Security Assessor
Why Work at Lenovo
We are Lenovo. We do what we say. We own what we do. We WOW our customers.
Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).
This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.
Description and Requirements
Senior Cyber Security Engineer
Location:Shanghai, China
Job Summary
We are seeking an experienced and highly motivated Senior Cyber Security Engineer to join our security team. This role focuses on Vehicle Cybersecurity, Application Security, Security Assessment, Penetration Testing, and Risk Management. The successful candidate will work closely with product, engineering, architecture, and operations teams to strengthen security throughout the product lifecycle and support secure business growth.
Key Responsibilities
Vehicle Cybersecurity
- Support cybersecurity activities for connected vehicle products, platforms, and related services.
- Participate in security architecture reviews, risk assessments, and security requirement definition.
- Conduct security evaluations and identify potential security risks in vehicle-related systems and services.
- Collaborate with cross-functional teams to improve the security posture of connected products and ecosystems.
- Track industry cybersecurity trends, emerging threats, standards, and regulatory requirements related to vehicle and IoT security.
Application Security
- Perform security assessments for mobile, web, cloud-based, and enterprise applications.
- Collaborate with development teams to promote secure design and secure coding practices.
- Identify application security risks and support remediation throughout the software development lifecycle.
- Review application architectures and provide security recommendations.
- Promote security best practices and contribute to improving overall product security maturity.
Security Assessment & Penetration Testing
- Conduct cybersecurity assessments for products, platforms, applications, and projects.
- Participate in solution reviews, architecture reviews, and security risk evaluations.
- Plan, coordinate, and perform penetration testing activities to identify security vulnerabilities and validate security controls.
- Perform security testing of applications, APIs, cloud services, and connected systems.
- Analyze penetration testing findings and provide actionable remediation recommendations.
- Validate vulnerability fixes and support security verification activities.
- Work with stakeholders to drive timely remediation and risk closure.
Security Governance & Risk Management
- Support vulnerability management and security risk tracking activities.
- Assist in security incident investigation and response activities when required.
- Contribute to the development of security standards, policies, guidelines, and best practices.
- Provide security consultation and technical guidance to business and engineering teams.
- Support compliance initiatives, customer security reviews, and security assurance activities.
- Promote a risk-based approach to security decision-making and governance.
Qualifications
Required
- Bachelor’s degree or above in Cyber Security, Computer Science, Information Technology, or a related field.
- 5+ years of experience in cybersecurity, application security, product security, penetration testing, or a related discipline.
- Strong understanding of cybersecurity principles, risk management, and security controls.
- Experience conducting security assessments, security reviews, or risk evaluations.
- Experience identifying, analyzing, and mitigating security vulnerabilities.
- Strong analytical, communication, and problem-solving skills.
- Ability to work effectively in a cross-functional and global environment.
- Strong stakeholder management and collaboration skills.
- Self-driven with a strong sense of ownership and accountability.
Preferred
- Experience in connected vehicle, automotive, IoT, or intelligent device security.
- Experience in application security, product security, or security architecture.
- Hands-on experience in penetration testing, vulnerability assessment, or offensive security activities.
- Familiarity with common attack techniques, security testing methodologies, and vulnerability validation.
- Experience conducting security assessments for mobile, web, cloud, API, or connected systems.
- Ability to identify security weaknesses and provide practical remediation recommendations.
- Experience in vulnerability management, security consulting, or risk assessment.
- Knowledge of cloud security and secure software development practices.
- Relevant industry certifications such as CISSP, CISP, OSCP, CEH, CISA, or equivalent.
What We Are Looking For
- Strong sense of ownership and accountability.
- Excellent communication and stakeholder management skills.
- Ability to influence and collaborate with technical and non-technical audiences.
- Ability to balance security requirements with business objectives.
- Practical and risk-based mindset toward solving security challenges.
- Passion for cybersecurity, emerging technologies, and continuous learning.

