×
Register Here to Apply for Jobs or Post Jobs. X

Manager, Cyber Resilience Act Compliance

Job in Farnborough, Hampshire County, OX17, England, UK
Listing for: Lenovo
Full Time position
Listed on 2026-08-04
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 30000 - 44000 GBP Yearly GBP 30000.00 44000.00 YEAR
Job Description & How to Apply Below

We are Lenovo. We do what we say. We own what we do. We WOW our customers.

Lenovo is a US $83 billion revenue global technology powerhouse, ranked #196 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services.

Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).

This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit , and read about the latest news via our Story Hub.

We are seeking a high-agency Manager, CRA Compliance Program to operationalize the EU Cyber Resilience Act (CRA) framework across our product and service portfolios. Operating within the enterprise security organization, this role bridges the gap between regulatory mandates and engineering execution.

While legal teams define baseline regulatory interpretations, you are strictly accountable for translating these interpretations into continuous operational outcomes. You will drive execution across cross-functional engineering and security teams to ensure precise product lifecycle coverage, applicability, and audit defensibility.

Job Responsibilities
  • Program Operationalization:
    Drive assigned EU CRA compliance work streams across product life cycles. Ensure execution meets strict regulatory deadlines and internal service level agreements (SLAs) while embedding requirements into design, development, and post-market phases.
  • Cross-Functional Alignment:
    Direct compliance deliverables across Product Security, IT, Legal, Privacy, and Supply Chain. Eliminate operational silos and enforce stakeholder accountability for required evidence.
  • Artifact Engineering Traceability:
    Architect and maintain defensible CRA documentation, including technical system descriptions and compliance records. Enforce end-to-end traceability between regulatory mandates and implemented controls within the enterprise system of record.
  • Risk Escalation Governance:
    Identify, document, and quantify CRA-specific technical and operational risks. Formulate risk treatment plans and elevate material blockers to security leadership with proposed remediation paths.
  • Audit Command:
    Orchestrate audit preparation and evidence coordination. Serve as the primary operational point of contact for CRA regulatory inquiries and transition assigned areas to a state of continuous audit readiness.
  • Executive Telemetry:
    Synthesize complex compliance metrics into actionable leadership briefings. Deliver precise status updates to drive rapid cross-functional alignment.
Minimum Requirements
  • Education:

    Bachelor’s degree in Cybersecurity, Information Systems, Systems Engineering, Law, or a highly related technical discipline.
  • Experience:

    7 to 10 years of applied experience in cybersecurity, product security, enterprise risk, or regulatory compliance roles.
  • Domain Expertise:
    Proven capability in executing complex cyber compliance frameworks. Verifiable experience with product-centric regulations (CRA) or major enterprise frameworks (NIS2, ISO/IEC 27001) is required.
  • Execution Capability:
    Demonstrated ability to manage complex, multi-stakeholder initiatives and translate abstract regulatory text into discrete, actionable engineering tasks.
  • Communication Mastery:
    Exceptional written and verbal communication skills. Capable of bridging the lexicon gap between legal, engineering, and executive stakeholders.
Preferred Requirements
  • Professional

    Certifications:

    Active professional credentials such as CISSP, CISM, CISA, or ISO/IEC 27001 Lead Implementer.
  • Operational Flexibility:
    Availability to…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary