Manager, Security Risk Controls

Lenovo

Morrisville

On-site

CAD 180,000 - 276,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Lenovo in Morrisville, NC, is looking for a Manager, Security Controls Management to lead the enterprise security controls program. You will own control lifecycle, governance, documentation, evidence, and audit readiness while partnering with security, risk, compliance, privacy, and audit teams.

This role emphasizes cross-functional influence over process improvements, control ownership, and measurable program health through KPIs and KRIs.

Qualifications

  • Bachelor's degree in cybersecurity, information systems, information technology, business, or engineering.
  • 7+ years of experience in cybersecurity, governance, risk, compliance, internal controls, or audit.
  • Experience managing security controls and governance programs.
  • Experience supporting audits, assessments, and remediation activities.

Responsibilities

  • Own and manage the lifecycle of security controls, including definition, implementation, maintenance, review, and retirement.
  • Establish and maintain a centralized inventory of security controls and associated documentation.
  • Ensure security controls remain aligned with security requirements, policies, standards, and regulatory obligations.
  • Define and maintain control ownership, accountability, and governance processes.
  • Drive continuous improvement of the security controls framework and supporting methodologies.
  • Lead continuous improvement initiatives that enhance governance, reporting, and control maturity.
  • Assess control design and operating effectiveness to ensure objectives are met.

Skills

Cybersecurity
Security governance
Risk management
Compliance
Internal controls
Audit

Education

Bachelor's degree in related field

Job description

* United States of America - North Carolina - Morrisville

Why Work at Lenovo

We are Lenovo. We do what we say. We own what we do. We WOW our customers.

Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).

This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com , and read about the latest news via our StoryHub .

Description and Requirements

The Manager, Security Controls Management is responsible for the execution, governance, assurance, and continuous improvement of the enterprise security controls program. This role serves as the process owner for security controls, ensuring controls are defined, documented, implemented, measured, and maintained consistently across the organization.

Operating as an individual contributor and process leader, this role partners closely with Security, Risk, Compliance, Internal Audit, Privacy, and business stakeholders to drive effective control management practices. The Manager is accountable for the health and maturity of the security controls program, including control lifecycle management, control effectiveness validation, issue remediation tracking, and audit readiness.

This position does not have direct people management responsibilities but requires strong leadership through influence, coordination, and stakeholder engagement across multiple functions.

Key Responsibilities:

Security Controls Governance & Management

  • Own and manage the lifecycle of security controls, including control definition, implementation, maintenance, review, and retirement.
  • Establish and maintain a centralized inventory of security controls and associated control documentation.
  • Ensure security controls remain aligned with corporate security requirements, policies, standards, and regulatory obligations.
  • Define and maintain control ownership, accountability, and governance processes.
  • Drive continuous improvement of the security controls framework and supporting methodologies.
  • Lead continuous improvement initiatives that enhance governance, standardization, reporting, and overall control maturity.
  • Partner with control owners and subject matter experts to establish scalable, risk-based security controls that support evolving business, regulatory, and security requirements.
  • Assess control design and operating effectiveness to ensure intended objectives are achieved.
  • Identify control gaps, weaknesses, and opportunities for improvement.
  • Coordinate periodic control reviews and validation activities.
  • Support development of compensating controls when necessary to address identified risks or operational constraints.

Cross-Functional Coordination

  • Collaborate with various security teams, Risk Management, Compliance, Privacy, and Internal Audit teams to ensure consistent control implementation and operation.
  • Facilitate discussions regarding control ownership, responsibilities, remediation activities, and control performance.
  • Coordinate control-related initiatives across multiple stakeholders and business functions.
  • Drive accountability for completion of control-related deliverables and commitments.
  • Build trusted partnerships across security, compliance, privacy, audit, and business organizations to drive governance, accountability, and successful execution of security assurance activities.

