Senior Penetration Tester

L''OREAL INDIA PVT LTD

Hyderabad

Hybrid

INR 2,600,000 - 4,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work model
3 days in office + 2 days work from 0

Job summary

L''Oréal India Pvt Ltd seeks a Regional Senior Penetration Tester to secure regional assets with a hacker mindset and enterprise-grade execution. You will mentor engineers, lead testing across web, mobile, APIs, networks, and cloud, and integrate AI-driven tooling to enhance processes.

Interactions with development teams and stakeholders will form a key part of the role. The position requires 8+ years in offensive security, strong English communication, and hands-on expertise across multi-cloud

Qualifications

  • 8+ years hands-on offensive security, penetration testing, or vulnerability research.
  • Bachelor's degree in Computer Science, Information Security, Cybersecurity, or equivalent practical field experience.

Responsibilities

  • Mentor mid-level and junior security engineers and review reports.
  • Perform manual security assessments across web apps, APIs, mobile apps, networks, and cloud environments.
  • Lead AI-driven innovation to automate and optimize offensive workflows and tooling.
  • Triage vulnerabilities, prioritize findings, and guide remediation with stakeholders.
  • Draft high-quality technical reports detailing exploit chains and remediation steps.

Skills

Team Mentorship
Penetration Testing
Vulnerability Management
AI-Enabled Pentesting
Scripting (Python/Go/Bash/PowerShell)
Threat Modeling
Network Security
Communication in English

Education

Bachelor's degree in CS/Info Sec/Cybersecurity

Tools

Kubernetes
Docker
SFCC/SFMC (Salesforce)

Job description

Who Are We

For 115 years, LOral, the worlds leading beauty player, has devoted itself to one thing only: fulfilling the beauty aspirations of consumers around the world.

For more than a century, LOral has devoted itself solely to one business: Beauty.Presentin 150 countries across five continents and with 42 billionconsolidatedsales, L''Oral is the global industry leader.With37 global beauty brandsacross four divisions,LOral offersbeauty for eachcoveringall beauty categories and cateringto all beauty desires.With the acquisition of the Australian brandAsopin 2023, the Group continues to expand its portfolio through targeted acquisitions as part of its drive tocreate the future of beauty.

Today, LOral includes more than2,000 tech professionalsand is constantly growing.Beauty Tech is changing the game and leading the shifttowardsnew consumer realities andadigitaldisruption.Championing Beauty Tech, we invent the beauty of the future while becoming the company of the future.

Beauty Tech is how we know our consumers intimately, augmenting their beauty journeys with unparalleled diverse and sustainable experiences. Beauty Tech equips the Group with the key assets it needs to conquer this new world, where Tech has become strategic. With this ambition, LOral continues to recruitdiverse,innovative,skilledandpassionateminds in different tech domains such asData, Digital, Cloud, Cyber Security, IT Architecture, DevOps,Applicationsand Infrastructure.

A Day in the Life of Regional Senior Penetration Tester!

As a Regional Senior Penetration Tester, you will combine a hackers mindset with enterprise-grade execution to secure our regional assets.

In this role, You will..

Be responsible for the following:

  • Team Mentorship: guide and mentor mid-level and junior offensive security engineers. Conduct technical peer reviews of report deliverables, provide career coaching, and help elevate the team''s overall technical capability.
  • Lead Penetration Testing: Perform rigorous, manual security assessments against L''Orals internal and external assets, including web applications, APIs, mobile apps, network architectures, and cloud environments.
  • Lead AI-Driven Innovation: Leverage and integrate cutting-edge Generative AI capabilities to develop, automate, and continuously optimize our offensive workflows, custom exploit tooling, and testing methodologies.
  • Vulnerability Management Triage: perform continuous vulnerability scans, eliminate false positives, and accurately prioritize findings.
  • Collaborative Remediation: Evaluate identified security flaws to recommend pragmatic, risk-based remediation strategies (patching, configuration changes, deprecation, or compensating controls).
  • Stakeholder Engagement: Run engagement kick-off calls and translate technical vulnerabilities into clear, actionable risks during walkthroughs with application development teams and business stakeholders when needed
  • Metrics Documentation: Draft comprehensive, high-quality technical reports detailing exploit chains, impact analysis, and remediation steps, while reporting key project and operational metrics.
What are we looking for
1) Education Experience
  • Experience: 8+ years of dedicated, hands-on experience in offensive security, penetration testing, or vulnerability research.
  • Education: Bachelors degree in computer science, Information Security, Cybersecurity, or equivalent practical field experience.
2) Technical Competency Domain Expertise

- Elite Multi-Domain Exploitation: Advanced, provable experience in:

  • Web API Exploitation: Testing complex web apps and services (REST, GraphQL, microservices), bypassing complex authentication, authorization, and WAF controls in modern web apps and APIs
  • Enterprise/Ecommerce solutions: Salesforce (SFCC, SFMC), Shopify, etc.
  • Network Infrastructure: Assessing internal/external corporate networks and system configurations.
  • Mobile Client Security: Reverse engineering, dynamic binary analysis, and static analysis of mobile platforms and complex thick client applications.
  • Multi-Cloud Penetration Testing: Deep knowledge of exploiting IAM policies, serverless functions, and containerized architectures (Kubernetes/Docker) in Azure, GCP, AWS and Alicloud.
  • Active Directory Network Infrastructure: Designing and executing internal infrastructure compromise pathways (Kerberoasting, AD CS abuse, lateral movement).
  • AI-Enabled Pentesting Capability: Proven experience utilizing or building AI-driven security tooling (e.g., leveraging LLMs for automated script generation, secure code review, or creating agentic workflows to augment penetration testing capabilities).
  • Advanced Scripting Exploit Dev: High proficiency in Python, Go, Bash, or PowerShell to develop custom tooling, shellcode, and automated exploit flows.
  • Architectural Threat Modeling: Deep understanding of secure design methodologies, threat modeling, and building defensive compensating controls.
  • Network Security Fundamentals: TCP/IP networking, IDS/IPS behaviour, firewalls, Web Application Firewalls (WAF)
  • Published CVEs, specialized security research papers, whitepapers, tools on GitHub, or proven history in global CTFs/Bug Bounty platforms
3) Communication Interpersonal Skills
  • Language: Fluency in professional-grade English (written and spoken).
  • Interpersonal: Outstanding negotiation, diplomacy, and presentation skills. Ability to confidently guide development teams through stressful remediation phases and align stakeholders across multiple cultures.
Great to Have (Stand-Out Skills)
  • Public Contributions: Published CVEs, specialized security research papers, whitepapers, tools on GitHub, or proven history in global CTFs/Bug Bounty platforms.
  • Advanced Code Review: Deep experience in manual secure code review across diverse languages (Python, NodeJS, PHP, Java, C#, or Go).
  • Advanced Credentials: Holders of specialized certifications such as OSCE, OSWE, OSEE, CREST CRT, or GIAC GXPN.
  • Hardware / IoT Security: Experience testing embedded systems, firmware analysis, and radio communication protocols (Bluetooth, NFC, Wi-Fi) for smart consumer devices.
  • DevSecOps/AppSec Mastery: Strong experience integrating SAST/DAST and custom offensive testing tools directly into enterprise GitOps/CI-CD pipelines.
Whats In It for You
  • Working with cutting edge Technology, empowering employees with new age learning, global exposure, and opportunities to build future-ready careers.
  • A flexible and modern workplace, enabling teams to perform at their best through a smart hybrid model that supports balance and autonomy. A 3 Day in Office, 2 Day Work from Home setup.
  • Employee support at every life stage, with inclusive and progressive parental policies that help individuals and families thrive.
  • Holistic wellbeing offerings - personalized health benefits and strong mental wellness support to ensure employees feel their best.
  • Reward and Recognition opportunities, long-term incentives, and opportunities to share in LOrals collective success.
  • L''Oreal is an Equal Opportunity Employer and takes pride in a diverse environment
Good to know: The Recruitment Process
  1. Interview with HR
  2. Technical Interview
  3. Interview with the hiring manager
  4. Business Managerial Interview

We would love to find out more about you as a candidate and we do not discriminate in recruitment, hiring, training, promotion, or other employment practices. The beauty we find in our differences gives us the freedom to go beyond. Thats the beauty of LOral.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SecOps Manager
SecOps Manager

L''OREAL INDIA PVT LTD • Hyderabad

Hybrid
INR 3,000,000 - 5,400,000
Flexible hybrid work model (3 in, 2 at
Global exposure and learning
Wellbeing and inclusive culture
Identity Specialist
Identity Specialist

L''OREAL INDIA PVT LTD • Hyderabad

Hybrid
INR 1,800,000 - 2,400,000
Flexible hybrid work model
Global exposure and learning
Wellbeing and health benefits
+1
Identity Specialist
Identity Specialist

L'Oréal • Hyderabad

Hybrid
INR 4,000,000 - 6,400,000
Hybrid work model
3 days in office, 2 days work fromhome
Parental support policies
+3
GLOBAL API INTEGRATION ENGINEER (Apigee X + Hybrid Developer)
GLOBAL API INTEGRATION ENGINEER (Apigee X + Hybrid Developer)

L'Oréal • Hyderabad

Hybrid
INR 450,000 - 750,000
Senior Developer - Salesforce
Senior Developer - Salesforce

L'Oréal • Hyderabad

Hybrid
INR 1,200,000 - 2,000,000
3 Day in Office
2 Day Work From Home
Global exposure
+1
Senior Manager, Hair Care - Product Development
Senior Manager, Hair Care - Product Development

L''OREAL INDIA PVT LTD • Mumbai

On-site
INR 2,500,000 - 4,200,000
Senior Manager, Product Development, NOE/OD
Senior Manager, Product Development, NOE/OD

L''OREAL INDIA PVT LTD • Mumbai

On-site
INR 2,500,000 - 4,500,000
Data Engineer
Data Engineer

L'Oréal • Hyderabad

Hybrid
INR 2,400,000 - 4,200,000
3 Day in Office, 2 Day Work from Home
Senior Manager, Hair care - Product Development
Senior Manager, Hair care - Product Development

Loreal • Mumbai

On-site
INR 4,000,000 - 7,000,000
OMS Tech Lead
OMS Tech Lead

L'Oréal • Hyderabad

Hybrid
INR 2,500,000 - 4,500,000
Hybrid work model
3 days in office / 2 days work from 1
Global exposure