
Senior Product Security Engineer (Cloud Security & DevSecOps)
Why Work at Lenovo
We are Lenovo. We do what we say. We own what we do. We WOW our customers.
Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).
This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.
Description and Requirements
Lenovo is looking for a Senior Product Security Engineer to join our PCSD Product Security team. In this role, you will help drive the secure design, development, and operation of Lenovo's cloud-based products and SaaS offerings, working closely with global Engineering and Product teams.
This position combines Cloud Security, Application Security, DevSecOps, and Secure Architecture, helping ensure security is embedded throughout the entire software development lifecycle.
What you'll do
- Assess and improve the security posture of cloud-based products, applications, APIs, and architectures.
- Perform threat modeling and security design reviews for cloud and SaaS solutions.
- Evaluate authentication, authorization, encryption, and secure communication mechanisms.
- Support and enhance DevSecOps practices and CI/CD security implementations.
- Define and implement cloud security controls including IAM, encryption, logging, monitoring, and incident response.
- Partner with Engineering and Product teams to drive Secure-by-Design and Security-by-Default practices.
- Conduct application security reviews and identify potential security weaknesses before production release.
- Contribute to cloud and product security strategy, training, tooling, and awareness initiatives.
What we're looking for
- 3+ years of experience in Product Security, Application Security, Cloud Security, or DevSecOps.
- Hands-on experience securing cloud environments such as AWS and/or Azure.
- Strong understanding of Secure SDLC, SaaS security, threat modeling, and secure architecture principles.
- Knowledge of authentication and authorization technologies such as OAuth, OpenID Connect, SAML, JWT, and modern identity systems.
- Working knowledge of encryption, PKI, TLS, certificates, and secure communication protocols.
- Familiarity with OWASP principles and common application security risks.
- Strong collaboration, communication, and stakeholder management skills.
- Advanced English is required.
Nice to have
- Experience with SAST, DAST, IAST, SCA, and other DevSecOps security tools.
- Container and Kubernetes security.
- Infrastructure as Code security (Terraform, CloudFormation, Ansible).
- Security certifications such as CISSP, CCSP, CCSK, CSSLP, or Security+.
- Knowledge of GDPR, LGPD, and global privacy regulations.
Work arrangement: Hybrid model with in-office attendance 3 times a week.
Diversity & Inclusion: We are an equal opportunity employer and do not discriminate against any employee or job applicant on the basis of race, color, sex, age, national origin, religion, sexual orientation, gender identity, veteran status, disability, or any other class protected by federal, state, or local law.