Documentation & Evidence Management

  • Ensure security control documentation is accurate, complete, and maintained within designated systems of record.
  • Maintain traceability between security requirements, controls, procedures, and supporting evidence.
  • Establish documentation standards to support consistency, audit readiness, and operational effectiveness.
  • Validate the quality and completeness of evidence supporting control operation.
  • Support the development and maintenance of control narratives, procedures, standards, and process documentation.
  • Establish documentation and evidence management practices that support repeatable assurance activities and audit readiness.
  • Identify, document, and track control deficiencies, gaps, and improvement opportunities.
  • Partner with stakeholders to develop remediation plans and corrective actions.
  • Monitor remediation progress and elevate issues that may impact control effectiveness or compliance obligations.
  • Assess the potential risk impact associated with identified control weaknesses.
  • Support risk acceptance and exception management processes when applicable.
  • Prioritize remediation efforts based on risk and provide governance oversight to ensure timely resolution of control deficiencies.
  • Develop and maintain key performance indicators (KPIs) and key risk indicators (KRIs) for the security controls program that measure program health.
  • Establish reporting that provides meaningful visibility into governance assurance, compliance initiatives, remediation progress, and overall program health.
  • Analyze program data and trends to identify improvement opportunities.
  • Provide regular status reporting and executive-level program updates.
  • Drive initiatives that improve efficiency, automation, and overall control maturity.

Assessment Support

  • Support internal and external audits by facilitating evidence collection and validating control documentation.
  • Coordinate responses to assessment findings and recommendations.
  • Maintain the enterprise security assurance posture through ongoing assessment and remediation tracking.
  • Support regulatory, customer, and third-party assessments involving security controls.

Basic Qualifications:

  • Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Business, Engineering, or a related field.
  • 7+ years of experience in cybersecurity, security governance, risk management, compliance, internal controls, audit, or related disciplines.
  • Demonstrated experience managing security controls, control frameworks, or governance programs.
  • Experience supporting audits, assessments, and remediation activities.

The Manager, Security Controls Management is responsible for the execution, governance, assurance, and continuous improvement of the enterprise security controls program. This role serves as the process owner for security controls, ensuring controls are defined, documented, implemented, measured, and maintained consistently across the organization.

Operating as an individual contributor and process leader, this role partners closely with Security, Risk, Compliance, Internal Audit, Privacy, and business stakeholders to drive effective control management practices. The Manager is accountable for the health and maturity of the security controls program, including control lifecycle management, control effectiveness validation, issue remediation tracking, and audit readiness.

This position does not have direct people management responsibilities but requires strong leadership through influence, coordination, and stakeholder engagement across multiple functions.

Key Responsibilities:

Security Controls Governance & Management

  • Own and manage the lifecycle of security controls, including control definition, implementation, maintenance, review, and retirement.
  • Establish and maintain a centralized inventory of security controls and associated control documentation.
  • Ensure security controls remain aligned with corporate security requirements, policies, standards, and regulatory obligations.
  • Define and maintain control ownership, accountability, and governance processes.
  • Drive continuous improvement of the security controls framework and supporting methodologies.
  • Lead continuous improvement initiatives that enhance governance, standardization, reporting, and overall control maturity.

Control Design & Effectiveness

  • Partner with control owners and subject matter experts to establish scalable, risk-based security controls that support evolving business, regulatory, and security requirements.
  • Assess control design and operating effectiveness to ensure intended objectives are achieved.
  • Identify control gaps, weaknesses, and opportunities for improvement.
  • Coordinate periodic control reviews and validation activities.
  • Support development of compensating controls when necessary to address identified risks or operational constraints.

Cross-Functional Coordination

  • Collaborate with various security teams, Risk Management, Compliance, Privacy, and Internal Audit teams to ensure consistent control implementation and operation.
  • Facilitate discussions regarding control ownership, responsibilities, remediation activities, and control performance.
  • Coordinate control-related initiatives across multiple stakeholders and business functions.
  • Drive accountability for completion of control-related deliverables and commitments.
  • Build trusted partnerships across security, compliance, privacy, audit, and business organizations to drive governance, accountability, and successful execution of security assurance activities.

Documentation & Evidence Management

  • Ensure security control documentation is accurate, complete, and maintained within designated systems of record.
  • Maintain traceability between security requirements, controls, procedures, and supporting evidence.
  • Establish documentation standards to support consistency, audit readiness, and operational effectiveness.
  • Validate the quality and completeness of evidence supporting control operation.
  • Support the development and maintenance of control narratives, procedures, standards, and process documentation.
  • Establish documentation and evidence management practices that support repeatable assurance activities and audit readiness.

Issue, Risk & Remediation Management

  • Identify, document, and track control deficiencies, gaps, and improvement opportunities.
  • Partner with stakeholders to develop remediation plans and corrective actions.
  • Monitor remediation progress and elevate issues that may impact control effectiveness or compliance obligations.
  • Assess the potential risk impact associated with identified control weaknesses.
  • Support risk acceptance and exception management processes when applicable.
  • Prioritize remediation efforts based on risk and provide governance oversight to ensure timely resolution of control deficiencies.

