Cybersecurity - Penetration Tester

L'Oréal · Hyderabad

  • Experience3–4 yrs
  • SalaryNot disclosed
  • Work modehybrid
  • Posted29 Sept 2026

About L'Oréal

L'Oréal is hiring in Hyderabad in consumer goods. This role looks for around 3+ years of experience.

Skills

  • Penetration Testing
  • Vulnerability Management
  • Web Application Security
  • API Security
  • Mobile Application Security
  • Network Security
  • Cloud Security
  • Threat Modeling
  • Attack Surface Management
  • Python
  • Go
  • Bash
  • Node.js
  • TCP/IP
  • Intrusion Detection and Prevention Systems
  • Firewalls
  • Web Application Firewalls
  • English
  • CREST
  • OSCP
  • OSWE
  • OSED
  • GPEN
  • GWAPT

The role

A penetration tester at a beauty technology company performs Penetration Testing, Vulnerability Research, and Multi-Cloud Security across web applications, APIs, mobile applications, networks, and cloud environments, and develops Generative AI automation workflows. The role also applies Threat Modeling and Python to produce exploit tooling and risk-based remediation.

Full job description

Unleash Your Potential at L'Oréal's Beauty Tech!

Who Are We?

For 115 years, L’Oréal, the world’s leading beauty player, has devoted itself to one thing only: fulfilling the beauty aspirations of consumers around the world.

For more than a century, L’Oréal has devoted itself solely to one business: Beauty. Present in 150 countries across five continents and with €42 billion consolidated sales, L'Oréal is the global industry leader. With 37 global beauty brands across four divisions, L’Oréal offers beauty for each covering all beauty categories and catering to all beauty desires. With the acquisition of the Australian brand Aēsop in 2023, the Group continues to expand its portfolio through targeted acquisitions as part of its drive to create the future of beauty.

Today, L’Oréal includes more than 2,000 tech professionals and is constantly growing. Beauty Tech is changing the game and leading the shift towards new consumer realities and a digital disruption. Championing Beauty Tech, we invent the beauty of the future while becoming the company of the future.

Beauty Tech is how we know our consumers intimately, augmenting their beauty journeys with unparalleled diverse and sustainable experiences. Beauty Tech equips the Group with the key assets it needs to conquer this new world, where Tech has become strategic. With this ambition, L’Oréal continues to recruit diverse, innovative, skilled and passionate minds in different tech domains such as Data, Digital, Cloud, Cyber Security, IT Architecture, DevOps, Applications and Infrastructure.

A Day in the Life of Regional Penetration Tester

Sponsored training and personal career development plan. A highly dynamic playground where you will assess modern technologies (AI, multi-clouds, IoT, and custom enterprise solutions) and have the autonomy to make a massive impact. A flexible, hybrid working model based out of our Tech Hub designed for collaboration and high performance. Be part of a core team in a regional hub experiencing exponential growth, offering internal mobility and leadership opportunities.

In this role, You will..

As a Regional Penetration Tester, You Will Combine a Hacker’s Mindset With Enterprise-grade Execution To Secure Our Regional Assets. Your Day-to-day Will Involve

Hands-on Penetration Testing: Perform rigorous, manual security assessments against L'Oréal’s internal and external assets, including web applications, APIs, mobile apps, network architectures, and cloud environments. AI-Driven Innovation: Leverage and integrate cutting-edge Generative AI capabilities to develop, automate, and continuously optimize our offensive workflows, custom exploit tooling, and testing methodologies. Vulnerability Management & Triage: perform continuous vulnerability scans, eliminate false positives, and accurately prioritize findings. Collaborative Remediation: Evaluate identified security flaws to recommend pragmatic, risk-based remediation strategies (patching, configuration changes, deprecation, or compensating controls). Stakeholder Engagement: Run engagement kick-off calls and translate technical vulnerabilities into clear, actionable risks during walkthroughs with application development teams and business stakeholders when needed Metrics & Documentation: Draft comprehensive, high-quality technical reports detailing exploit chains, impact analysis, and remediation steps, while reporting key project and operational metrics.

What are we looking for?

Education & Experience Experience: 3+ years of dedicated, hands-on experience in offensive security, penetration testing, or vulnerability research. Education: Bachelor's degree in Computer Science, Information Security, Cybersecurity, or equivalent practical field experience. Certifications CREST certification OR at least one industry-recognized offensive security certification (such as OSCP, OSWE, OSED, GPEN, or GWAPT). Technical Competency & Domain Expertise Multi-Domain Penetration Testing: Demonstrated experience across:Web Application & APIs: Testing complex web apps and services (REST, GraphQL, microservices).Enterprise/Ecommerce solutions: Salesforce (SFCC, SFMC), Shopify, etc.Network Infrastructure: Assessing internal/external corporate networks and system configurations.Mobile Applications: Dynamic and static analysis of iOS and Android applications.Thick Clients: Conducting reverse engineering when needed, and security assessments of desktop/thick client applications.Multi-Cloud Security: Assessing secure configurations and exploit paths in AWS, Azure, GCP, and Alicloud. Secure by Design: Practical understanding of threat modeling, attack surface reduction, and attack path mapping. Development & Automation: Proficiency in writing automation workflows and utilizing scripting languages (such as Python, Go, Bash, or NodeJS) to develop proof-of-concepts (PoCs). Network & Security Fundamentals: TCP/IP networking, IDS/IPS behaviour, firewalls, Web Application Firewalls (WAF) Communication & Interpersonal Skills Language: Fluency in professional-grade English (written and spoken). Collaboration: Exceptional communication skills with the ability to build trust and collaborate seamlessly with diverse technical and non-technical stakeholders across the APAC region.

Great to Have (Stand-Out Skills)

Vulnerability Research & Bug Hunting: A proven track record in CTFs, private/public Bug Bounty programs, or published CVEs. Advanced Code Review: Deep experience in manual secure code review across diverse languages (Python, NodeJS, PHP, Java, C#, or Go). Advanced Credentials: Holders of specialized certifications such as OSCE, OSWE, OSEE, CREST CRT, or GIAC GXPN. AI-Enabled Pentesting Capability: Proven experience utilizing or building AI-driven security tooling (e.g., leveraging LLMs for automated script generation, secure code review, or creating agentic workflows to augment penetration testing capabilities).

What’s In It for You?

Working with cutting edge Technology, empowering employees with new age learning, global exposure, and opportunities to build future-ready careers.A flexible and modern workplace, enabling teams to perform at their best through a smart hybrid model that supports balance and autonomy. A 3 Day in Office, 2 Day Work from Home setup.Employee support at every life stage, with inclusive and progressive parental policies that help individuals and families thrive.Holistic wellbeing offerings - personalized health benefits and strong mental wellness support to ensure employees feel their best.Reward and Recognition opportunities, long-term incentives, and opportunities to share in L’Oréal’s collective success.L'Oreal is an Equal Opportunity Employer and takes pride in a diverse environment

We would love to find out more about you as a candidate and we do not discriminate in recruitment, hiring, training, promotion, or other employment practices. The beauty we find in our differences gives us the freedom to go beyond. That’s the beauty of L’Oréal.