Sr. Program Manager, Enterprise Product Security Incident Response Team (E-PSIRT)

Lenovo

Morrisville (NC)

On-site

USD 161,000 - 246,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Lenovo is seeking a Senior Enterprise Product Security Incident Response Program Manager to lead the Global Enterprise PSIRT and coordinate enterprise-wide vulnerability response. You will establish a central coordination team for vulnerability intake, triage, disclosure, and CRA reporting across Lenovo’s business groups.

The role demands hands-on technical leadership, orchestration across security and engineering teams, and strong communication with legal, product, and executive stakeholders.

Qualifications

  • 10+ years of experience in cybersecurity, product security, incident response, threat intelligence, or related program management.
  • Proven capability in establishing and leading a technical cybersecurity program.
  • Excellent written and verbal communication, bridging legal, engineering, and executive stakeholders.

Responsibilities

  • Lead Lenovo's Global Enterprise PSIRT and coordinate enterprise-wide vulnerability response.
  • Establish central intake, triage, disclosure, and CRA reporting processes across business units.
  • Oversee CRA readiness and governance, including ENISA workflows and regulatory evidence retention.
  • Publish timely security advisories and coordinate with researchers, suppliers, and engineering teams.

Skills

Cybersecurity expertise
Incident response
Threat intelligence
Program management
Leadership

Education

Bachelor's degree in Cybersecurity

Tools

PSIRT tooling

Job description

General Information

Req # WD00104873

Career area: Information Technology

Country/Region: United States of America

State: North Carolina

City: Morrisville

Date: Friday, September 4, 2026

Working time: Full-time

Additional Locations
  • United States of America
  • United States of America - North Carolina
  • United States of America - North Carolina - Morrisville
Why Work at Lenovo

We are Lenovo. We do what we say. We own what we do. We WOW our customers.

Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world's largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo's continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).

This transformation together with Lenovo's world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.

Description and Requirements

The Sr. Enterprise Product Security Incident Response Program Manager will lead Lenovo's Global Enterprise PSIRT and serve as the central coordination authority for enterprise-wide incidents, including products, vulnerability management governance, and Cyber Resilience Act (CRA) readiness across all Lenovo business groups.

In this role, as a hands‑on technical leader, you will establish a central coordination team for vulnerability intake, researcher engagement, issue triage, coordinated vulnerability disclosure, business unit coordination, reporting oversight, KPIs, playbook maintenance, executive escalation, briefings/meetings, and CRA reporting support.

This role will act as the primary orchestrator across a multitude of teams to ensure consistent vulnerability handling, incident response, threat intelligence and compliance with global regulatory requirements, including the EU Cyber Resilience Act (CRA).

Key Responsibilities
  • Product Security Governance Establish and manage Lenovo's Global Enterprise Product Security Governance framework
    • Establish enterprise tools, standards, policies, procedures, KPIs, and reporting for Enterprise-level PSIRT
    • Drive alignment across Product Security Offices within IDG, ISG, SSG, Motorola, CAIO, Legal, and other business groups
  • Program Oversight
    • Serve as the central orchestration lead for product security vulnerabilities, including AI and related security incidents
    • Coordinate enterprise‑wide vulnerability response activities across business group security and engineering teams
    • Facilitate triage, prioritization, remediation, escalation, communication, and disclosure decision‑making processes
    • Oversee tooling, automation, and process improvements to support scale and efficiency
  • Cyber Resilience Act Leadership
    • Lead Lenovo's operational readiness and execution of CRA Article 14 requirements
    • Maintain and Improve governance processes for:
      • Actively Exploited Vulnerability Reporting
      • Serve Incident Reporting
      • ENISA notification workflows
      • Regulatory evidence retention
    • Coordinated Vulnerability Disclosure (CVD) requirements
    • Lead CRA readiness including tabletop exercises
  • Oversee Daily Operations
    • Lead vulnerability disclosure and coordinated remediation efforts with internal stakeholders, suppliers, partners, and security researchers
    • Drive end‑to‑end security advisory development, including vulnerability tirage, risk assessment, mitigation guidance, and customer communications
    • Manage communications with third‑party suppliers and researchers to facilitate timely vulnerability resolution and responsible disclosure
    • Publish and maintain customer‑facing security advisories, ensuring clear, accurate, and actionable remediation guidance
    • Partner with engineering, legal, communications, and support organizations to coordinate response activities and ensure consistent stakeholder communications throughout the vulnerability lifecycle
Qualifications
  • Bachelor's degree in Cybersecurity, Information Systems, Systems Engineering, or a highly related technical discipline preferred
  • 10+ years of applied experience in cybersecurity, product security, incident response, threat intelligence, or related program management/functional roles
  • Proven capability in establishing and leading a technical cybersecurity program in vulnerability management, incident response, or threat intelligence
  • Hands‑on technical leader with ability to manage complex, multi‑stakeholder initiatives
  • Exceptional written and verbal communication skills; Capable of bridging the lexicon gap between legal, engineering, and executive stakeholders
  • Availability to support critical cycles during business hours with occasional off‑hours engagement; Intermittent travel may be required for regulatory assessments and stakeholder alignment
  • Previous PSIRT leadership experience
  • Experience interacting with external researchers, CERTs, regulators, and industry consortiums
  • Experience handling AI‑related vulnerabilities and/or incidents
  • Active professional credentials such as CISSP, CISM, CISA, or ISO related certifications
Basic Requirements
  • Bachelor's degree or equivalent experience
  • 10+ years of experience in cybersecurity, product security, incident response, threat intelligence, and/or program management

#LI-MM5

We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.

PAY TRANSPARENCY

The anticipated annual compensation range for this position is 160,700-246,445 USD. Final compensation will be based on relevant experience, skills, and business considerations. Individuals may also be considered for bonuses and/or commissions. Lenovo's various benefits can be found at www.lenovobenefits.com.

In compliance with Colorado's Equal Pay for Equal Work Act (EPEWA), the expected application deadline for this position is 11-30-2026. This requirement applies to both internal and external candidates.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Advisory Engineer, Enterprise Product Security Incident Response Team (E-PSIRT)
Advisory Engineer, Enterprise Product Security Incident Response Team (E-PSIRT)

Lenovo • Morrisville (NC)

On-site
USD 127,000 - 195,000
Senior Manager, AI Risk Management
Senior Manager, AI Risk Management

Lenovo • Morrisville (NC)

On-site
USD 161,000 - 246,000
Sr Manager Software Security
Sr Manager Software Security

Lenovo • Raleigh (NC)

On-site
USD 140,000 - 210,000
Sr. Product Manager – Platform Security
Sr. Product Manager – Platform Security

Lenovo • Morrisville (NC)

On-site
USD 120,000 - 180,000
Manager, AI Governance Programs
Manager, AI Governance Programs

Lenovo • Morrisville (NC)

On-site
USD 127,000 - 195,000
Sr Software Security Architect
Sr Software Security Architect

Lenovo • Raleigh (NC)

On-site
USD 140,000 - 190,000
Enterprise PSIRT Lead — Security Incident Response & CRA
Enterprise PSIRT Lead — Security Incident Response & CRA

Lenovo • Morrisville (NC)

On-site
USD 161,000 - 246,000
Sr. Services Sales Executive Manager
Sr. Services Sales Executive Manager

Lenovo • Morrisville (NC)

On-site
USD 175,000 - 200,000
Solutions & Services Specialist - Security SW
Solutions & Services Specialist - Security SW

Lenovo • Morrisville (NC)

On-site
USD 110,000 - 160,000
Sr Manager Cloud Security Operations
Sr Manager Cloud Security Operations

Lenovo • Raleigh (NC)

On-site
USD 120,000 - 190,000