Advisory Engineer, Enterprise Product Security Incident Response Team (E-PSIRT)

Lenovo - United States

Hiring: Advisory Engineer, Enterprise Product Security Incident Response Team (E-PSIRT) Company: Lenovo Location: United States Job Posted Time: 2026-09-10 07:41:00 Target Skills & Keywords : Regulatory Compliance About the job Experience: •5+ years of applied experience in cybersecurity, software engineering, product security, enterprise risk, or regulatory compliance roles, preferably in a team lead capacity •5+ years of experience in cybersecurity, software engineering, product security, enterprise risk, and/or regulatory compliance Required Skills: •Vulnerability Assessment Triage: Assess product security vulnerabilities, exploits, and incidents from: researchers, customers, suppliers, threat intelligence feeds, public disclosures, CERTs, and internal testing •Perform technical analysis and risk evaluation •Determine vulnerability severity and likelihood •PSIRT Case Management: Manage vulnerability cases from intake through closure, coordinate technical investigations across product security offices and engineering teams, track remediation progress and disclosure milestones •Central Orchestration: Serve as the operational coordinator across Product Security Offices within IDG, ISG, SSG, Motorola, CAIO, Legal, and other business groups •Cyber Resilience Act (CRA) Support: Assist with CRA vulnerability reporting requirements in identifying actively exploited vulnerabilities, and/or severe incidents, support preparation of regulatory reports and notifications, participate in readiness exercises and process testing •Threat Intelligence Monitoring: Monitor vulnerability databases and threat intelligence sources, assess emerging vulnerabilities impacting Lenovo products, participate in coordinated industry disclosures, evaluate supplier and third-party vulnerability notifications •Metrics Continuous Improvement: Develop vulnerability management metrics and reporting, identify process and tool improvement opportunities, support automation initiatives for triage and case management, contribute to playbooks, SOPs, and governance documentation Qualifications: •Bachelor’s degree in Cybersecurity, Information Systems, Systems Engineering, Law, or a highly related technical discipline preferred •Proven capability in security operations, incident response, vulnerability analysis, and/or threat intelligence •Exceptional written and verbal communication skills •Availability to support critical audit cycles during business hours with occasional off-hours engagement; Intermittent travel required for regulatory assessments and stakeholder alignment •Bachelor's degree or equivalent experience Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!