Cyber Resilience Act Compliance Manager

Lenovo

Farnborough

On-site

GBP 30,000 - 44,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Career development
Performance-based rewards
Hybrid working model (3:2)
Personal days
Additional vacation days
Sick leave compensation
Training and mentoring
Pension contribution
Life insurance

Job summary

Lenovo is seeking a high-agency Manager, CRA Compliance Program to operationalize the EU CRA framework across product and service portfolios. You will bridge regulatory mandates and engineering execution, driving cross-functional work to ensure lifecycle coverage and audit defensibility.

The role requires translating regulatory interpretations into actionable engineering tasks, managing risk, and delivering precise leadership telemetry while meeting strict regulatory deadlines in a hybrid work

Qualifications

  • Bachelor’s degree or higher in a relevant field (Cybersecurity, Information Systems, Engineering, Law)
  • 7–10 years of experience in cybersecurity, product security, enterprise risk, or regulatory compliance
  • Experience applying CRA, NIS2, or ISO/IEC 27001 frameworks to products or services
  • Ability to translate regulatory text into concrete engineering tasks and roadmaps
  • Excellent written and verbal communication bridging legal, engineering and executive stakeholders

Responsibilities

  • Drive EU CRA compliance workstreams across product lifecycles and meet SLAs
  • Coordinate across Product Security, IT, Legal, Privacy, and Supply Chain
  • Architect and maintain CRA documentation with end-to-end traceability
  • Identify CRA risks and propose remediation paths to leadership
  • Lead audit readiness, inquiries, and evidence coordination
  • Convert complex metrics into actionable leadership briefings

Skills

Cybersecurity
Regulatory compliance
CRA/NIS2
ISO27001
Stakeholder management
Documentation

Education

Bachelor’s degree in Cybersecurity or related

Job description

We are Lenovo. We do what we say. We own what we do. We WOW our customers.

Lenovo is a US$83 billion revenue global technology powerhouse, ranked #196 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).

This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.

We are seeking a high-agency Manager, CRA Compliance Program to operationalize the EU Cyber Resilience Act (CRA) framework across our product and service portfolios. Operating within the enterprise security organization, this role bridges the gap between regulatory mandates and engineering execution.

While legal teams define baseline regulatory interpretations, you are strictly accountable for translating these interpretations into continuous operational outcomes. You will drive execution across cross-functional engineering and security teams to ensure precise product lifecycle coverage, applicability, and audit defensibility.

Job Responsibilities
  • Program Operationalization: Drive assigned EU CRA compliance workstreams across product lifecycles. Ensure execution meets strict regulatory deadlines and internal service level agreements (SLAs) while embedding requirements into design, development, and post-market phases.
  • Cross-Functional Alignment: Direct compliance deliverables across Product Security, IT, Legal, Privacy, and Supply Chain. Eliminate operational silos and enforce stakeholder accountability for required evidence.
  • Artifact Engineering Traceability: Architect and maintain defensible CRA documentation, including technical system descriptions and compliance records. Enforce end-to-end traceability between regulatory mandates and implemented controls within the enterprise system of record.
  • Risk Escalation Governance: Identify, document, and quantify CRA-specific technical and operational risks. Formulate risk treatment plans and elevate material blockers to security leadership with proposed remediation paths.
  • Audit Command: Orchestrate audit preparation and evidence coordination. Serve as the primary operational point of contact for CRA regulatory inquiries and transition assigned areas to a state of continuous audit readiness.
  • Executive Telemetry: Synthesize complex compliance metrics into actionable leadership briefings. Deliver precise status updates to drive rapid cross-functional alignment.
Minimum Requirements
  • Education: Bachelor’s degree in Cybersecurity, Information Systems, Systems Engineering, Law, or a highly related technical discipline.
  • Experience: 7 to 10 years of applied experience in cybersecurity, product security, enterprise risk, or regulatory compliance roles.
  • Domain Expertise: Proven capability in executing complex cyber compliance frameworks. Verifiable experience with product-centric regulations (CRA) or major enterprise frameworks (NIS2, ISO/IEC 27001) is required.
  • Execution Capability: Demonstrated ability to manage complex, multi-stakeholder initiatives and translate abstract regulatory text into discrete, actionable engineering tasks.
  • Communication Mastery: Exceptional written and verbal communication skills. Capable of bridging the lexicon gap between legal, engineering, and executive stakeholders.
Preferred Requirements
  • Professional Certifications: Active professional credentials such as CISSP, CISM, CISA, or ISO/IEC 27001 Lead Implementer.
  • Operational Flexibility: Availability to support critical audit cycles during business hours with occasional off-hours engagement. Intermittent travel is required for regulatory assessments and stakeholder alignment.
What Lenovo Can Offer You
  • Opportunities for career development growth
  • Performance based rewards
  • Hybrid working model (3:2)
  • Up to 3 paid Personal Days annually
  • Additional vacation days
  • 100% sick leave compensation up to 2 months per year
  • A broad selection of soft / hard skills trainings and individual mentoring
  • Employer contribution to the Third Pillar Pension System
  • Life life events insurance, fully covered by company

The anticipated initial gross base monthly salary range for this position in Slovakia is 3,150 EUR – 4,620 EUR, depending on experience + variable part 12% of your annual earnings.

We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Compliance Advisor
Cybersecurity Compliance Advisor

Lenovo • Farnborough

On-site
GBP 70,000 - 110,000
Employee Assistance Program
Diversity focus
Training platform
Cyber Security Manager
Cyber Security Manager

Lenovo • Farnborough

On-site
GBP 32,000 - 43,000
Gender Diversity
Employee Assistance Program
Sustainable solutions initiatives
+1
Operational Security Manager
Operational Security Manager

Lenovo • Farnborough

On-site
GBP 80,000 - 120,000
EAP
Training platform
Sustainability initiatives
+1
EU CRA Compliance Manager: Cyber Resilience for Products
EU CRA Compliance Manager: Cyber Resilience for Products

Lenovo • Farnborough

Hybrid
GBP 30,000 - 44,000
Career development
Performance-based rewards
Hybrid working model (3:2)
+6
Senior Manager, Europe Strategic Retail Accounts
Senior Manager, Europe Strategic Retail Accounts

Lenovo • Farnborough

On-site
GBP 90,000 - 140,000
Holiday purchase
Private medical
Life insurance
+4
Advisory Engineer, AI Governance and Product Security
Advisory Engineer, AI Governance and Product Security

Lenovo • Farnborough

On-site
GBP 110,000 - 150,000
Holiday purchase
Private medical
Life insurance
+2
Client Manager - Financial Services, UK and Ireland
Client Manager - Financial Services, UK and Ireland

Lenovo • Farnborough

On-site
GBP 70,000 - 100,000
Holiday purchase
Private medical
Income protection
+12
Advisory Engineer, AI and Product Security
Advisory Engineer, AI and Product Security

Lenovo • Farnborough

On-site
GBP 120,000 - 170,000
Holiday purchase
Private medical
Income protection
+8
Sr. Legal Counsel SSG (Europe and META)
Sr. Legal Counsel SSG (Europe and META)

Lenovo • Farnborough

On-site
GBP 120,000 - 160,000
Holiday purchase
Private medical
Income protection
+2
Field Technical Consultant
Field Technical Consultant

Lenovo • Farnborough

On-site
GBP 55,000 - 90,000
Holiday purchase
Private medical
Income protection
+9