Cyber Resilience Act Compliance Manager

Lenovo

Warszawa

On-site

PLN 152,000 - 222,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid working model (3:2)
Personal days
Vacation days
Sick leave compensation

Job summary

Lenovo is seeking a high-agency Manager, CRA Compliance Program to operationalize the EU Cyber Resilience Act framework across product and service portfolios. You will translate regulatory interpretations into actionable engineering tasks, drive cross-functional execution, and ensure audit-ready processes within the enterprise security organization.

Requirements include 7–10 years in cyber compliance, and a track record with CRA or major enterprise frameworks.

Qualifications

  • Bachelor’s degree in Cybersecurity, Information Systems, Systems Engineering, Law, or a related field.
  • Experience in cybersecurity, product security, enterprise risk, or regulatory compliance roles (7–10 years).
  • Proven ability to translate regulatory text into actionable engineering tasks.
  • Experience with CRA, NIS2, ISO/IEC 27001 or similar frameworks.
  • Excellent written and verbal communication, bridging legal, engineering, and executive stakeholders.

Responsibilities

  • Drive EU CRA compliance workstreams across product lifecycles and meet SLA deadlines.
  • Coordinate with Product Security, IT, Legal, Privacy, and Supply Chain to align compliance deliverables.
  • Architect and maintain CRA documentation and ensure end-to-end traceability.
  • Identify CRA-specific risks and develop remediation plans.
  • Lead audit preparation and act as primary CRA inquiries contact; ensure continuous audit readiness.
  • Synthesize compliance metrics into leadership briefings.

Skills

Regulatory compliance
Cross-functional collaboration
Regulatory interpretation
Communications

Education

Bachelor’s degree in Cybersecurity or related field

Tools

Documentation management

Job description

We are Lenovo. We do what we say. We own what we do. We WOW our customers.

Lenovo is a US$83 billion revenue global technology powerhouse, ranked #196 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).

This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.

We are seeking a high-agency Manager, CRA Compliance Program to operationalize the EU Cyber Resilience Act (CRA) framework across our product and service portfolios. Operating within the enterprise security organization, this role bridges the gap between regulatory mandates and engineering execution.

While legal teams define baseline regulatory interpretations, you are strictly accountable for translating these interpretations into continuous operational outcomes. You will drive execution across cross-functional engineering and security teams to ensure precise product lifecycle coverage, applicability, and audit defensibility.

Job Responsibilities
  • Program Operationalization: Drive assigned EU CRA compliance workstreams across product lifecycles. Ensure execution meets strict regulatory deadlines and internal service level agreements (SLAs) while embedding requirements into design, development, and post-market phases.
  • Cross-Functional Alignment: Direct compliance deliverables across Product Security, IT, Legal, Privacy, and Supply Chain. Eliminate operational silos and enforce stakeholder accountability for required evidence.
  • Artifact Engineering Traceability: Architect and maintain defensible CRA documentation, including technical system descriptions and compliance records. Enforce end-to-end traceability between regulatory mandates and implemented controls within the enterprise system of record.
  • Risk Escalation Governance: Identify, document, and quantify CRA-specific technical and operational risks. Formulate risk treatment plans and elevate material blockers to security leadership with proposed remediation paths.
  • Audit Command: Orchestrate audit preparation and evidence coordination. Serve as the primary operational point of contact for CRA regulatory inquiries and transition assigned areas to a state of continuous audit readiness.
  • Executive Telemetry: Synthesize complex compliance metrics into actionable leadership briefings. Deliver precise status updates to drive rapid cross-functional alignment.
Minimum Requirements
  • Education: Bachelor’s degree in Cybersecurity, Information Systems, Systems Engineering, Law, or a highly related technical discipline.
  • Experience: 7 to 10 years of applied experience in cybersecurity, product security, enterprise risk, or regulatory compliance roles.
  • Domain Expertise: Proven capability in executing complex cyber compliance frameworks. Verifiable experience with product-centric regulations (CRA) or major enterprise frameworks (NIS2, ISO/IEC 27001) is required.
  • Execution Capability: Demonstrated ability to manage complex, multi-stakeholder initiatives and translate abstract regulatory text into discrete, actionable engineering tasks.
  • Communication Mastery: Exceptional written and verbal communication skills. Capable of bridging the lexicon gap between legal, engineering, and executive stakeholders.
Preferred Requirements
  • Professional Certifications: Active professional credentials such as CISSP, CISM, CISA, or ISO/IEC 27001 Lead Implementer.
  • Operational Flexibility: Availability to support critical audit cycles during business hours with occasional off-hours engagement. Intermittent travel is required for regulatory assessments and stakeholder alignment.
What Lenovo Can Offer You
  • Opportunities for career development growth
  • Performance based rewards
  • Hybrid working model (3:2)
  • Up to 3 paid Personal Days annually
  • Additional vacation days
  • 100% sick leave compensation up to 2 months per year
  • A broad selection of soft / hard skills trainings and individual mentoring
  • Employer contribution to the Third Pillar Pension System
  • Life life events insurance, fully covered by company

