Product Security Engineer - PSIRT
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
In this role, you will work as part of Lenovo’s Product Security Incident Response Team (PSIRT). You will be responsible for supporting the end-to-end response to product security vulnerabilities, including technical investigation, driving remediation with product teams, and publishing security advisories to customers., * Independently own end-to-end handling of product security vulnerabilities, from intake through remediation and disclosure
- Perform hands-on technical investigation and validation of reported issues across software, firmware, and system components
- Drive cross-functional coordination with development teams to ensure timely and effective remediation
- Draft security advisories, clearly communicating risk and mitigation to customers
- Assign and manage CVE, CWE, and CVSS scoring for vulnerabilities
- Engage with external security researchers, customers, and partners, supporting coordinated vulnerability disclosure (CVD)
- Identify opportunities to automate vulnerability triage, analysis, and reporting workflows, including use of scripting or AI-based approaches
- Contribute to PSIRT tooling, automation, and process improvements to support scale and efficiency
- Monitor external sources and industry channels for vulnerabilities impacting Lenovo products
- Partner with global stakeholders to ensure consistent PSIRT execution across regions
Requirements
- Bachelor’s degree or equivalent experience
- 5+ years of experience in software engineering, cybersecurity, or a related technical field
- Experience in at least one of the following areas:
- PSIRT or vulnerability response
- Secure software development
- Vulnerability management or security operations
- Experience performing technical security investigations or triage
- Experience with scripting or automation (e.g., Python or similar)
- Strong written and verbal communication skills
- Experience working in a PSIRT or coordinated vulnerability disclosure (CVD) environment
- Software development background, particularly in application or system-level components
- Experience with bug bounty programs or security research
- Familiarity with application security concepts and common vulnerability classes
- Experience building or leveraging automation, tooling, or AI-driven workflows
- Strong understanding of vulnerability management processes, especially when paired with development experience
- Familiarity with CVE, CVSS, CWE, and vulnerability disclosure practices
- Understanding of product ecosystems (e.g., firmware, OS, drivers, applications)
Basic Requirements:
- 5+ years of software engineering, cybersecurity, software development, vulnerability management, security operations, and/or technical experience
About the company
Why Work at Lenovo
We are Lenovo. We do what we say. We own what we do. We WOW our customers. Lenovo is a US$83 billion revenue global technology powerhouse, ranked #196 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY). This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking
The Overflow: Security and Privacy
Understanding and Mitigating Common Web Vulnerabilities