Technology Internal Audit Project Manager
Why Work at Lenovo
We are Lenovo. We do what we say. We own what we do. We WOW our customers.
Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).
This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.
Description and Requirements
Lenovo is a global technology leader focused on delivering Smarter Technology for All. As Lenovo advances its Hybrid AI strategy and transformation toward an AI-native company, Internal Audit plays a critical role in strengthening enterprise resilience, providing trusted assurance, and delivering forward-looking risk insight.
This position is designed for an experienced audit leader with strong technology risk expertise, business acumen, project leadership, and stakeholder influence. The individual is accountable for the full audit lifecycle, including risk assessment, scope decisions, team leadership, quality, stakeholder alignment, and timely delivery of business-relevant insights.
Project Management & Technical Capabilities
- Lead complex technology and integrated audits from pre-planning through report publication and closure, with clear accountability for scope, quality, timeliness, team utilization, and stakeholder experience.
- Develop a well-supported risk assessment and audit approach that considers Lenovo's strategy, enterprise risks, stakeholder perspectives, prior assurance results, relevant data, and external developments.
- Define and manage a risk-based scope throughout the engagement, making timely and well-judged adjustments when risks, circumstances, or available evidence change.
- Ensure the team appropriately evaluates the design and operating effectiveness of technology controls relevant to the audit objectives and scope.
- Establish and manage an efficient project plan, allocate work appropriately, monitor progress, resolve dependencies, and escalate matters that may affect scope, quality, or delivery.
- Use data analytics, automation, and approved AI-enabled tools to improve audit coverage, efficiency, documentation quality, and insight generation while complying with Lenovo requirements for security, confidentiality, responsible AI, and professional judgment.
- Review workpapers and draft results to ensure that evidence is sufficient, conclusions are balanced and supportable, and communication is clear and proportionate. Produce leadership-review-ready draft reports requiring minimal revision.
- Drive continuous improvement through post-engagement lessons learned, reusable approaches, knowledge sharing, and practice-based coaching.
Communication & Collaboration
- Manage relationships with mid-to-senior technology and business stakeholders, adapting communication to the audience and positioning audit insights in a concise, business-relevant manner.
- Lead key engagement meetings and communicate scope decisions, emerging risks, evidence gaps, and conclusions with confidence, clarity, objectivity, and professional skepticism.
- Influence constructive outcomes without compromising independence. Resolve disagreement through evidence, risk judgment, and pragmatic discussion, and escalate significant matters promptly.
- Build effective collaboration across general audit, technical audit, data enablement, enterprise risk management, investigations, external audit, and co-source specialists.
Business Acumen
- Maintain strong knowledge of Lenovo's strategy, Hybrid AI priorities, operating model, products, services, enterprise systems, transformation agenda, and relevant external technology and regulatory trends.
- Connect technical findings to enterprise outcomes such as resilience, security, trust, regulatory compliance, customer experience, operational performance, financial reporting, and execution of strategic initiatives.
- Apply professional judgment to balance risk coverage, available capacity, technical complexity, and expected assurance value.
- Evaluate proposed actions for risk reduction, sustainability, ownership, feasibility, and cost-benefit.
- Identify opportunities for advisory insight, benchmarking, innovation, or scalable assurance while maintaining clarity between assurance and advisory responsibilities.
Contribution / Leadership
- Provide clear direction, role expectations, and timely coaching to project team members. Match assignments to development needs while ensuring appropriate oversight and challenge.
- Take accountability for project deliverables, workpaper quality, report readiness, and development of less experienced auditors.
- Build team capability in risk-based auditing, technology risk, data analytics, emerging risks, professional judgment, and effective communication.
- Anticipate project risks, make timely decisions, adapt the plan, and maintain momentum in ambiguous or changing circumstances.
- Model Lenovo values, applicable professional standards, ethical behavior, independence, objectivity, discretion, and accountability.
POSITION REQUIREMENTS
- University degree in Information Systems, Computer Science, Cybersecurity, Artificial Intelligence, or a related discipline. An advanced degree is a plus.
- 5 to 8 years of relevant experience in internal audit, external audit, technology risk, cybersecurity, IT general controls (ITGC) and IT application controls (ITAC), system implementation assurance, or a related field, including at least 3 years leading complex audit projects or comparable assurance engagements.
- Demonstrated full-lifecycle project management experience, including risk assessment, scope management, resource planning, milestone management, quality review, stakeholder alignment, and reporting.
- Broad and strong knowledge of technology risk and controls across areas such as IT governance, cybersecurity, infrastructure, applications, cloud, data, AI and emerging technology, system development and implementation, and technology-enabled business processes.
- Experience with enterprise platforms such as SAP S/4HANA, SAP BPC, cloud platforms, identity and access management tools, or other major business systems is preferred.
- Flexibility and demonstrated capability to manage integrated and general audits across business areas such as sales, marketing, procurement, supply chain, finance, and human resources, based on audit-plan priorities, and resource needs.
- Demonstrated use of data analytics and visualization tools such as Power BI, Excel, SQL, Python, or comparable tools is preferred. Ability to identify responsible and value-adding uses of approved AI-enabled audit tools is preferred.
- Excellent analytical, writing, presentation, negotiation, and stakeholder-influence skills, including the ability to communicate complex technical risks to executive and non-technical audiences.
- Experience in a global, matrixed, high-technology, manufacturing, services, telecommunications, or similarly complex environment is preferred. Big Four or comparable professional-services experience is preferred.
- Fluency in English, including writing, speaking, and reading, is required. Additional language capability is preferred based on location and audit coverage.
- Ability to travel approximately 20%, subject to business needs.
- Preferred certifications include CISA, CISSP, CISM, CIA, CFE, PMP, cloud-security certifications, data or AI-related certifications, or equivalent credentials.

