and consistency.
- Working knowledge of Infrastructure as Code (IaC) security practices, including secure provisioning, configuration validation, policy-as-code, secrets management, version control, and automated compliance checks.
- Experience reviewing or supporting IaC technologies such as Terraform, Ansible, ARM templates, Bicep, Alibaba Cloud Resource Orchestration Service (ROS), or equivalent tools.
We Are Looking For
Education & Experience
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related technical discipline.
- Minimum 7 years of relevant experience in cybersecurity operations, server security, cloud security, vulnerability management, IT infrastructure security, audit remediation, or IT risk.
- Demonstrated experience managing security for servers, virtual machines, cloud workloads, and hybrid infrastructure.
- Proven experience with vulnerability remediation, patch-management coordination, audit tracking, and security-control reporting.
- Experience in enterprise-scale, geographically distributed, or managed-services environments is preferred.
Certifications Candidates should hold at least one relevant cybersecurity or cloud-security certification, such as:
- CISM, CISSP, CCSP, CompTIA Security+
- Microsoft Azure Security Engineer Associate
- AWS Certified Security – Specialty
- Relevant Ali Cloud certification, preferably in cloud architecture, cloud security, or cloud operations
Technical Skills
- Robust knowledge of server, VM, and cloud-workload security.
- Experience with vulnerability management, patching, secure configuration, CSPM, CWPP, CMDB, audit remediation, and DRP testing.
- Working knowledge of AliCloud, including ECS, VPC, RAM, security groups, logging, monitoring, and cloud-security practices.
- Familiarity with Azure and AWS cloud-security controls.
- Exposure to tools such as Tanium, Qualys, Tenable, Rapid7, Microsoft Defender for Cloud/Servers, CrowdStrike, Wiz, Prisma Cloud, or equivalent technologies.
- Knowledge of ISO 27001, NIST, CIS Benchmarks, ITIL, and cloud-security best practices is desirable.
What’s In It For You
- Real responsibility from day one in a global Beauty Tech organisation.
- The opportunity to work on modern hybrid and multi-cloud technologies, including AliCloud.
- A collaborative and inclusive environment where diverse perspectives are valued.
- Opportunities to grow your cybersecurity, cloud, automation, and leadership capabilities while contributing to a secure and resilient technology ecosystem.
📌 LOreal is Hiring For SecOps Lead/Manager (Hyderabad)
🏢 Loreal India
📍 Hyderabad