Cybersecurity Compliance Advisor
Legal
Farnborough, UK
EUR 3,150-4,200 / month
Why Work at Lenovo
Description and Requirements
This position is for a Cyber Security Compliance Manager in the Solutions & Services Group (SSG). This is an exciting role that will give you the opportunity to work with Lenovo Product teams around the world to help Lenovo Business Units align with various regional, national and international security standards and regulations. You will be working alongside some of the best security teams in the industry. You will join a growing team of security professionals to help assess risk, ensure compliance and to design risk remediation and mitigation strategies and tactics.
This role will work hand in hand with business executives, product managers, architects, engineers, devops, and developers to support operationalization of cybersecurity compliance program to meet regulatory obligations with a primary focus on the EU Network and Information Security Directive 2 (NIS2) and the Cyber Resilience Act (CRA).
What You Will Do:
- Lead NIS2 & CRA compliance readiness by conducting gap assessments, identifying risks, and translating findings into clear, prioritized remediation plans.
- Partner with engineering and product teams to embed Cyber Resilience Act (CRA) requirements into the product lifecycle, including secure-by-design principles, vulnerability management, SBOMs, and incident reporting processes.
- Drive implementation of cybersecurity and risk management controls, ensuring compliance with regulatory requirements related to governance, accountability, supply chain security, and operational resilience.
- Manage compliance programs and projects end-to-end, defining timelines, milestones, and deliverables while proactively tracking progress, risks, dependencies, and blockers.
- Act as the primary liaison across SSG, collaborating with security, legal, engineering, product, procurement, and leadership teams on NIS2 and CRA compliance initiatives.
- Develop and maintain compliance frameworks and documentation, including policies, procedures, control matrices, evidence repositories, audit trails, and supporting records.
- Support internal and external audits, assessments, and regulatory engagements, ensuring the organization is prepared for compliance reviews and regulator inquiries.
- Monitor evolving cybersecurity regulations and industry standards, including ENISA guidance and harmonized standards, while delivering metrics, reporting, and insights that measure program maturity and communicate compliance status to leadership.
- 7+ years of experience in cybersecurity compliance, governance, risk & compliance (GRC), IT/cyber risk management, or a related regulatory compliance function.
- Strong knowledge of EU cybersecurity regulations, including NIS2 and the Cyber Resilience Act (CRA), or experience with frameworks such as GDPR, DORA, and ISO 27001 with the ability to quickly build expertise in emerging regulations.
- Proven experience developing, implementing, or maturing compliance programs, helping organizations strengthen governance, controls, and regulatory readiness.
- Excellent project management skills, with the ability to independently lead multiple initiatives, manage competing priorities, and coordinate complex cross-functional workstreams.
- Strong stakeholder management and influencing capabilities, comfortable partnering with engineering, product, legal, procurement, security, and executive leadership teams to drive alignment and execution.
- Exceptional communication skills, with the ability to translate complex technical, cybersecurity, and regulatory requirements into clear, practical guidance for both technical and non-technical audiences.
- Bachelor’s degree in Cybersecurity, Information Systems, Law, Computer Science, or a related field, or equivalent combination of education and practical experience.
- Professional certifications such as CISSP, CISM, CISA, CRISC, or similar are preferred, along with cybersecurity experience within a technology company, managed services provider (MSP), or connected-product organization operating under Cyber Resilience Act requirements.
- An international team with a high focus on Gender Diversity.
- Employee Assistance Program, e.g., for psychological, legal & financial consultancy.
- You are joining a company that prioritizes sustainable solutions like CO2 Offset, Asset Recovery Services, and the Lenovo Certified Refurbished portfolio.
- Access to training for personal development - Internal E-learning Development Platform Available for Employees
- Mentorship program.