Job Description : Lead – Offensive Security
Department : Security Assurance
Experience - 5 years
Salary up to 10 LPA
Location : Kochi
Role Summary
The Lead – Offensive Security is a key member of the Security Assurance Team, responsible for evaluating, testing, and enhancing Lulu Retail’s cybersecurity posture. The role plays a critical part in strengthening IT security, improving cyber resilience, and supporting regulatory compliance across cloud and on-premise environments.
Key Responsibilities
Offensive Security Testing
- Plan, execute, and manage periodic offensive security activities, including :
- Vulnerability Assessments
- Penetration Testing (internal & external)
- Wi-Fi Security Testing
- Network Segmentation Testing
- PCI-DSS ASV Scans
- Active Directory Security Audits
- Red Teaming / Adversary Simulation
Cloud & Infrastructure Security
Perform cloud security assessments for AWS and Azure , identifying misconfigurations, insecure architecture, and policy gaps.Evaluate endpoint, network, and application security controls.Vulnerability & Risk Management
Conduct CVE analysis, risk scoring, and prioritization.Track remediation progress and verify vulnerability closure.Ensure all security testing aligns with compliance requirements and internal security standards.Collaboration & Advisory
Work closely with development, DevOps, infrastructure, and IT support teams to :Explain identified vulnerabilitiesRecommend mitigation strategies and best practicesSupport secure design and implementationLead meetings with asset owners and project teams to ensure timely remediation.Reporting & Documentation
Prepare detailed technical and executive-level security assessment reports.Document findings, recommendations, and remediation timelines.Required Qualifications
Education
Bachelor’s degree in Computer Science , Information Security , or a related discipline.Experience
Minimum 3 years of hands-on experience in cybersecurity, penetration testing, or offensive security roles.Certifications (Preferred)
CEHECSACHFIOther recognized offensive security or penetration testing certifications (e.g., OSCP, OSWP, OSCE, GPEN).Technical Skills
Strong understanding of :Penetration Testing methodologiesVulnerability Assessment & Patch ManagementAdvanced cyber threats and mitigation techniquesProficiency with IT security tools / platforms :Anti-malware, Firewalls, IDS / IPS, DLPWeb Proxies, Email SecurityCloud Security (AWS & Azure)Privileged Access ManagementIAM & Identity SecurityExperience with frameworks / standards :OWASPNIST 800-64PCI-DSSISO 27001GDPRSoft Skills
Excellent communication and stakeholder-management skillsStrong analytical and problem-solving abilitiesSolid organizational and time-management skillsAbility to work well independently as well as collaboratively within a team