Sr. Manager, Security Compliance & Certification Program
Listed on 2026-08-04
-
IT/Tech
Cybersecurity, Information Security & Data Protection
We are Lenovo. We do what we say. We own what we do. We WOW our customers.
Lenovo is a US $83 billion revenue global technology powerhouse, ranked #196 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services.
Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).
This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit , and read about the latest news via our Story Hub.
We are seeking a high-agency, strategic Senior Manager to serve as the enterprise execution lead for our security compliance and certification portfolio. This role directly supports our global assurance programs, focusing on translating complex regulatory requirements (NIS2, ISO/IEC 27001, EU CRA, and customer-driven mandates) into seamless enterprise execution.
You will work across product security, IT, engineering, and legal disciplines to build a continuously audit-ready organization. Your core objective is translating baseline regulatory interpretations into actionable, automated, and defensible engineering reality.
Job Responsibilities- Portfolio Architecture:
Direct the execution of a multi-framework security compliance portfolio. Engineer end-to-end operational traceability linking regulatory obligations directly to technical controls and automated systems. - Operational Execution:
Co-own the operationalization of compliance mandates with central GRC and Legal leadership. Translate legal interpretations into actionable engineering deliverables and actively manage cross-functional dependencies. - Risk Escalation Governance:
Govern the identification, quantification, and remediation tracking of compliance risks. Wield the authority to enforce SLAs and escalation material blockers directly to executive leadership. - Audit Command Quality:
Enforce stringent quality standards for technical system descriptions and continuous evidence generation. Command external audit operations to maintain a continuously audit-ready posture. - Team Leadership:
Manage, mentor, and scale a high-performing compliance team. Define clear accountability matrices, allocate workload dynamically, and establish rigorous execution standards.
- Education:
BSc/MSc in Cybersecurity, Information Systems, Systems Engineering, Law, or a highly related technical discipline. - Experience:
10+ years of progressive leadership experience in cybersecurity, enterprise risk, compliance, product security, or technical assurance domains. - Portfolio Capability:
Senior-level ability to architect and deliver multi-initiative compliance portfolios within highly regulated, certification-driven environments. - Audit Leadership:
Verifiable track record of commanding external audits, driving regulatory compliance initiatives, and successfully closing technical control gaps. - People Management:
Demonstrated team leadership expertise, characterized by high-agency decision-making, strict prioritization, and precise escalation judgment. - Executive Communication:
Elite written and verbal communication skills. Capable of synthesizing complex regulatory risks into executive-level briefings, telemetry dashboards, and decision frameworks.
- Professional
Certifications:
Active credentials such as CISSP, CISM, CISA, PMP, or ISO/IEC 27001 Lead Implementer. - Regulatory Specialization:
Deep operational understanding of software security requirements, secure SDLC, vulnerability disclosure programs, and emerging global mandates (specifically EU Cyber Resilience Act). - Operational Flexibility:
Availability to support critical audit cycles and off-hours engagement, with occasional travel for on-site assessments and executive stakeholder alignment.
- Opportunities for career development growth
- Performance based rewards
- Hybrid working model (3:2)
- Up to 3 paid Personal Days annually
- Additional vacation days
- 100% sick leave compensation up to 2 months per year
- A broad selection of soft / hard skills trainings and individual mentoring
- Employer contribution to the Third Pillar Pension System
- Life life events insurance, fully covered by company
The anticipated initial gross base monthly salary range for this position in Slovakia is 4,860 EUR – 7,140 EUR, depending on experience + variable part 15% of your annual earnings.
We are an Equal Opportunity Employer and do not…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: