Product Security Engineer - PSIRT

Lenovo

Morrisville (NC)

On-site

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Lenovo is seeking an experienced security professional to join the Product Security Incident Response Team (PSIRT). The role involves end-to-end handling of product security vulnerabilities, coordinating remediation with product teams, and publishing advisories.

You will perform hands-on investigations across software, firmware, and system components, drive cross‑functional remediation, and manage CVE/CWE/CVSS scoring while engaging external researchers and customers in coordinated vulnerability

Qualifications

  • Bachelor's degree or equivalent experience required.
  • 5+ years of experience in software engineering, cybersecurity, or related field.
  • Experience in PSIRT or vulnerability response, secure software development, or vulnerability management.
  • Experience performing technical security investigations or triage.
  • Experience with scripting or automation (e.g., Python).
  • Strong written and verbal communication skills.
  • Experience in PSIRT or coordinated vulnerability disclosure environments.
  • Software development background in application or system-level components.
  • Experience with bug bounty programs or security research.
  • Familiarity with CVE, CVSS, CWE, and vulnerability disclosure practices.

Responsibilities

  • Independently own end-to-end handling of product security vulnerabilities, from intake through remediation and disclosure.
  • Perform hands-on technical investigation and validation across software, firmware, and system components.
  • Drive cross-functional coordination with development teams to ensure timely remediation.
  • Draft security advisories communicating risk and mitigation to customers.
  • Assign and manage CVE, CWE, and CVSS scoring for vulnerabilities.
  • Engage with external security researchers, customers, and partners for coordinated vulnerability disclosure.
  • Identify opportunities to automate vulnerability triage, analysis, and reporting workflows.
  • Contribute to PSIRT tooling, automation, and process improvements for scale.
  • Monitor external sources for vulnerabilities impacting Lenovo products.
  • Partner with global stakeholders to ensure consistent PSIRT execution across regions.

Skills

Software security
Vulnerability triage
Automation
Python scripting
Technical investigation
Communication
Coordinated disclosure
Threat analysis
Security operations

Education

Bachelor's degree or equivalent experience

Tools

Python

Job description

In this role, you will work as part of Lenovo's Product Security Incident Response Team (PSIRT). You will be responsible for supporting the end-to-end response to product security vulnerabilities, including technical investigation, driving remediation with product teams, and publishing security advisories to customers.

This role operates as an experienced individual contributor, capable of independently handling complex vulnerability cases while collaborating across global teams. Candidates may come from PSIRT, software development, vulnerability management, or security research backgrounds, with a strong emphasis on application-level security and the ability to automate and scale workflows.

Responsibilities
  • Independently own end-to-end handling of product security vulnerabilities, from intake through remediation and disclosure
  • Perform hands‑on technical investigation and validation of reported issues across software, firmware, and system components
  • Drive cross‑functional coordination with development teams to ensure timely and effective remediation
  • Draft security advisories, clearly communicating risk and mitigation to customers
  • Assign and manage CVE, CWE, and CVSS scoring for vulnerabilities
  • Engage with external security researchers, customers, and partners, supporting coordinated vulnerability disclosure (CVD)
  • Identify opportunities to automate vulnerability triage, analysis, and reporting workflows, including use of scripting or AI-based approaches
  • Contribute to PSIRT tooling, automation, and process improvements to support scale and efficiency
  • Monitor external sources and industry channels for vulnerabilities impacting Lenovo products
  • Partner with global stakeholders to ensure consistent PSIRT execution across regions
Qualifications
  • Bachelor's degree or equivalent experience
  • 5+ years of experience in software engineering, cybersecurity, or a related technical field
  • Experience in at least one of the following areas:
    • PSIRT or vulnerability response
    • Secure software development
    • Vulnerability management or security operations
  • Experience performing technical security investigations or triage
  • Experience with scripting or automation (e.g., Python or similar)
  • Strong written and verbal communication skills
  • Experience working in a PSIRT or coordinated vulnerability disclosure (CVD) environment
  • Software development background, particularly in application or system‑level components
  • Experience with bug bounty programs or security research
  • Familiarity with application security concepts and common vulnerability classes
  • Experience building or leveraging automation, tooling, or AI‑driven workflows
  • Strong understanding of vulnerability management processes, especially when paired with development experience
  • Familiarity with CVE, CVSS, CWE, and vulnerability disclosure practices
  • Understanding of product ecosystems (e.g., firmware, OS, drivers, applications)
Basic Requirements
  • 5+ years of software engineering, cybersecurity, software development, vulnerability management, security operations, and/or technical experience

We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer – PSIRT
Product Security Engineer – PSIRT

Lenovo • Morrisville (NC)

On-site
USD 120,000 - 150,000
Senior Product Security Engineer, PSIRT & Automation
Senior Product Security Engineer, PSIRT & Automation

Lenovo • Morrisville (NC)

On-site
USD 140,000 - 190,000
Product Security Engineer: Lead Vulnerability Response
Product Security Engineer: Lead Vulnerability Response

Lenovo • Morrisville (NC)

On-site
USD 120,000 - 150,000
Sr Software Security Architect
Sr Software Security Architect

Lenovo • Raleigh (NC)

On-site
USD 140,000 - 190,000
Sr Manager Software Security
Sr Manager Software Security

Lenovo • Raleigh (NC)

On-site
USD 140,000 - 210,000
Sr. Product Manager – Platform Security
Sr. Product Manager – Platform Security

Lenovo • Morrisville (NC)

On-site
USD 120,000 - 180,000
Sr Manager Cloud Security Operations
Sr Manager Cloud Security Operations

Lenovo • Raleigh (NC)

On-site
USD 120,000 - 190,000
Lead Secure Development & Tools Trainer
Lead Secure Development & Tools Trainer

Lenovo • Raleigh (NC)

On-site
USD 110,000 - 140,000
Senior Services Sales Executive - Security
Senior Services Sales Executive - Security

Lenovo • North Carolina

Hybrid
USD 215,000 - 230,000
Bonus and/or commission
Comprehensive benefits package
Senior Engineer II - Product Security
Senior Engineer II - Product Security

Microchip Technology Inc. • Chandler (AZ)

On-site
USD 140,000 - 190,000