| Location | Morrisville, NC |
| Salary | $160,700–$246,445 Per Year |
General Information
Req #
WD00104873
Career area:
Information Technology
Country/Region:
United States of America
State:
North Carolina
City:
Morrisville
Date:
Friday, September 4, 2026
Working time:
Full-time
Additional Locations:
Why Work at Lenovo
We are Lenovo. We do what we say. We own what we do. We WOW our customers.
Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world's largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo's continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).
This transformation together with Lenovo's world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.
Description and Requirements
The Sr. Enterprise Product Security Incident Response Program Manager will lead Lenovo's Global Enterprise PSIRT and serve as the central coordination authority for enterprise-wide incidents, including products, vulnerability management governance, and Cyber Resilience Act (CRA) readiness across all Lenovo business groups
In this role, as a hands-on technical leader, you will establish a central coordination team for vulnerability intake, researcher engagement, issue triage, coordinated vulnerability disclosure, business unit coordination, reporting oversight, KPIs, playbook maintenance, executive escalation, briefings/meetings, and CRA reporting support
This role will act as the primary orchestrator across a multitude of teams to ensure consistent vulnerability handling, incident response, threat intelligence and compliance with global regulatory requirements, including the EU Cyber Resilience Act (CRA).
Key Responsibilities:
Product Security Governance: Establish and manage Lenovo's Global Enterprise Product Security Governance framework
Establish enterprise tools, standards, policies, procedures, KPIs, and reporting for Enterprise-level PSIRT
Drive alignment across Product Security Offices within IDG, ISG, SSG, Motorola, CAIO, Legal, and other business groups
Program Oversight
Serve as the central orchestration lead for product security vulnerabilities, including AI and related security incidents
Coordinate enterprise-wide vulnerability response activities across business group security and engineering teams
Facilitate triage, prioritization, remediation, escalation, communication, and disclosure decision-making processes
Oversee tooling, automation, and process improvements to support scale and efficiency
Cyber Resilience Act Leadership
Lead Lenovo's operational readiness and execution of CRA Article 14 requirements
Maintain and Improve governance processes for:
Actively Exploited Vulnerability Reporting
Serve Incident Reporting
ENISA notification workflows
Regulatory evidence retention
Coordinated Vulnerability Disclosure (CVD) requirements
Lead CRA readiness including tabletop exercises
Oversee Daily Operations
Lead vulnerability disclosure and coordinated remediation efforts with internal stakeholders, suppliers, partners, and security researchers
Drive end-to-end security advisory development, including vulnerability tirage, risk assessment, mitigation guidance, and customer communications
Manage communications with third-party suppliers and researchers to facilitate timely vulnerability resolution and responsible disclosure
Publish and maintain customer-facing security advisories, ensuring clear, accurate, and actionable remediation guidance
Partner with engineering, legal, communications, and support organizations to coordinate response activities and ensure consistent stakeholder communications throughout the vulnerability lifecycle
Qualifications:
Basic Requirements:
#LI-MM5
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.
Additional Locations:
PAY TRANSPARENCY
The anticipated annual compensation range for this position is 160,700-246,445 USD. Final compensation will be based on relevant experience, skills, and business considerations. Individuals may also be considered for bonuses and/or commissions. Lenovo's various benefits can be found at www.lenovobenefits.com
In compliance with Colorado's Equal Pay for Equal Work Act (EPEWA), the expected application deadline for this position is 11-30-2026. This requirement applies to both internal and external candidates.