Advisory Engineer, Enterprise Product Security Incident Response Team (E-PSIRT)

Lenovo

Morrisville (NC)

On-site

USD 127,000 - 195,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Lenovo is seeking a Product Security Advisory Engineer in the Enterprise Product Security Incident Response Team (E-PSIRT) to assess, triage, coordinate, and track vulnerabilities across Lenovo's global product portfolio.

This role acts as the central orchestrator for vulnerability activities, coordinating security offices, engineering teams, suppliers, and stakeholders to ensure timely remediation, disclosure, and regulatory reporting.

Qualifications

  • Bachelor's degree or equivalent in a technical field.
  • 5+ years in cybersecurity, product security, or related roles.
  • Experience with vulnerability management and regulatory reporting.

Responsibilities

  • Assess vulnerabilities, triage incidents, and coordinate investigations
  • Manage PSIRT cases from intake to closure and track remediation
  • Coordinate with security offices, engineering teams, suppliers, and stakeholders
  • Support CRA compliance activities and regulatory reporting readiness
  • Develop advisories, publish mitigation guidance, and communicate with customers

Skills

Cybersecurity
Security operations
Incident response
Threat intelligence
Communication skills
Regulatory compliance
Collaboration

Education

Bachelor's degree in cybersecurity or related field

Job description

General Information
  • Req # WD00104875
  • Career area: Information Technology
  • Country/Region: United States of America
  • State: North Carolina
  • City: Morrisville
  • Date: Friday, September 4, 2026
  • Working time: Full-time
  • Additional Locations: United States of America - North Carolina - Morrisville
Why Work at Lenovo

We are Lenovo. We do what we say. We own what we do. We WOW our customers.

Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world's largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo's continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).

This transformation together with Lenovo's world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.

Description and Requirements

The Product Security Advisory Engineer of Lenovo's Enterprise Product Security Incident Response Team (E-PSIRT) is responsible for assessing, triaging, coordinating, and tracking product security vulnerabilities and incidents across Lenovo's global product portfolio.

This role functions as the central operational orchestrator for product vulnerability activities, coordinating product security offices, engineering teams, suppliers, and other stakeholders to ensure vulnerabilities are appropriately evaluated, prioritized, remediated, disclosed and reported. The position will play a critical role in supporting Lenovo's Cyber Resilience Act (CRA) compliance program, including vulnerability reporting readiness and regulatory response activities. Lenovo's E-PSIRT responsibilities include vulnerability intake, triage, workflow management, coordination, impact assessment, reporting, disclosure tracking, technical advisory writing, and support for notification activities.

Core Day-to-Day Operations
  • Liaison with internal and external stakeholders, including Lenovo business units and third-party upstream and downstream suppliers, to coordinate vulnerability response and remediation activities
  • Collaborate and negotiate with suppliers, technology partners, and security researchers to triage vulnerabilities, develop remediation plans, and coordinate responsible disclosure activities
  • Develop, review, and publish security advisories, communicating available fixes, workarounds, and mitigation strategies for identified vulnerabilities
  • Draft and issue customer-facing security communications and advisories, ensuring timely dissemination of mitigation and remediation guidance
  • Coordinate cross-functional communications to ensure accurate, consistent, and timely messaging related to security vulnerabilities and product security issues
Key Responsibilities
  • Vulnerability Assessment & Triage: Assess product security vulnerabilities, exploits, and incidents from: researchers, customers, suppliers, threat intelligence feeds, public disclosures, CERTs, and internal testing
    • Perform technical analysis and risk evaluation
    • Validate business impact
    • Determine vulnerability severity and likelihood
  • PSIRT Case Management: Manage vulnerability cases from intake through closure, coordinate technical investigations across product security offices and engineering teams, track remediation progress and disclosure milestones
  • Central Orchestration: Serve as the operational coordinator across Product Security Offices within IDG, ISG, SSG, Motorola, CAIO, Legal, and other business groups
  • Cyber Resilience Act (CRA) Support: Assist with CRA vulnerability reporting requirements in identifying actively exploited vulnerabilities, and/or severe incidents, support preparation of regulatory reports and notifications, participate in readiness exercises and process testing
  • Threat Intelligence & Monitoring: Monitor vulnerability databases and threat intelligence sources, assess emerging vulnerabilities impacting Lenovo products, participate in coordinated industry disclosures, evaluate supplier and third-party vulnerability notifications
  • Metrics & Continuous Improvement: Develop vulnerability management metrics and reporting, identify process and tool improvement opportunities, support automation initiatives for triage and case management, contribute to playbooks, SOPs, and governance documentation
Qualifications
  • Bachelor's degree in Cybersecurity, Information Systems, Systems Engineering, Law, or a highly related technical discipline preferred
  • 5+ years of applied experience in cybersecurity, software engineering, product security, enterprise risk, or regulatory compliance roles, preferably in a team lead capacity
  • Proven capability in security operations, incident response, vulnerability analysis, and/or threat intelligence
  • Exceptional written and verbal communication skills
  • Availability to support critical audit cycles during business hours with occasional off-hours engagement; Intermittent travel required for regulatory assessments and stakeholder alignment
  • Previous PSIRT experience
  • Experience interacting with external researchers, CERTs, regulators, and industry consortiums
  • Experience handling AI-related vulnerabilities and/or incidents
Basic Requirements
  • Bachelor's degree or equivalent experience
  • 5+ years of experience in cybersecurity, software engineering, product security, enterprise risk, and/or regulatory compliance

#LI-MM5

Equal Opportunity Statement

We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.

Additional Locations
  • United States of America
  • United States of America - North Carolina
  • United States of America - North Carolina - Morrisville
PAY TRANSPARENCY

The anticipated annual compensation range for this position is 127,100-194,925 USD. Final compensation will be based on relevant experience, skills, and business considerations. Individuals may also be considered for bonuses and/or commissions. Lenovo's various benefits can be found at www.lenovobenefits.com

In compliance with Colorado's Equal Pay for Equal Work Act (EPEWA), the expected application deadline for this position is 11-30-2026. This requirement applies to both internal and external candidates.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Program Manager, Enterprise Product Security Incident Response Team (E-PSIRT)
Sr. Program Manager, Enterprise Product Security Incident Response Team (E-PSIRT)

Lenovo • Morrisville (NC)

On-site
USD 161,000 - 246,000
Advisory Engineer, Enterprise Product Security Incident Response Team (E-PSIRT)
Advisory Engineer, Enterprise Product Security Incident Response Team (E-PSIRT)

Lenovo • North Carolina

On-site
USD 120,000 - 150,000
Sr. Program Manager, Enterprise Product Security Incident Response Team (E-PSIRT)
Sr. Program Manager, Enterprise Product Security Incident Response Team (E-PSIRT)

Lenovo • North Carolina

On-site
USD 140,000 - 190,000
Advisory Engineer, AI Security
Advisory Engineer, AI Security

Lenovo • Morrisville (NC)

Hybrid
USD 140,000 - 190,000
Advisory Engineer AI Trust and Safety Operations
Advisory Engineer AI Trust and Safety Operations

Lenovo • Mobile (AL)

Hybrid
USD 120,000 - 180,000
Hybrid work model
Travel opportunities (5-20% domestic/…
Technical Support Engineer - Waukesha, WI
Technical Support Engineer - Waukesha, WI

Lenovo • Morrisville (NC)

Hybrid
USD 73,000 - 112,000
Sr Manager Software Security
Sr Manager Software Security

Lenovo • Raleigh (NC)

On-site
USD 140,000 - 210,000
Sr Software Security Architect
Sr Software Security Architect

Lenovo • Raleigh (NC)

On-site
USD 140,000 - 190,000
Technical Client Advisor
Technical Client Advisor

Lenovo • Morrisville (NC)

On-site
USD 103,000 - 158,000
Senior Enterprise PSIRT Engineer - Vulnerability Response
Senior Enterprise PSIRT Engineer - Vulnerability Response

Lenovo • North Carolina

On-site
USD 120,000 - 150,000