Stand out for this role — generate a tailored resume and cover letter in about a minute.
Lenovo in the United States seeks a Sr. Enterprise Product Security Incident Response Program Manager to lead Lenovo's Global Enterprise PSIRT, coordinating vulnerability intake, triage, disclosure, and CRA readiness across all business groups.
You will establish central governance, drive risk-based remediation, manage communications with researchers and suppliers, and oversee tooling and processes to scale incident response and regulatory compliance.
We are Lenovo. We do what we say. We own what we do. We WOW our customers. Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world's largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo's continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY). This transformation together with Lenovo's world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub. The Sr. Enterprise Product Security Incident Response Program Manager will lead Lenovo's Global Enterprise PSIRT and serve as the central coordination authority for enterprise-wide incidents, including products, vulnerability management governance, and Cyber Resilience Act (CRA) readiness across all Lenovo business groups. In this role, as a hands-on technical leader, you will establish a central coordination team for vulnerability intake, researcher engagement, issue triage, coordinated vulnerability disclosure, business unit coordination, reporting oversight, KPIs, playbook maintenance, executive escalation, briefings/meetings, and CRA reporting support. This role will act as the primary orchestrator across a multitude of teams to ensure consistent vulnerability handling, incident response, threat intelligence and compliance with global regulatory requirements, including the EU Cyber Resilience Act (CRA).
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.