The Sr. Enterprise Product Security Incident Response Program Manager will lead Lenovo’s Global Enterprise PSIRT and serve as the central coordination authority for enterprise-wide incidents, including products, vulnerability management governance, and Cyber Resilience Act (CRA) readiness across all Lenovo business groups
In this role, as a hands-on technical leader, you will establish a central coordination team for vulnerability intake, researcher engagement, issue triage, coordinated vulnerability disclosure, business unit coordination, reporting oversight, KPIs, playbook maintenance, executive escalation, briefings/meetings, and CRA reporting support
This role will act as the primary orchestrator across a multitude of teams to ensure consistent vulnerability handling, incident response, threat intelligence and compliance with global regulatory requirements, including the EU Cyber Resilience Act (CRA).
Key Responsibilities
Product Security Governance: Establish and manage Lenovo’s Global Enterprise Product Security Governance framework
Establish enterprise tools, standards, policies, procedures, KPIs, and reporting for Enterprise-level PSIRT
Drive alignment across Product Security Offices within IDG, ISG, SSG, Motorola, CAIO, Legal, and other business groups
Program Oversight
Serve as the central orchestration lead for product security vulnerabilities, including AI and related security incidents
Coordinate enterprise-wide vulnerability response activities across business group security and engineering teams
Facilitate triage, prioritization, remediation, escalation, communication, and disclosure decision-making processes
Oversee tooling, automation, and process improvements to support scale and efficiency
Cyber Resilience Act Leadership
Lead Lenovo’s operational readiness and execution of CRA Article 14 requirements
Maintain and Improve governance processes for:
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
EHS System Development and Policy Management Develop and refine environmental, occupational health, and safety policies, procedures, and workflows in line with corporate objectives and production plans. Establish, mainta
General Information Req # WD00104350 Career area: Engineering Country/Region: Saudi Arabia City: Riyadh Date: Sunday, September 13, 2026 Working time: Full-time Additional Locations: * Saudi Arabia ### Why Work at Lenovo
Lenovo is seeking a Factory Planning Specialist to support management of MBG factory planning at its new overseas KSA plant. The provided posting contains very limited role-specific information and does not state detaile
Lenovo is seeking an Assistant QA professional to support manufacturing quality and new product introduction activities. The role covers quality documentation, inspections, defect tracking, data analysis, customer compla
Lenovo is seeking a Facility Specialist to manage equipment throughout its lifecycle and coordinate facility operations and maintenance. The role requires experience with technical requirements, maintenance planning, doc
Lenovo is seeking an EHS Supervisor to develop environmental, occupational health, and safety systems and policies. The role manages inspections, hazard controls, chemicals, fire safety, incident investigations, PPE, and
Lead vulnerability disclosure and coordinated remediation efforts with internal stakeholders, suppliers, partners, and security researchers
Drive end-to-end security advisory development, including vulnerability tirage, risk assessment, mitigation guidance, and customer communications
Manage communications with third-party suppliers and researchers to facilitate timely vulnerability resolution and responsible disclosure
Publish and maintain customer-facing security advisories, ensuring clear, accurate, and actionable remediation guidance
Partner with engineering, legal, communications, and support organizations to coordinate response activities and ensure consistent stakeholder communications throughout the vulnerability lifecycle
Qualifications
Bachelor’s degree in Cybersecurity, Information Systems, Systems Engineering, or a highly related technical discipline preferred
10+ years of applied experience in cybersecurity, product security, incident response, threat intelligence, or related program management/functional roles
Proven capability in establishing and leading a technical cybersecurity program in vulnerability management, incident response, or threat intelligence
Hands-on technical leader with ability to manage complex, multi-stakeholder initiatives
Exceptional written and verbal communication skills; Capable of bridging the lexicon gap between legal, engineering, and executive stakeholders
Availability to support critical cycles during business hours with occasional off-hours engagement; Intermittent travel may be required for regulatory assessments and stakeholder alignment
Previous PSIRT leadership experience
Experience interacting with external researchers, CERTs, regulators, and industry consortiums