Advisory Engineer, AI and Product Security
Software Engineering, Product, Data Science
Farnborough, UK
Why Work at Lenovo
Description and Requirements
This new position joins Lenovo's AI Governance and Product Security organization within the Chief AI Office in our mission of enabling security and trust in Lenovo's use of AI technology in product development through Responsible AI. The AI Governance and Product Security Office works across all Lenovo's business and product areas to ensure AI tools are used in accordance with Company standards and international regulations and products are developed and implemented with industry best practices for security.
In partnership with AI and security leaders across Lenovo, the Advisory Engineer, AI Security will lead the technical security assurance and enablement of secure agentic AI across Lenovo. The role will develop and apply practical security and responsible AI control patterns for AI agents, assess high-risk agentic use cases and drive the delivery of controls that enable safe adoption across customer-facing and internal solutions.
This person combines deep AI security expertise with a strong delivery mindset. They will translate agentic AI risks into implementable technical controls, work directly with engineering teams through design, testing and remediation, and help establish scalable assurance practices for agentic AI.
Key Responsibilities:
- Drive delivery of the Agentic AI Security and Assurance roadmap, including priorities, technical deliverables, adoption measures and remediation tracking.
- Define and maintain security standards, reference architectures and control patterns for AI agents, including identity, permissions, tool use, data access, memory, human oversight, logging and containment.
- Lead security risk assessments, threat modelling and assurance reviews for high-risk agentic AI use cases, platforms and material design changes.
- Develop and apply test scenarios for agentic AI threats.
- Define requirements for agentic AI discovery, inventory, runtime visibility, monitoring and control tooling; partner with operations teams on implementation and ongoing operation.
- Support investigation of material agentic-AI security events and incorporate lessons learned into standards, controls and assurance practices.
- Occasional domestic and international travel (approx. 5-20%) for meetings and collaboration.
Qualifications:
- Demonstrated experience delivering security controls from design through implementation, validation and operational handover across cross-functional engineering teams.
- Experience with threat modelling, security assessment and remediation for applications, cloud services, APIs or AI-enabled systems.
- Strong understanding of agentic AI security risks and controls, including identity and access management, tool/API security, data flows, prompt injection, privilege boundaries, logging and human oversight.
- Experience designing or assessing security controls across cloud environments, APIs, CI/CD pipelines, identity services and data platforms.
- Working knowledge of relevant guidance, such as OWASP guidance for LLM and agentic applications, MITRE ATLAS and cloud-provider AI security guidance.
- Ability to participate in incident response and product security operations as required.
- Relevant security certifications are advantageous.
Basic Requirements:
- Bachelor's degree in computer science, artificial intelligence, data science, software engineering, mathematics, or equivalent experience
- 8+ years of experience in product security, application security, cloud security, security engineering or related discipline.
- Holiday purchase
- Private medical
- Income protection
- Attractive pension scheme
- Positive work life balance
- Learning and development
- Life insurance
- Lenovo and Motorola products discounts
- Lifestyle discounts
- Cycle to work
- MyGymDiscounts
- Mortgage advice and support
- Referral bonus
- Free onsite parking