Unleash Your Potential at L'Oréal's Beauty Tech!
Who Are We?
For 115 years, L’Oréal, the world’s leading beauty player, has devoted itself to one thing only: fulfilling the beauty aspirations of consumers around the world.
For more than a century, L’Oréal has devoted itself solely to one business: Beauty. Present in 150 countries across five continents and with €42 billion consolidated sales, L'Oréal is the global industry leader. With 37 global beauty brands across four divisions, L’Oréal offers beauty for each covering all beauty categories and catering to all beauty desires. With the acquisition of the Australian brand Aēsop in 2023, the Group continues to expand its portfolio through targeted acquisitions as part of its drive to create the future of beauty.
Today, L’Oréal includes more than 2,000 tech professionals and is constantly growing. Beauty Tech is changing the game and leading the shift towards new consumer realities and a digital disruption. Championing Beauty Tech, we invent the beauty of the future while becoming the company of the future.
Beauty Tech is how we know our consumers intimately, augmenting their beauty journeys with unparalleled diverse and sustainable experiences. Beauty Tech equips the Group with the key assets it needs to conquer this new world, where Tech has become strategic. With this ambition, L’Oréal continues to recruit diverse, innovative, skilled and passionate minds in different tech domains such as Data, Digital, Cloud, Cyber Security, IT Architecture, DevOps, Applications and Infrastructure.
A Day in the Life of SecOps Manager!
We are looking for a proactive and technically strong SecOps Manager to strengthen the cybersecurity posture of our server, virtual machine, cloud workload, and hybrid infrastructure environments.
Reporting to the CSD Zone Lead, the SecOps Manager will lead security operations, vulnerability remediation, audit-action tracking, cloud-security posture management, and resilience activities across on-premise and multi-cloud environments.
You will work closely with Infrastructure, Cloud, Applications, IT Operations, Global Cyber Security, managed-service providers, and business stakeholders to ensure cybersecurity risks are identified, prioritised, remediated, and clearly reported.
In this role, You will.
Be responsible for the following:
Security Operations & Risk Mitigation
- Lead security operations for servers, virtual machines, cloud workloads, and associated infrastructure services.
- Oversee the effectiveness and coverage of security technologies such as Tanium, server EDR, anti-malware, CWPP, vulnerability-management, and security-monitoring tools.
- Drive the remediation of vulnerabilities, misconfigurations, unsupported technologies, and security-control gaps.
- Define and track SecOps KPIs and KRIs, including vulnerability ageing, patch compliance, workload-security coverage, remediation timelines, and risk exceptions.
- Prepare operational dashboards and risk reports for cybersecurity governance and leadership teams.
Vulnerability, Patch & Obsolescence Management
- Own the end-to-end vulnerability-management lifecycle for servers, VMs, infrastructure platforms, and cloud workloads.
- Coordinate vulnerability identification, triage, prioritisation, remediation planning, exception management, validation, and closure.
- Orchestrate lifecycle patching across on-premise, hybrid, and multi-cloud environments.
- Track and manage technology-obsolescence risks related to operating systems, middleware, databases, runtimes, virtualization platforms, and infrastructure components.
- Apply a risk-based approach considering severity, exploitability, asset criticality, business impact, and external exposure.
Cloud Security
- Manage cloud-security posture and remediation activities across AliCloud ,Azure, GCP and AWS environments.
- Demonstrate hands-on experience with AliCloud technologies and security controls, including ECS, VPC, RAM, security groups, logging, monitoring, workload protection, and cloud-configuration security.
- Coordinate remediation of CSPM findings and cloud misconfigurations.
- Partner with Cloud and Platform teams to improve identity controls, network segmentation, encryption, logging, monitoring, security baselines, and workload hardening.
- Ensure server, VM, cloud workload, and security-relevant configuration information is complete and accurate in the CMDB.
Security Audit Tracking & Mitigation
- Manage the tracking and remediation of findings from internal and external audits, cybersecurity assessments, penetration tests, cloud-security reviews, compliance reviews, and operational-risk assessments.
- Maintain a central audit-action tracker covering action owner, due date, remediation evidence, risk status, and escalation requirements.
- Validate evidence before closure and ensure actions address the root cause of the identified control gap.
- Report on open, overdue, high-risk, and recurring audit findings, highlighting trends and required management decisions.
DRP & Resilience Management
- Own and maintain the annual Disaster Recovery Plan (DRP) calendar.
- Coordinate DRP exercises, recovery tests, failover tests, tabletop exercises, evidence collection, lessons learned, and remediation follow-up.