Metrics, Reporting & Continuous Improvement

  • Develop and maintain key performance indicators (KPIs) and key risk indicators (KRIs) for the security controls program that measure program health.
  • Establish reporting that provides meaningful visibility into governance assurance, compliance initiatives, remediation progress, and overall program health.
  • Analyze program data and trends to identify improvement opportunities.
  • Provide regular status reporting and executive-level program updates.
  • Drive initiatives that improve efficiency, automation, and overall control maturity.

Assessment Support

  • Support internal and external audits by facilitating evidence collection and validating control documentation.
  • Coordinate responses to assessment findings and recommendations.
  • Maintain the enterprise security assurance posture through ongoing assessment and remediation tracking.
  • Support regulatory, customer, and third-party assessments involving security controls.

Basic Qualifications:

  • Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Business, Engineering, or a related field.
  • 7+ years of experience in cybersecurity, security governance, risk management, compliance, internal controls, audit, or related disciplines.
  • Demonstrated experience managing security controls, control frameworks, or governance programs.
  • Experience supporting audits, assessments, and remediation activities.
Preferred Qualifications:
  • Relevant certifications such as CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer, or similar.
  • Strong knowledge of cybersecurity controls, governance, and risk management principles.
  • Experience managing security control frameworks and control lifecycle processes.
  • Strong understanding of security standards and frameworks such as ISO 27001, NIST CSF, NIST 800-53, or similar.
  • Ability to assess control design and operating effectiveness.
  • Demonstrated ability to lead enterprise governance and security assurance initiatives through cross-functional collaboration and influence.
  • Strong organizational and program management skills.
  • Experience coordinating cross-functional initiatives in matrixed environments.
  • Strong analytical and problem-solving capabilities.
  • Ability to influence stakeholders and drive accountability without direct authority.
  • Excellent written, verbal, and presentation skills.
  • Experience developing metrics, reporting, and executive-level communications.
  • Limited travel may be required for business, audit, or stakeholder engagements.

In compliance with Colorado's EPEWA, the expected application deadline for this position is August 27, 2027. This applies to both external and internal candidates.

#LI-FL1

#LI-Remote

We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.

Additional Locations: * United States of America - North Carolina - Morrisville

PAY TRANSPARENCY

The anticipated annual compensation range for this position is127,100–194,925 USD. Final compensation will be based on relevant experience, skills, and business considerations. Individuals may also be considered for bonuses and/or commissions. Lenovo’s various benefits can be found at www.lenovobenefits.com

In compliance with Colorado’s Equal Pay for Equal Work Act (EPEWA), the expected application deadline for this position is 08-27-2027. This requirement applies to both internal and external candidates.

If you require an accommodation to complete this application, please contact ability@lenovo.com

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Manager, Cyber Resilience Act Compliance
Sr. Manager, Cyber Resilience Act Compliance

Lenovo • Morrisville

On-site
CAD 224,000 - 344,000
Chief of Staff
Chief of Staff

Lenovo • Morrisville

On-site
CAD 195,000 - 298,000
Financial Analyst
Financial Analyst

Lenovo • Morrisville

Hybrid
CAD 92,000 - 128,000
AI Strategy Manager
AI Strategy Manager

Lenovo • Morrisville

On-site
CAD 212,000 - 325,000
Sr. Mgr., Tools Strategy & Execution
Sr. Mgr., Tools Strategy & Execution

Lenovo • Morrisville

On-site
CAD 199,000 - 298,000
Senior Program Manager
Senior Program Manager

Lenovo • Morrisville

On-site
CAD 154,000 - 237,000
ESMB Strategy & Operations, Sr. Manager
ESMB Strategy & Operations, Sr. Manager

Lenovo • Morrisville

On-site
CAD 170,000 - 226,000
Sustainability & Product Services Finance Lead
Sustainability & Product Services Finance Lead

Lenovo • Morrisville

On-site
CAD 153,000 - 237,000
Forward Deployed Engineer
Forward Deployed Engineer

Lenovo • Morrisville

Remote
CAD 216,000 - 331,000
Remote work
Hybrid schedule
Technology Strategy Senior Manager
Technology Strategy Senior Manager

Lenovo • Morrisville

On-site
CAD 209,000 - 264,000