Advisory Engineer, Enterprise Product Security Incident Response Team (E-PSIRT)

Lenovo

North Carolina

On-site

USD 120,000 - 150,000

Full time

31 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Lenovo is seeking a Product Security Advisory Engineer to join the Enterprise PSIRT, coordinating vulnerability response across Lenovo's global portfolio. You will triage and assess security issues and drive remediation and disclosure.

This role supports CRA compliance, vulnerability reporting readiness, and regulatory response activities, collaborating with engineering, legal, and suppliers. Occasional travel may be required.

Qualifications

  • Bachelor's degree or equivalent in a related field.
  • 5+ years in cybersecurity, software engineering, product security, or regulatory roles.

Responsibilities

  • Assess product security vulnerabilities and incidents from multiple sources.
  • Coordinate investigations and remediation across product security offices and engineering teams.
  • Publish advisories and communicate fixes, workarounds, and mitigations to customers.

Skills

Cybersecurity
Incident response
Threat intelligence
Security operations
Regulatory compliance

Education

Bachelor's degree

Job description

We are Lenovo. We do what we say. We own what we do. We WOW our customers. Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY). This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub. The Product Security Advisory Engineer of Lenovo’s Enterprise Product Security Incident Response Team (E-PSIRT) is responsible for assessing, triaging, coordinating, and tracking product security vulnerabilities and incidents across Lenovo’s global product portfolio. This role functions as the central operational orchestrator for product vulnerability activities, coordinating product security offices, engineering teams, suppliers, and other stakeholders to ensure vulnerabilities are appropriately evaluated, prioritized, remediated, disclosed and reported. The position will play a critical role in supporting Lenovo’s Cyber Resilience Act (CRA) compliance program, including vulnerability reporting readiness and regulatory response activities. Lenovo’s E-PSIRT responsibilities include vulnerability intake, triage, workflow management, coordination, impact assessment, reporting, disclosure tracking, technical advisory writing, and support for notification activities.

Core Day-to-Day Operations
  • Liaison with internal and external stakeholders, including Lenovo business units and third-party upstream and downstream suppliers, to coordinate vulnerability response and remediation activities
  • Collaborate and negotiate with suppliers, technology partners, and security researchers to triage vulnerabilities, develop remediation plans, and coordinate responsible disclosure activities
  • Develop, review, and publish security advisories, communicating available fixes, workarounds, and mitigation strategies for identified vulnerabilities
  • Draft and issue customer-facing security communications and advisories, ensuring timely dissemination of mitigation and remediation guidance
  • Coordinate cross-functional communications to ensure accurate, consistent, and timely messaging related to security vulnerabilities and product security issues
Key Responsibilities
  • Vulnerability Assessment Triage: Assess product security vulnerabilities, exploits, and incidents from: researchers, customers, suppliers, threat intelligence feeds, public disclosures, CERTs, and internal testing
  • Perform technical analysis and risk evaluation
  • Validate business impact
  • Determine vulnerability severity and likelihood
  • PSIRT Case Management: Manage vulnerability cases from intake through closure, coordinate technical investigations across product security offices and engineering teams, track remediation progress and disclosure milestones
  • Central Orchestration: Serve as the operational coordinator across Product Security Offices within IDG, ISG, SSG, Motorola, CAIO, Legal, and other business groups
  • Cyber Resilience Act (CRA) Support: Assist with CRA vulnerability reporting requirements in identifying actively exploited vulnerabilities, and/or severe incidents, support preparation of regulatory reports and notifications, participate in readiness exercises and process testing
  • Threat Intelligence Monitoring: Monitor vulnerability databases and threat intelligence sources, assess emerging vulnerabilities impacting Lenovo products, participate in coordinated industry disclosures, evaluate supplier and third-party vulnerability notifications
  • Metrics Continuous Improvement: Develop vulnerability management metrics and reporting, identify process and tool improvement opportunities, support automation initiatives for triage and case management, contribute to playbooks, SOPs, and governance documentation
Qualifications
  • Bachelor’s degree in Cybersecurity, Information Systems, Systems Engineering, Law, or a highly related technical discipline preferred
  • 5+ years of applied experience in cybersecurity, software engineering, product security, enterprise risk, or regulatory compliance roles, preferably in a team lead capacity
  • Proven capability in security operations, incident response, vulnerability analysis, and/or threat intelligence
  • Exceptional written and verbal communication skills
  • Availability to support critical audit cycles during business hours with occasional off-hours engagement; Intermittent travel required for regulatory assessments and stakeholder alignment
  • Previous PSIRT experience
  • Experience interacting with external researchers, CERTs, regulators, and industry consortiums
  • Experience handling AI-related vulnerabilities and/or incidents
Basic Requirements
  • Bachelor's degree or equivalent experience
  • 5+ years of experience in cybersecurity, software engineering, product security, enterprise risk, and/or regulatory compliance
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Advisory Engineer, Enterprise Product Security Incident Response Team (E-PSIRT)
Advisory Engineer, Enterprise Product Security Incident Response Team (E-PSIRT)

Lenovo • Morrisville (NC)

On-site
USD 127,000 - 195,000
Sr. Program Manager, Enterprise Product Security Incident Response Team (E-PSIRT)
Sr. Program Manager, Enterprise Product Security Incident Response Team (E-PSIRT)

Lenovo • North Carolina

On-site
USD 140,000 - 190,000
Sr. Program Manager, Enterprise Product Security Incident Response Team (E-PSIRT)
Sr. Program Manager, Enterprise Product Security Incident Response Team (E-PSIRT)

Lenovo • Morrisville (NC)

On-site
USD 161,000 - 246,000
Lead Product Security Incident Response Engineer
Lead Product Security Incident Response Engineer

Lenovo • Morrisville (NC)

On-site
USD 127,000 - 195,000
Senior Enterprise PSIRT Engineer - Vulnerability Response
Senior Enterprise PSIRT Engineer - Vulnerability Response

Lenovo • North Carolina

On-site
USD 120,000 - 150,000
Sr Manager Software Security
Sr Manager Software Security

Lenovo • Raleigh (NC)

On-site
USD 140,000 - 210,000
Sr Software Security Architect
Sr Software Security Architect

Lenovo • Raleigh (NC)

On-site
USD 140,000 - 190,000
Advisory Engineer, AI Security
Advisory Engineer, AI Security

Lenovo • Morrisville (NC)

Hybrid
USD 140,000 - 190,000
Enterprise PSIRT Lead — Security Incident Response & CRA
Enterprise PSIRT Lead — Security Incident Response & CRA

Lenovo • Morrisville (NC)

On-site
USD 161,000 - 246,000
Sr. Product Manager – Platform Security
Sr. Product Manager – Platform Security

Lenovo • Morrisville (NC)

On-site
USD 120,000 - 180,000