- Work with Infrastructure, Cloud, Application, and Business Continuity teams to improve recovery readiness, backup controls, resilience, and operational continuity.
- Ensure gaps identified during DRP tests are tracked, assigned, and closed within agreed timelines.
On-Demand Cybersecurity Initiatives
- Lead or support targeted cybersecurity initiatives based on business, audit, technology, regulatory, or risk requirements.
- Typical initiatives may include Java compliance, cyber-process improvement, server hardening, cloud-security remediation, security-tool onboarding, CMDB improvement, privileged-access remediation, audit remediation, and cloud-migration security assessments.
- Manage action plans, milestones, risks, dependencies, stakeholder communication, and delivery reporting.
AI, Automation & Infrastructure as Code (IaC)
- Experience applying automation and AI-enabled capabilities to improve cybersecurity operations, such as vulnerability prioritisation, alert enrichment, remediation tracking, audit-evidence collection, compliance reporting, and security-dashboard automation.
- Understanding of responsible use of AI in security operations, including validation of AI-generated outputs, data protection, access controls, traceability, and human oversight for risk-based decisions.
- Practical experience with automation and orchestration tools, scripting, APIs, or workflow platforms to reduce manual operational activities and improve remediation speed and consistency.
- Working knowledge of Infrastructure as Code (IaC) security practices, including secure provisioning, configuration validation, policy-as-code, secrets management, version control, and automated compliance checks.
- Experience reviewing or supporting IaC technologies such as Terraform, Ansible, ARM templates, Bicep, Alibaba Cloud Resource Orchestration Service (ROS), or equivalent tools.
What are we looking for?
Education & Experience
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related technical discipline.
- Minimum 7 years of relevant experience in cybersecurity operations, server security, cloud security, vulnerability management, IT infrastructure security, audit remediation, or IT risk.
- Demonstrated experience managing security for servers, virtual machines, cloud workloads, and hybrid infrastructure.
- Proven experience with vulnerability remediation, patch-management coordination, audit tracking, and security-control reporting.
- Experience in enterprise-scale, geographically distributed, or managed-services environments is preferred.
Certifications Candidates should hold at least one relevant cybersecurity or cloud-security certification, such as:
- CISM, CISSP, CCSP, CompTIA Security+
- Microsoft Azure Security Engineer Associate
- AWS Certified Security – Specialty
- Relevant Ali Cloud certification, preferably in cloud architecture, cloud security, or cloud operations
Technical Skills
- Strong knowledge of server, VM, and cloud-workload security.
- Experience with vulnerability management, patching, secure configuration, CSPM, CWPP, CMDB, audit remediation, and DRP testing.
- Working knowledge of AliCloud, including ECS, VPC, RAM, security groups, logging, monitoring, and cloud-security practices.
- Familiarity with Azure and AWS cloud-security controls.
- Exposure to tools such as Tanium, Qualys, Tenable, Rapid7, Microsoft Defender for Cloud/Servers, CrowdStrike, Wiz, Prisma Cloud, or equivalent technologies.
- Knowledge of ISO 27001, NIST, CIS Benchmarks, ITIL, and cloud-security best practices is desirable.
Nice to Have
- Relevant Ali Cloud certification, preferably in cloud architecture, cloud security, or cloud operations
What’s In It for You?
- Working with cutting edge Technology, empowering employees with new age learning, global exposure, and opportunities to build future-ready careers.
- A flexible and modern workplace, enabling teams to perform at their best through a smart hybrid model that supports balance and autonomy. A 3 Day in Office, 2 Day Work from Home setup.
- Employee support at every life stage, with inclusive and progressive parental policies that help individuals and families thrive.
- Holistic wellbeing offerings - personalized health benefits and strong mental wellness support to ensure employees feel their best.
- Reward and Recognition opportunities, long-term incentives, and opportunities to share in L’Oréal’s collective success.
- L'Oreal is an Equal Opportunity Employer and takes pride in a diverse environment
Good to know: The Recruitment Process
- Interview with HR
- Technical Interview
- Interview with the hiring manager
We would love to find out more about you as a candidate and we do not discriminate in recruitment, hiring, training, promotion, or other employment practices. The beauty we find in our differences gives us the freedom to go beyond. That’s the beauty of L’Oréal.
- 在30天內,您最多可以申請三個職位
- 您可以在"您的求職空間"查看您已申請的職位
- 您可以在"您的求職空間"查看您已申請的職位
- 請不要用其他電子郵件申請多個帳號,您的帳號會被合併且職位申請紀錄會被刪除