Advisory Engineer, Enterprise Product Security Incident Response Team; E-PSIRT
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Support, Systems Analyst
General Information
- Req # WD
- Career area:
Information Technology - Country/Region:
United States of America - State:
North Carolina - City:
Morrisville - Date:
Friday, September 4, 2026 - Working time:
Full-time - Additional Locations:
United States of America
- North Carolina
- Morrisville
We are Lenovo. We do what we say. We own what we do. We WOW our customers.
Lenovo is a US $83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world's largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services.
Lenovo's continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).
This transformation together with Lenovo's world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit , and read about the latest news via our Story Hub.
Description and RequirementsThe Product Security Advisory Engineer of Lenovo's Enterprise Product Security Incident Response Team (E-PSIRT) is responsible for assessing, triaging, coordinating, and tracking product security vulnerabilities and incidents across Lenovo's global product portfolio.
This role functions as the central operational orchestrator for product vulnerability activities, coordinating product security offices, engineering teams, suppliers, and other stakeholders to ensure vulnerabilities are appropriately evaluated, prioritized, remediated, disclosed and reported. The position will play a critical role in supporting Lenovo's Cyber Resilience Act (CRA) compliance program, including vulnerability reporting readiness and regulatory response activities. Lenovo's E-PSIRT responsibilities include vulnerability intake, triage, workflow management, coordination, impact assessment, reporting, disclosure tracking, technical advisory writing, and support for notification activities.
CoreDay-to-Day Operations
- Liaison with internal and external stakeholders, including Lenovo business units and third-party upstream and downstream suppliers, to coordinate vulnerability response and remediation activities
- Collaborate and negotiate with suppliers, technology partners, and security researchers to triage vulnerabilities, develop remediation plans, and coordinate responsible disclosure activities
- Develop, review, and publish security advisories, communicating available fixes, workarounds, and mitigation strategies for identified vulnerabilities
- Draft and issue customer-facing security communications and advisories, ensuring timely dissemination of mitigation and remediation guidance
- Coordinate cross-functional communications to ensure accurate, consistent, and timely messaging related to security vulnerabilities and product security issues
- Vulnerability Assessment & Triage: Assess product security vulnerabilities, exploits, and incidents from: researchers, customers, suppliers, threat intelligence feeds, public disclosures, CERTs, and internal testing
- Perform technical analysis and risk evaluation
- Validate business impact
- Determine vulnerability severity and likelihood
- PSIRT Case Management: Manage vulnerability cases from intake through closure, coordinate technical investigations across product security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).