The anticipated initial gross base monthly salary range for this position in Slovakia is 3,150 EUR – 4,620 EUR, depending on experience + variable part 12% of your annual earnings.

We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CRA Compliance Lead: Cyber Risk & Audit Readiness
CRA Compliance Lead: Cyber Risk & Audit Readiness

Lenovo • Warszawa

Hybrid
PLN 152,000 - 222,000
Hybrid working model (3:2)
Personal days
Vacation days
+1
CRA Compliance Engineer (f/m/x)
CRA Compliance Engineer (f/m/x)

Sii Poland • Toruń

On-site
PLN 150,000 - 240,000
Great Place to Work
Solid financial situation
Contracts with the biggest brands
+9
Senior Associate, Legal - Privacy
Senior Associate, Legal - Privacy

Lenovo • Warszawa

On-site
PLN 60,000 - 80,000
Life Insurance
Private Medical Insurance
Pension Plan
+3
CRA Compliance Engineer (f/m/x)
CRA Compliance Engineer (f/m/x)

Sii Poland • Województwo pomorskie

On-site
PLN 120,000 - 200,000
Great Place to Work
Centre of internal trainings
Profit sharing
+1
CRA Compliance Engineer (f/m/x)
CRA Compliance Engineer (f/m/x)

Sii Poland • Katowice

On-site
PLN 120,000 - 180,000
Great Place to Work
Profit sharing
Medical care
+2
CRA Compliance Engineer (f/m/x)
CRA Compliance Engineer (f/m/x)

Sii Poland • Piła

On-site
PLN 120,000 - 180,000
Great Place to Work
Solid financial situation
Contracts with the biggest brands
+9
Consent and Preference Management Platform -Service/Product Owner (m/f/d)
Consent and Preference Management Platform -Service/Product Owner (m/f/d)

Siemens Healthineers • Warszawa

Hybrid
PLN 109,000 - 131,000
Hybrid work – telework + office
Flexible working hours
Sick days
+4
CRA Compliance Engineer (f/m/x)
CRA Compliance Engineer (f/m/x)

Sii Poland • Szczecin

On-site
PLN 120,000 - 180,000
Great Place to Work
Solid financial situation
Contracts with the biggest brands
+9
CRA Compliance Engineer (f/m/x)
CRA Compliance Engineer (f/m/x)

Sii Poland • Lublin

On-site
PLN 110,000 - 170,000
Great Place to Work
Solid financial situation
Contracts with the biggest brands
+9
CRA Compliance Engineer (f/m/x)
CRA Compliance Engineer (f/m/x)

Sii Poland • Bydgoszcz

On-site
PLN 150,000 - 210,000
Great Place to Work
Internal trainings
Medical care
+2