Advisory Engineer, Enterprise Product Security Incident Response Team (E-PSIRT)
Product
Morrisville, NC, USA
Why Work at Lenovo
Description and Requirements
The Product Security Advisory Engineer of Lenovo’s Enterprise Product Security Incident Response Team (E-PSIRT) is responsible for assessing, triaging, coordinating, and tracking product security vulnerabilities and incidents across Lenovo’s global product portfolio.
This role functions as the central operational orchestrator for product vulnerability activities, coordinating product security offices, engineering teams, suppliers, and other stakeholders to ensure vulnerabilities are appropriately evaluated, prioritized, remediated, disclosed and reported. The position will play a critical role in supporting Lenovo’s Cyber Resilience Act (CRA) compliance program, including vulnerability reporting readiness and regulatory response activities. Lenovo’s E-PSIRT responsibilities include vulnerability intake, triage, workflow management, coordination, impact assessment, reporting, disclosure tracking, technical advisory writing, and support for notification activities.
Core Day-to-Day Operations:
- Liaison with internal and external stakeholders, including Lenovo business units and third-party upstream and downstream suppliers, to coordinate vulnerability response and remediation activities
- Collaborate and negotiate with suppliers, technology partners, and security researchers to triage vulnerabilities, develop remediation plans, and coordinate responsible disclosure activities
- Develop, review, and publish security advisories, communicating available fixes, workarounds, and mitigation strategies for identified vulnerabilities
- Draft and issue customer-facing security communications and advisories, ensuring timely dissemination of mitigation and remediation guidance
- Coordinate cross-functional communications to ensure accurate, consistent, and timely messaging related to security vulnerabilities and product security issues
Key Responsibilities:
Vulnerability Assessment & Triage: Assess product security vulnerabilities, exploits, and incidents from: researchers, customers, suppliers, threat intelligence feeds, public disclosures, CERTs, and internal testing
- Perform technical analysis and risk evaluation
- Validate business impact
- Determine vulnerability severity and likelihood
PSIRT Case Management: Manage vulnerability cases from intake through closure, coordinate technical investigations across product security offices and engineering teams, track remediation progress and disclosure milestones
Central Orchestration: Serve as the operational coordinator across Product Security Offices within IDG, ISG, SSG, Motorola, CAIO, Legal, and other business groups
Cyber Resilience Act (CRA) Support: Assist with CRA vulnerability reporting requirements in identifying actively exploited vulnerabilities, and/or severe incidents, support preparation of regulatory reports and notifications, participate in readiness exercises and process testing
Threat Intelligence & Monitoring: Monitor vulnerability databases and threat intelligence sources, assess emerging vulnerabilities impacting Lenovo products, participate in coordinated industry disclosures, evaluate supplier and third-party vulnerability notifications
Metrics & Continuous Improvement: Develop vulnerability management metrics and reporting, identify process and tool improvement opportunities, support automation initiatives for triage and case management, contribute to playbooks, SOPs, and governance documentation
Qualifications:
- Bachelor’s degree in Cybersecurity, Information Systems, Systems Engineering, Law, or a highly related technical discipline preferred
- 5+ years of applied experience in cybersecurity, software engineering, product security, enterprise risk, or regulatory compliance roles, preferably in a team lead capacity
- Proven capability in security operations, incident response, vulnerability analysis, and/or threat intelligence
- Exceptional written and verbal communication skills
- Availability to support critical audit cycles during business hours with occasional off-hours engagement; Intermittent travel required for regulatory assessments and stakeholder alignment
- Previous PSIRT experience
- Experience interacting with external researchers, CERTs, regulators, and industry consortiums
- Experience handling AI-related vulnerabilities and/or incidents
- Bachelor's degree or equivalent experience
- 5+ years of experience in cybersecurity, software engineering, product security, enterprise risk, and/or regulatory compliance