Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details
Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Lenovo

Advisory Engineer, Enterprise Product Security Incident Response Team (E-PSIRT)

Career Insights for Vulnerability Analyst / Penetration Tester

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on North Carolina data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.

$118,018 / year median in North Carolina

+8% projected growth

Explore Career

Job Description

General Information Req #
WD00104875
Career area:
Information Technology Country/Region:
United States of America State:
North Carolina City:
Morrisville Date:
Friday, September 4, 2026 Working time:
Full-time Additional Locations :
  • United States of America
  • North Carolina
  • Morrisville Why Work at Lenovo We are Lenovo.
We do what we say. We own what we do. We WOW our customers. Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world's largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo's continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (
HKSE:
992) (
ADR:
LNVGY). This transformation together with Lenovo's world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com , and read about the latest news via our StoryHub . Description and Requirements The Product Security Advisory Engineer of Lenovo's Enterprise Product Security Incident Response Team (E-PSIRT) is responsible for assessing, triaging, coordinating, and tracking product security vulnerabilities and incidents across Lenovo's global product portfolio. This role functions as the central operational orchestrator for product vulnerability activities, coordinating product security offices, engineering teams, suppliers, and other stakeholders to ensure vulnerabilities are appropriately evaluated, prioritized, remediated, disclosed and reported. The position will play a critical role in supporting Lenovo's Cyber Resilience Act (CRA) compliance program, including vulnerability reporting readiness and regulatory response activities. Lenovo's E-PSIRT responsibilities include vulnerability intake, triage, workflow management, coordination, impact assessment, reporting, disclosure tracking, technical advisory writing, and support for notification activities.
Core Day-to-Day Operations:
Liaison with internal and external stakeholders, including Lenovo business units and third-party upstream and downstream suppliers, to coordinate vulnerability response and remediation activities Collaborate and negotiate with suppliers, technology partners, and security researchers to triage vulnerabilities, develop remediation plans, and coordinate responsible disclosure activities Develop, review, and publish security advisories, communicating available fixes, workarounds, and mitigation strategies for identified vulnerabilities Draft and issue customer-facing security communications and advisories, ensuring timely dissemination of mitigation and remediation guidance Coordinate cross-functional communications to ensure accurate, consistent, and timely messaging related to security vulnerabilities and product security issues
Key Responsibilities:
Vulnerability Assessment & Triage:
Assess product security vulnerabilities, exploits, and incidents from: researchers, customers, suppliers, threat intelligence feeds, public disclosures, CERTs, and internal testing Perform technical analysis and risk evaluation Validate business impact Determine vulnerability severity and likelihood
PSIRT Case Management:
Manage vulnerability cases from intake through closure, coordinate technical investigations across product security offices and engineering teams, track remediation progress and disclosure milestones
Central Orchestration:
Serve as the operational coordinator across Product Security Offices within IDG, ISG, SSG, Motorola, CAIO, Legal, and other business groups Cyber Resilience Act (CRA)
Support:
Assist with CRA vulnerability reporting requirements in identifying actively exploited vulnerabilities, and/or severe incidents, support preparation of regulatory reports and notifications, participate in readiness exercises and process testing
Threat Intelligence & Monitoring:
Monitor vulnerability databases and threat intelligence sources, assess emerging vulnerabilities impacting Lenovo products, participate in coordinated industry disclosures, evaluate supplier and third-party vulnerability notifications
Metrics & Continuous Improvement:
Develop vulnerability management metrics and reporting, identify process and tool improvement opportunities, support automation initiatives for triage and case management, contribute to playbooks, SOPs, and governance documentation
Qualifications:
Bachelor's degree in Cybersecurity, Information Systems, Systems Engineering, Law, or a highly related technical discipline preferred 5+ years of applied experience in cybersecurity, software engineering, product security, enterprise risk, or regulatory compliance roles, preferably in a team lead capacity Proven capability in security operations, incident response, vulnerability analysis, and/or threat intelligence Exceptional written and verbal communication skills Availability to support critical audit cycles during business hours with occasional off-hours engagement; Intermittent travel required for regulatory assessments and stakeholder alignment Previous PSIRT experience Experience interacting with external researchers, CERTs, regulators, and industry consortiums Experience handling AI-related vulnerabilities and/or incidents
Basic Requirements:
Bachelor's degree or equivalent experience 5+ years of experience in cybersecurity, software engineering, product security, enterprise risk, and/or regulatory compliance #LI-MM5 We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.
Additional Locations :
  • United States of America
  • North Carolina
  • Morrisville
  • United States of America
  • United States of America
  • North Carolina
  • United States of America
  • North Carolina
  • Morrisville
PAY TRANSPARENCY
The anticipated annual compensation range for this position is 127,100-194,925 USD . Final compensation will be based on relevant experience, skills, and business considerations. Individuals may also be considered for bonuses and/or commissions. Lenovo's various benefits can be found at www.lenovobenefits.com In compliance with Colorado's Equal Pay for Equal Work Act (EPEWA), the expected application deadline for this position is 11-30-2026. This requirement applies to both internal and external candidates.