Location : Kochi
Role Summary :
The Lead - Offensive Security is a key member of the Security Assurance Team, responsible for evaluating, testing, and enhancing Lulu Retail's cybersecurity posture. The role plays a critical part in strengthening IT security, improving cyber resilience, and supporting regulatory compliance across cloud and on-premise environments.
Key Responsibilities :
Offensive Security Testing
Plan, execute, and manage periodic offensive security activities, including :
- Vulnerability Assessments
- Penetration Testing (internal & external)
- Wi-Fi Security Testing
- Network Segmentation Testing
- PCI-DSS ASV Scans
- Active Directory Security Audits
- Red Teaming / Adversary Simulation
Cloud & Infrastructure Security :
Perform cloud security assessments for AWS and Azure, identifying misconfigurations, insecure architecture, and policy gaps.Evaluate endpoint, network, and application security controls.Vulnerability & Risk Management :
Conduct CVE analysis, risk scoring, and prioritization.Track remediation progress and verify vulnerability closure.Ensure all security testing aligns with compliance requirements and internal security standards.Collaboration & Advisory :
Work closely with development, DevOps, infrastructure, and IT support teams to :
Explain identified vulnerabilitiesRecommend mitigation strategies and best practicesSupport secure design and implementationLead meetings with asset owners and project teams to ensure timely remediation.Reporting & Documentation :
Prepare detailed technical and executive-level security assessment reports.
Document findings, recommendations, and remediation timelines.Required Qualifications :
Education : Bachelor's degree in Computer Science, Information Security, or a related discipline.
Experience :
Minimum 3 years of hands-on experience in cybersecurity, penetration testing, or offensive security roles.Certifications (Preferred) :
CEHECSACHFIOther recognized offensive security or penetration testing certifications (e.g., OSCP, OSWP, OSCE, GPEN).Technical Skills :
Strong understanding of :
Penetration Testing methodologiesVulnerability Assessment & Patch ManagementAdvanced cyber threats and mitigation techniquesProficiency with IT security tools / platforms :
Anti-malware, Firewalls, IDS / IPS, DLPWeb Proxies, Email SecurityCloud Security (AWS & Azure)Privileged Access ManagementIAM & Identity SecurityExperience with frameworks / standards :
OWASPNIST 800-64PCI-DSSISO 27001GDPRSoft Skills :
Excellent communication and stakeholder-management skillsStrong analytical and problem-solving abilitiesSolid organizational and time-management skillsAbility to work well independently as well as collaboratively within a team(ref : hirist.tech)