> Markdown version of [/jobs/ext/1846563-product-security-engineer-psirt](https://www.wearedevelopers.com/jobs/ext/1846563-product-security-engineer-psirt). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Product Security Engineer - PSIRT - **Company:** Lenovo - **Location:** Morrisville, NC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Firmware, Python (Programming Language), Software Engineering, Software Vulnerability Management, Scripting, Software Security - **Published:** July 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=4f6213166e73d9b9 ## About the Role * Bachelor's degree or equivalent experience * 5+ years of experience in software engineering, cybersecurity, or a related technical field * Experience in at least one of the following areas: + PSIRT or vulnerability response + Secure software development + Vulnerability management or security operations * Experience performing technical security investigations or triage * Experience with scripting or automation (e.g., Python or similar) * Strong written and verbal communication skills * Experience working in a PSIRT or coordinated vulnerability disclosure (CVD) environment * Software development background, particularly in application or system-level components * Experience with bug bounty programs or security research * Familiarity with application security concepts and common vulnerability classes * Experience building or leveraging automation, tooling, or AI-driven workflows * Strong understanding of vulnerability management processes, especially when paired with development experience * Familiarity with CVE, CVSS, CWE, and vulnerability disclosure practices * Understanding of product ecosystems (e.g., firmware, OS, drivers, applications) Basic Requirements: * 5+ years of software engineering, cybersecurity, software development, vulnerability management, security operations, and/or technical experience ## Description In this role, you will work as part of Lenovo's Product Security Incident Response Team (PSIRT). You will be responsible for supporting the end-to-end response to product security vulnerabilities, including technical investigation, driving remediation with product teams, and publishing security advisories to customers., * Independently own end-to-end handling of product security vulnerabilities, from intake through remediation and disclosure * Perform hands-on technical investigation and validation of reported issues across software, firmware, and system components * Drive cross-functional coordination with development teams to ensure timely and effective remediation * Draft security advisories, clearly communicating risk and mitigation to customers * Assign and manage CVE, CWE, and CVSS scoring for vulnerabilities * Engage with external security researchers, customers, and partners, supporting coordinated vulnerability disclosure (CVD) * Identify opportunities to automate vulnerability triage, analysis, and reporting workflows, including use of scripting or AI-based approaches * Contribute to PSIRT tooling, automation, and process improvements to support scale and efficiency * Monitor external sources and industry channels for vulnerabilities impacting Lenovo products * Partner with global stakeholders to ensure consistent PSIRT execution across regions ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 189: Open Phones, Be the Messenger and the USB-C of AI](https://www.wearedevelopers.com/magazine/639-dev-digest-189-open-phones-be-the-messenger-and-the-usb-c-of-ai)