Advisory Engineer, Enterprise Product Security Incident Response Team (E-PSIRT)
Why Work at Lenovo
We are Lenovo. We do what we say. We own what we do. We WOW our customers.
Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).
This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.
Description and Requirements
The Product Security Advisory Engineer of Lenovo’s Enterprise Product Security Incident Response Team (E-PSIRT) is responsible for assessing, triaging, coordinating, and tracking product security vulnerabilities and incidents across Lenovo’s global product portfolio.
This role functions as the central operational orchestrator for product vulnerability activities, coordinating product security offices, engineering teams, suppliers, and other stakeholders to ensure vulnerabilities are appropriately evaluated, prioritized, remediated, disclosed and reported. The position will play a critical role in supporting Lenovo’s Cyber Resilience Act (CRA) compliance program, including vulnerability reporting readiness and regulatory response activities. Lenovo’s E-PSIRT responsibilities include vulnerability intake, triage, workflow management, coordination, impact assessment, reporting, disclosure tracking, technical advisory writing, and support for notification activities.
Core Day-to-Day Operations:
- Liaison with internal and external stakeholders, including Lenovo business units and third-party upstream and downstream suppliers, to coordinate vulnerability response and remediation activities
- Collaborate and negotiate with suppliers, technology partners, and security researchers to triage vulnerabilities, develop remediation plans, and coordinate responsible disclosure activities
- Develop, review, and publish security advisories, communicating available fixes, workarounds, and mitigation strategies for identified vulnerabilities
- Draft and issue customer-facing security communications and advisories, ensuring timely dissemination of mitigation and remediation guidance
- Coordinate cross-functional communications to ensure accurate, consistent, and timely messaging related to security vulnerabilities and product security issues
Key Responsibilities:
- Vulnerability Assessment & Triage: Assess product security vulnerabilities, exploits, and incidents from: researchers, customers, suppliers, threat intelligence feeds, public disclosures, CERTs, and internal testing
- Perform technical analysis and risk evaluation
- Validate business impact
- Determine vulnerability severity and likelihood
- PSIRT Case Management: Manage vulnerability cases from intake through closure, coordinate technical investigations across product security offices and engineering teams, track remediation progress and disclosure milestones
- Central Orchestration: Serve as the operational coordinator across Product Security Offices within IDG, ISG, SSG, Motorola, CAIO, Legal, and other business groups
- Cyber Resilience Act (CRA) Support: Assist with CRA vulnerability reporting requirements in identifying actively exploited vulnerabilities, and/or severe incidents, support preparation of regulatory reports and notifications, participate in readiness exercises and process testing
- Threat Intelligence & Monitoring: Monitor vulnerability databases and threat intelligence sources, assess emerging vulnerabilities impacting Lenovo products, participate in coordinated industry disclosures, evaluate supplier and third-party vulnerability notifications
- Metrics & Continuous Improvement: Develop vulnerability management metrics and reporting, identify process and tool improvement opportunities, support automation initiatives for triage and case management, contribute to playbooks, SOPs, and governance documentation
Qualifications:
- Bachelor’s degree in Cybersecurity, Information Systems, Systems Engineering, Law, or a highly related technical discipline preferred
- 5+ years of applied experience in cybersecurity, software engineering, product security, enterprise risk, or regulatory compliance roles, preferably in a team lead capacity
- Proven capability in security operations, incident response, vulnerability analysis, and/or threat intelligence
- Exceptional written and verbal communication skills
- Availability to support critical audit cycles during business hours with occasional off-hours engagement; Intermittent travel required for regulatory assessments and stakeholder alignment
- Previous PSIRT experience
- Experience interacting with external researchers, CERTs, regulators, and industry consortiums
- Experience handling AI-related vulnerabilities and/or incidents
Basic Requirements:
- Bachelor's degree or equivalent experience
- 5+ years of experience in cybersecurity, software engineering, product security, enterprise risk, and/or regulatory compliance
#LI-MM5
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.
PAY TRANSPARENCY
The anticipated annual compensation range for this position is 127,100–194,925 USD. Final compensation will be based on relevant experience, skills, and business considerations. Individuals may also be considered for bonuses and/or commissions. Lenovo’s various benefits can be found at www.lenovobenefits.com
In compliance with Colorado’s Equal Pay for Equal Work Act (EPEWA), the expected application deadline for this position is 11-30-2026. This requirement applies to both internal and external candidates.
