Cyber Security Manager
Lenovo
Why Work at Lenovo
Description and Requirements
Come be a part of the next generation of Managed Services and Solutions at Lenovo! This position is for a Cyber Security Manager in the Solutions & Services Group (SSG) to lead ISO27001 and SOC 1&2 compliance activities. This is an exciting role that will give you the opportunity to work with Lenovo Product teams around the world to help Lenovo Business Units align with various regional, national and international security standards and regulations. You will be working alongside some of the best security teams in the industry.
This role will work hand in hand with business executives, product managers, architects, engineers, devops and developers to deliver against Information Security Standards. This position will define methodologies, metrics and KPIs; scoping and delivering security assessments ensuring continued alignment to standards over time. Ensuring that growth, improvements, gaps and risks are accurately communicated to business leaders.
What you'll be doing
- Conducting ongoing activities to uphold the current ISO27001 and SOC 1&2 Certifications for SSG.
- Maintain metrics and KPIs to monitor progress and enable prioritization of management action.
- Providing constructive advice and challenge on the management of cyber risks throughout SSG.
- Working cross-functionally to develop strategies to identify, mitigate and manage current and emerging cyber threats.
- Creating, developing and maintaining security policies and practices.
- Advising design, service, operations teams on security requirements and implementation.
- Establishing and maintaining a strategy for managing security-related audits, compliance checks and external assessment processes for auditors, including but not limited to, ISO27001 and SOC 1&2.
- Liaising with auditors, both internal and external, to maintain and implement controls.
- Providing SME support to other business functions
- Build strong working relationships with stakeholders across the business.
- Stay up to date with relevant ISO standards, auditing practices, and regulatory requirements